[pkg-apparmor] Bug#981442: apparmor: Please do not install by default or depend on python3

Samuel Thibault sthibault at debian.org
Fri Feb 5 10:30:05 GMT 2021


Hello,

intrigeri, le ven. 05 févr. 2021 09:06:54 +0100, a ecrit:
> I did the backporting work in a topic branch:
> https://salsa.debian.org/apparmor-team/apparmor/-/tree/debian-bug-981442

Thanks!

>   4. ensure aa-status works (compare with how it works in a regular
>   testing/sid system)

I tried a bit with the base system, got 

apparmor module is loaded.
3 profiles are loaded.
3 profiles are in enforce mode.
   lsb_release
   nvidia_modprobe
   nvidia_modprobe//kmod
0 profiles are in complain mode.
0 processes have profiles defined.
0 processes are in enforce mode.
0 processes are in complain mode.
0 processes are unconfined but have a profile defined.

just like with the python version. I tried to install tcpdump and ntp, then got

apparmor module is loaded.
5 profiles are loaded.
5 profiles are in enforce mode.
   /usr/sbin/ntpd
   lsb_release
   nvidia_modprobe
   nvidia_modprobe//kmod
   tcpdump
0 profiles are in complain mode.
1 processes have profiles defined.
1 processes are in enforce mode.
   /usr/sbin/ntpd (792)
0 processes are in complain mode.
0 processes are unconfined but have a profile defined.

I'm not sure how I can easily check for the complain case.
(AIUI they'd be supposed to be bugs :) )


I'll keep the VMs around, for any further test you'd want?

Samuel



More information about the pkg-apparmor-team mailing list