recommended update for AppArmor

This recommended update for AppArmor fixes the following issues:
- Update from version 2.8.2 to 2.8.4 and several bugfixes
+ delete cache in apparmor-profiles %post (workaround for bnc#904620#c8 / lp#1392042)
+ mod_apparmor: try uri hat after AADefaultHatName, not before. Fixes the regression in 2.8.3 (lp#1322778)
+ libapparmor: fix log parsing memory leaks (lp#1340927)
+ parser: Fix profile loads from cache files that contain multiple profiles
+ several profiles and abstractions/* updates (including bnc#857122#c2, bnc#899746, bnc#869787, bnc#886225)
+ see http://wiki.apparmor.net/index.php/ReleaseNotes_2_8_4 for details
+ add Provides: apparmor-abstractions to apparmor-profiles
+ deny capability block_suspend for /usr/lib/dovecot/imap
+ usr.lib.dovecot.auth: allow /var/run/dovecot/auth-token-secret.dat{,.tmp}
+ allow dnsmasq read access to interface mtu in /proc/sys/net/ipv6/conf//mtu (bnc#892374)
+ usr.lib.dovecot.auth: add '/etc/dovecot/* r' to allow reading plaintext password files (bnc#874094)
+ Rename rpmlintrc to %{name}-rpmlintrc to follow the packaging guidelines.
+ perl-apparmor: Fix handling of network (or network all) (bnc#889650)
+ perl-apparmor: Fix handling of capability keyword (bnc#889651)
+ perl-apparmor: Properly handle bare file keyword (bnc#889652)
+ permit clustered Samba access to CTDB socket and databases (bnc#885317)
+ fix problems with dovecot and managesieve
+ add #include to usr.lib.dovecot.auth
+ update usr.sbin.winbindd profile (bnc#870607)
* restrict rw access to /var/cache/krb5rcache/ instead /var/tmp/
+ update usr.sbin.winbindd profile (bnc#870607)
* treat passdb.tdb.tmp as passdb.tdb
* allow rw access to /var/tmp/
+ add Recommends: libnotify-tools to apparmor-utils (aa-notify -p needs notify-send)
+ fix some cache clearing bugs in apparmor_parser
+ various fixes in mod_apparmor
+ several profile updates, most of them were already included as patches (except abstractions/winbind (bnc#863226), abstractions/fonts and abstractions/p11-kit)
+ see http://wiki.apparmor.net/index.php/ReleaseNotes_2_8_3 for all details
+ use current ruby macros, the rb_sitearch is obsolete since at least 12.1

Fixed bugs
bnc#857122
nagios plugin to check zypper cannot zypper ref due to apparmor profile
bnc#863226
Dynamic DNS does not cooperate with DHCP If AppArmor is enabled
bnc#869787
Samba cachedir location relocated
bnc#870607
winbind profile needs rw access to /var/cache/krb5rcache
bnc#874094
Dovecot passwd-file authentication and AppArmor
bnc#885317
apparmor causes Samba to fail to start when clustering is configured
bnc#886225
smbd should get read access to /run/nscd/{group,passwd}
bnc#889650
perl-apparmor: handling of network and network all keywords is broken
bnc#889651
perl-apparmor: use of the capability keyword without further arguments causes syntax error
bnc#889652
perl-apparmor: use of the file keyword results in a syntax error
bnc#892374
apparmor: dnsmasq denied access to /proc/sys/net/ipv6/conf/virbr1/mtu
bnc#899746
apparmor prevents ntpd start
bnc#904620
ntpd is unable to start
Selected Binaries
openSUSE Build Service is sponsored by