Overview

Request 730528 revoked

- Remove AA profile. Without internal knowledge about the goal of the
execution the profile needs to be so bread that it doesn't help
(bsc#1150338)

- Remove AA profile. Without internal knowledge about the goal of the
execution the profile needs to be so bread that it doesn't help
(bsc#1150338)

Loading...

Martin Wilck's avatar

AFAICS on bug 1150338, consensus hasn't been reached in the security team how to deal with this.


Christian Boltz's avatar

I strongly recommend to keep the AppArmor profile - even if it is very broad, it still can prevent some exploits, and removing it would reduce security - see the comment I just added to boo#1150338 for details.

Asking the other way round - does the profile cause any real-world problems, or do you just have doubts how useful it is? (Feel free to answer in bugzilla to keep the discussion at one place.)


Request History
Johannes Segitz's avatar

jsegitz created request

- Remove AA profile. Without internal knowledge about the goal of the
execution the profile needs to be so bread that it doesn't help
(bsc#1150338)

- Remove AA profile. Without internal knowledge about the goal of the
execution the profile needs to be so bread that it doesn't help
(bsc#1150338)


Dr. Werner Fink's avatar

WernerFink added cboltz as a reviewer

You might have some useful comments as well


Johannes Segitz's avatar

jsegitz revoked request

profile will be kept

openSUSE Build Service is sponsored by