Merge lp:~sdeziel/apparmor/smbd-refresh into lp:apparmor/2.12

Proposed by Simon Déziel
Status: Merged
Merged at revision: 3438
Proposed branch: lp:~sdeziel/apparmor/smbd-refresh
Merge into: lp:apparmor/2.12
Diff against target: 38 lines (+7/-0)
1 file modified
profiles/apparmor.d/usr.sbin.smbd (+7/-0)
To merge this branch: bzr merge lp:~sdeziel/apparmor/smbd-refresh
Reviewer Review Type Date Requested Status
AppArmor Developers Pending
Review via email: mp+291755@code.launchpad.net

Description of the change

New versions of Samba will soon land into Ubuntu [*] so it's a good time to refresh the profile.

*: https://lists.ubuntu.com/archives/ubuntu-server/2016-April/007266.html

To post a comment you must log in.
Revision history for this message
Seth Arnold (seth-arnold) wrote :

Thanks; pity they require so much privilege.

Merged

Preview Diff

[H/L] Next/Prev Comment, [J/K] Next/Prev File, [N/P] Next/Prev Hunk
1=== modified file 'profiles/apparmor.d/usr.sbin.smbd'
2--- profiles/apparmor.d/usr.sbin.smbd 2015-02-28 20:35:18 +0000
3+++ profiles/apparmor.d/usr.sbin.smbd 2016-04-13 13:28:08 +0000
4@@ -10,6 +10,7 @@
5 #include <abstractions/user-tmp>
6 #include <abstractions/wutmp>
7
8+ capability audit_write,
9 capability dac_override,
10 capability dac_read_search,
11 capability fowner,
12@@ -17,6 +18,7 @@
13 capability net_bind_service,
14 capability setgid,
15 capability setuid,
16+ capability sys_admin,
17 capability sys_resource,
18 capability sys_tty_config,
19
20@@ -31,6 +33,9 @@
21 /usr/lib*/samba/auth/script.so mr,
22 /usr/lib*/samba/pdb/*.so mr,
23 /usr/lib*/samba/{lowcase,upcase,valid}.dat r,
24+ /usr/lib/@{multiarch}/samba/*.so{,.[0-9]*} mr,
25+ /usr/lib/@{multiarch}/samba/**/ r,
26+ /usr/lib/@{multiarch}/samba/**/*.so{,.[0-9]*} mr,
27 /usr/sbin/smbd mr,
28 /usr/sbin/smbldap-useradd Px,
29 /var/cache/samba/** rwk,
30@@ -42,6 +47,8 @@
31 /{,var/}run/samba/ncalrpc/ rw,
32 /{,var/}run/samba/ncalrpc/** rw,
33 /{,var/}run/samba/smbd.pid rw,
34+ /{,var/}run/samba/msg.lock/ rw,
35+ /{,var/}run/samba/msg.lock/[0-9]* rwk,
36 /var/spool/samba/** rw,
37
38 @{HOMEDIRS}/** lrwk,

Subscribers

People subscribed via source and target branches