Recommended update for apparmor

This update to apparmor 2.9.3 fixes the following issues:

- aa-complain, aa-enforce, aa-audit: change flags of hats, not only the main profile (+ some bugfixes)
- aa-notify: also display notifications for complain mode events
- add python to the "no Px rule" list in logprof.conf
- several bugfixes in the aa-* tools (including boo#954104 and several bugs on lp)
- parser: set cache file timestamp to mtime of most recent policy file timestamp (lp#1460152)
- add permissions in several profiles (including boo#948584, boo#948753, boo#939568, boo#954959, boo#954958, boo#940749, boo#971790, boo#945592, boo#964971, boo#921098, boo#923201 and boo#921098#c15)
- systemd-rpm-macros and %systemd_requires were at the wrong place, move them to the parser package (boo#931792)
- lots of bugfixes in the parser and the aa-* tools (including boo#918787)
- update dovecot and dnsmasq profiles and several abstractions (including boo#911001)
- make sure %service_del_postun doesn't call systemctl try-restart (boo#853019, bare systemd edition)
- update samba (winbindd and nmb) profiles for samba 4.2 (boo#921098, boo#923201)
- allow lessopen.sh to run /usr/bin/unzip-plain (boo#906858)
- add Requires: python3 to python3-apparmor package - readline isn't part of python3-base (boo#917577)

Fixed bugs
bnc#948584
AppArmor blocks the start of syslog-ng
bnc#964971
smbd fails when calling setxattr to update acls in the security.NTACL namespace
bnc#931792
Apparmor is missing profiles and enforcement of it
bnc#918787
logprof fails to parse audit.log (disconnected path)
bnc#971790
nscd paranoia mode impossible
bnc#906858
VUL-1: aaa_base: LESSOPEN=lessopen.sh uses various other binaries, creates a large attack surface
bnc#911001
dnsmasq apparmor profile prevents libvirt default network to start
bnc#945592
ntpd wants to read directories in $PATH
bnc#923201
nmb.service failed
bnc#853019
systemctl restart apparmor considered harmful (was: %restart_on_update boot.apparmor + systemd wrapper considered harmful)
bnc#954104
no messages written to logfiles (systemd <> syslog-ng interaction ?)
bnc#939568
skype profile denies network access
bnc#940749
Apparmor prevents dnsmasq from executing /bin/bash
bnc#917577
security:apparmor/apparmor: Bug
bnc#921098
winbindd 4.2.0 panics on start-up when Apparmor is enabled
bnc#954958
dovecot sieve vacation
bnc#954959
dovecot /tmp/dovecot.lda.) Permission denied
bnc#948753
incomplete profile for /usr/sbin/syslog-ng
Selected Binaries
openSUSE Build Service is sponsored by