boot script should run aa-profile-hook in addition to aa-clickhook

Bug #1434143 reported by Jamie Strandboge
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
Snappy
Fix Released
High
Unassigned
apparmor (Ubuntu)
Fix Released
High
Steve Beattie

Bug Description

Summary says it all. aa-profile-hook does the same sort of thing as aa-clickhook and is used on snappy.

Changed in snappy-ubuntu:
status: New → Triaged
importance: Undecided → High
Changed in apparmor (Ubuntu):
assignee: nobody → Steve Beattie (sbeattie)
status: Triaged → In Progress
Revision history for this message
Steve Beattie (sbeattie) wrote :

Per discussion with Jamie on irc, aa-profile-hook is to be triggered when the apparmor package or click-apparmor package (provider of aa-profile-hook) is updated via the system image updater. It is *not* necessary to run aa-profile-hook on updates to apparmor-easyprof-ubuntu and apparmor-easyprof-ubuntu-snappy.

(I'm not sure what an update to apparmor-easyprof-ubuntu-snappy should trigger, if anything; aa-clickhook perhaps?)

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Update of apparmor-easyprof-ubuntu-snappy should trigger running aa-clickhook.

Revision history for this message
Steve Beattie (sbeattie) wrote :

Thanks, I've updated the apparmor-ubuntu-citrain branch to do that. Test packages are building in https://launchpad.net/~ubuntu-security-proposed/+archive/ubuntu/ppa and will test the changes once they're built.

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package apparmor - 2.9.1-0ubuntu8

---------------
apparmor (2.9.1-0ubuntu8) vivid; urgency=medium

  [ Steve Beattie ]
  * debian/rules: run make check on the libapparmor library
  * add-chromium-browser.patch: add support for chromium policies
    (LP: #1419294)
  * debian/apparmor.{init,upstart}: add support for triggering
    aa-profile-hook runs when packages are updated via snappy system
    image updates (LP: #1434143)
  * parser-fix_modifier_compilation_+_tests.patch: fix compilation
    of audit modifiers for exec and pivot_root and deny modifiers on
    link rules as well as significantly expand related tests
    (LP: #1431717, LP: #1432045, LP: #1433829)
  * tests-fix_systemd_breakage_in_pivot_root-lp1436109.patch: work
    around pivot_root test failures due to init=systemd (LP: #1436109)
  * GDM_X_authority-lp1432126.patch: add location GDM creates Xauthority
    file to X abstraction (LP: #1432126)

  [ Jamie Strandboge ]
  * easyprof-framework-policy.patch: add --include-templates-dir and
    --include-policy-groups-dir options to easyprof to support framework
    policy on snappy

  [ Robie Basak ]
  * Add /lib/apparmor/profile-load; moved from
    /lib/init/apparmor-profile-load from the upstart package. A wrapper at
    the original path is now provided by init-system-helpers. (LP: #1432683)
 -- Jamie Strandboge <email address hidden> Sat, 28 Mar 2015 07:22:30 -0500

Changed in apparmor (Ubuntu):
status: In Progress → Fix Released
Michael Terry (mterry)
affects: snappy-ubuntu → snappy
Changed in snappy:
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.