Merge lp:~morphis/apparmor-easyprof-ubuntu/fix-hybris-linker-loading-16.04 into lp:~ubuntu-security/apparmor-easyprof-ubuntu/16.04-stable-phone-overlay
Proposed by
Simon Fels
Status: | Merged |
---|---|
Merged at revision: | 49 |
Proposed branch: | lp:~morphis/apparmor-easyprof-ubuntu/fix-hybris-linker-loading-16.04 |
Merge into: | lp:~ubuntu-security/apparmor-easyprof-ubuntu/16.04-stable-phone-overlay |
Diff against target: |
121 lines (+15/-0) 10 files modified
data/templates/ubuntu/1.0/ubuntu-sdk (+1/-0) data/templates/ubuntu/1.0/ubuntu-webapp (+1/-0) data/templates/ubuntu/1.1/ubuntu-sdk (+1/-0) data/templates/ubuntu/1.1/ubuntu-webapp (+1/-0) data/templates/ubuntu/1.2/ubuntu-account-plugin (+1/-0) data/templates/ubuntu/1.2/ubuntu-scope-network (+1/-0) data/templates/ubuntu/1.3/ubuntu-sdk (+1/-0) data/templates/ubuntu/15.10/ubuntu-account-plugin (+1/-0) debian/changelog (+6/-0) pending/templates/ubuntu-scope-local-content (+1/-0) |
To merge this branch: | bzr merge lp:~morphis/apparmor-easyprof-ubuntu/fix-hybris-linker-loading-16.04 |
Related bugs: |
Reviewer | Review Type | Date Requested | Status |
---|---|---|---|
Pat McGowan (community) | Approve | ||
Jamie Strandboge (community) | Needs Fixing | ||
Review via email: mp+297626@code.launchpad.net |
Description of the change
Adjust libhybris rules for new dynamic linker loading
libhybris is now capable of loading a linker implementation dynamically at runtime. This requires us to allow another path for all applications to access.
To post a comment you must log in.
This change is fine for 16.04 since an upgrade to the 16.04 base from 15.04 will generate a policy recompile.
Importantly, this change on a 15.04 system will trigger an apparmor recompile for all policy on the next OTA upgrade. This may take 2-3 minutes on an average system and thus also requires an ack from the Touch release team.
That said, I suggest using this instead for future proofing: @{multiarch} /libhybris/ *.so mr, @{multiarch} /libhybris/ **.so mr,
- /usr/lib/
+ /usr/lib/