![]() |
ubuntu.com - launchpad.net - ubuntu help
|
|
|||||||
|
Security Discussions Discuss security flaws/updates/notices in the various Ubuntu releases. |
|
|
Thread Tools | Display Modes |
|
|
#1 |
|
Way Too Much Ubuntu
![]() Join Date: Feb 2005
Location: ${HOME}
My beans are hidden!
Ubuntu 9.10 Karmic Koala
|
AppArmor Support Thread
To avoid cluttering up the Share your AppArmor Profiles thread, please post questions about AppArmor (why something is asking for certain permissions or capabilities, what is the difference between Px and ix and why do I never ever ever use Ux, how do I figure out where the real executable is...) in this thread.
__________________
Joel Goguen Real-time help: #ubuntu-beginners on irc.ubuntu.com | How To IRC The Tao of Ubuntu Security | IPTables how-to AppArmor | AppArmor Support | AppArmor Profiles |
|
|
|
|
|
#2 | |
|
Gee! These Aren't Roasted!
![]() Join Date: Jul 2008
Beans: 187
|
Re: AppArmor Support Thread
http://ubuntuforums.org/showpost.php...6&postcount=40 :
Quote:
|
|
|
|
|
|
|
#3 | ||||
|
Way Too Much Ubuntu
![]() Join Date: Feb 2005
Location: ${HOME}
My beans are hidden!
Ubuntu 9.10 Karmic Koala
|
Re: AppArmor Support Thread
To start off, here's a few questions that have already been asked:
Quote:
Code:
sudo ln /usr/bin/myprogram /usr/bin/myprogram2 Quote:
Quote:
Quote:
In general, you should never use ux or Ux - that removes AppArmor protection for the executed program! Instead, use Px (or px) if the application being executed has its own profile, or ix if not. More again later!
__________________
Joel Goguen Real-time help: #ubuntu-beginners on irc.ubuntu.com | How To IRC The Tao of Ubuntu Security | IPTables how-to AppArmor | AppArmor Support | AppArmor Profiles Last edited by jgoguen; January 25th, 2009 at 09:17 PM.. Reason: Turning off emoticons |
||||
|
|
|
|
|
#4 | |
|
Way Too Much Ubuntu
![]() Join Date: Feb 2005
Location: ${HOME}
My beans are hidden!
Ubuntu 9.10 Karmic Koala
|
Re: AppArmor Support Thread
Quote:
I'm not sure about the Wine capabilities. It sounds like something that Windows programs would try to override though. dac_override means to bypass read, write and execute permission checks. dac_read_search means to bypass file read permission checks and directory read and execute permission checks. Windows programs may not function properly without those.
__________________
Joel Goguen Real-time help: #ubuntu-beginners on irc.ubuntu.com | How To IRC The Tao of Ubuntu Security | IPTables how-to AppArmor | AppArmor Support | AppArmor Profiles Last edited by jgoguen; January 25th, 2009 at 09:46 PM.. Reason: Adding a quote to refer back to the question |
|
|
|
|
|
|
#5 | |||
|
Way Too Much Ubuntu
![]() Join Date: Feb 2005
Location: ${HOME}
My beans are hidden!
Ubuntu 9.10 Karmic Koala
|
Re: AppArmor Support Thread
A few more questions that have been asked:
Quote:
Code:
grep username /etc/passwd | cut -d":" -f3 Quote:
Quote:
__________________
Joel Goguen Real-time help: #ubuntu-beginners on irc.ubuntu.com | How To IRC The Tao of Ubuntu Security | IPTables how-to AppArmor | AppArmor Support | AppArmor Profiles Last edited by jgoguen; February 5th, 2009 at 02:39 PM.. Reason: Ubuntu doesn't compile the kernel with the options needed for --cmd-owner |
|||
|
|
|
|
|
#6 |
|
Gee! These Aren't Roasted!
![]() Join Date: Jul 2008
Beans: 187
|
Re: AppArmor Support Thread
hello. i asked this: does apparmor work against codecs, flash player, videodriver?
now i know that i cannot make separate profile for flash when it is used with firefox. by the way does not flash package include a separate flash player for swf files? now i ask these: how to name/create profile file for nvidia and ati videodriver. can we make separate package for video codecs for they are used with different players. but i think there is another way: to make rules for them in separate file and include that in different profiles. that also applies to rules for flash player that can be used with different browsers. there are "bad" codec package that is in "multiverse", is it at least partially closed-source? 8:11 gmt: i have posted notice if multiverse package is completely/fully open-source in ubuntu brainstorm. Last edited by q.dinar; January 28th, 2009 at 04:12 AM.. |
|
|
|
|
|
#7 |
|
Gee! These Aren't Roasted!
![]() Join Date: Jul 2008
Beans: 187
|
Re: AppArmor Support Thread
/usr/share/libthai/* r,
is in firefox's [apparmor] profile file, but it still asks for it: Jan 28 09:52:17 linux2008 kernel: [808819.249751] type=1503 audit(1233125537.243:5497): operation="inode_permission" requested_mask="::r" denied_mask="::r" fsuid=1000 name="/usr/share/libthai/thbrk.sbm" pid=29530 profile="/usr/lib/firefox-3.0.5/firefox.sh" |
|
|
|
|
|
#8 |
|
Gee! These Aren't Roasted!
![]() Join Date: Jul 2008
Beans: 187
|
Re: AppArmor Support Thread
and [btw] what are these?:
808819.249751 type=1503 audit(1233125537.243:5497) fsuid=1000 |
|
|
|
|
|
#9 | |
|
Way Too Much Ubuntu
![]() Join Date: Feb 2005
Location: ${HOME}
My beans are hidden!
Ubuntu 9.10 Karmic Koala
|
Re: AppArmor Support Thread
Quote:
__________________
Joel Goguen Real-time help: #ubuntu-beginners on irc.ubuntu.com | How To IRC The Tao of Ubuntu Security | IPTables how-to AppArmor | AppArmor Support | AppArmor Profiles |
|
|
|
|
|
|
#10 | |
|
Way Too Much Ubuntu
![]() Join Date: Feb 2005
Location: ${HOME}
My beans are hidden!
Ubuntu 9.10 Karmic Koala
|
Re: AppArmor Support Thread
Quote:
Code:
sudo apparmor_parser -r < usr.lib.firefox-3.0.5.firefox.sh
__________________
Joel Goguen Real-time help: #ubuntu-beginners on irc.ubuntu.com | How To IRC The Tao of Ubuntu Security | IPTables how-to AppArmor | AppArmor Support | AppArmor Profiles |
|
|
|
|
| Bookmarks |
| Tags |
| apparmor |
| Thread Tools | |
| Display Modes | |
|
|