ubuntu/+source/strongswan:ubuntu/cosmic-updates

Last commit made on 2020-07-17
Get this branch:
git clone -b ubuntu/cosmic-updates https://git.launchpad.net/ubuntu/+source/strongswan
Members of git-ubuntu import can upload to this branch. Log in for directions.

Branch merges

Branch information

Name:
ubuntu/cosmic-updates
Repository:
lp:ubuntu/+source/strongswan

Recent commits

af23791... by Christian Ehrhardt 

changelog: apparmor fixes (LP: #1780534 LP: #1773956)

Signed-off-by: Christian Ehrhardt <email address hidden>

f7dbece... by Christian Ehrhardt 

- d/usr.lib.ipsec.lookip: executables need to be able to read map and execute themselves

Signed-off-by: Christian Ehrhardt <email address hidden>

ab44ec8... by Christian Ehrhardt 

- d/usr.lib.ipsec.stroke: executables need to be able to read map and execute themselves

Signed-off-by: Christian Ehrhardt <email address hidden>

c1660e2... by Christian Ehrhardt 

d/usr.lib.ipsec.charon: allow CLUSTERIP for ha plugin (LP: #1773956)

Signed-off-by: Christian Ehrhardt <email address hidden>

bb63f8a... by Andreas Hasenack

changelog

996a1df... by Christian Ehrhardt 

fix apparmor denies reading the own FDs (LP: #1786250)

As per LP #1786250, user noted audit failures in system log
against charon trying to read its own list of file descriptors
in /proc/<pid>/fd/.

We are uncertain when/why this started, however it is not
unreasonable for a process to attempt to read its own fd's,
so allow by extending the apparmor profile for charon.

References:
http://manpages.ubuntu.com/manpages/bionic/en/man5/apparmor.d.5.html
https://linux.die.net/man/5/proc

5aeaa41... by Marc Deslauriers

5.6.3-1ubuntu3 (patches unapplied)

Imported using git-ubuntu import.

2ed3a51... by Marc Deslauriers

5.6.3-1ubuntu2 (patches unapplied)

Imported using git-ubuntu import.

e0e7ae5... by Andreas Hasenack

Cleanup d/changelog (removed signed-off lines)

52230fd... by Andreas Hasenack

update-maintainer