Feature #9539

Install the apparmor-profiles package

Added by intrigeri 2015-06-06 10:44:53 . Updated 2015-07-19 06:29:15 .

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Target version:
Start date:
2015-06-06
Due date:
% Done:

100%

Feature Branch:
bugfix/8007-AppArmor-hardening
Type of work:
Code
Blueprint:

Starter:
Affected tool:
Deliverable for:

Description

That package installs a bunch of upstream profiles. The only ones that apply to software shipped in Tails are about ping and traceroute, but this might improve in the future, so why not?


Subtasks


Related issues

Related to Tails - Bug #9757: Remove AppArmor profiles we don't use Resolved 2015-07-18

History

#1 Updated by intrigeri 2015-06-06 13:39:13

  • Status changed from Confirmed to In Progress

Applied in changeset commit:5e47b2a7c8962b9d6d2dcc96f5bb00ba016ea396.

#2 Updated by intrigeri 2015-06-06 13:40:05

  • % Done changed from 0 to 10
  • Feature Branch set to bugfix/8007-AppArmor-hardening

#3 Updated by intrigeri 2015-07-18 07:50:29

  • Status changed from In Progress to Resolved
  • Assignee deleted (intrigeri)
  • Target version deleted (Tails_1.5)
  • % Done changed from 10 to 100

It doesn’t prevent ping and traceroute from working.

#4 Updated by intrigeri 2015-07-18 07:59:21

#5 Updated by intrigeri 2015-07-19 04:50:47

  • related to Bug #9757: Remove AppArmor profiles we don't use added

#6 Updated by intrigeri 2015-07-19 05:17:40

  • Status changed from Resolved to In Progress
  • Assignee set to intrigeri
  • Target version set to Tails_1.5
  • % Done changed from 100 to 70

These profiles are installed in complain mode by default. We should set to enforce mode the ones we really want to ship.

#7 Updated by intrigeri 2015-07-19 06:29:15

  • Status changed from In Progress to Resolved
  • Assignee deleted (intrigeri)
  • % Done changed from 70 to 100

intrigeri wrote:
> These profiles are installed in complain mode by default. We should set to enforce mode the ones we really want to ship.

More complicated than it seems, postponing: Feature #9764.