[pkg-apparmor] Bug#1147158: RM: apparmor-profiles-extra -- ROM; Obsolete upstream
intrigeri
intrigeri at debian.org
Tue Sep 8 14:35:52 BST 2026
Package: ftp.debian.org
Severity: normal
X-Debbugs-Cc: apparmor-profiles-extra at packages.debian.org, pkg-apparmor-team at lists.alioth.debian.org
Control: affects -1 + src:apparmor-profiles-extra
User: ftp.debian.org at packages.debian.org
Usertags: remove
Control: block -1 by 1147157
Control: block -1 by 1146674
Hi,
First, for a variety of reasons, the preferred way to add AppArmor policy to
Debian (short of having it maintained upstream) is to include it in the package
that ships the confined software, so it can be tested together with software
updates, and the maintainer is the best placed to tell whether a specific newly
denied access is legitimate or not.
So apparmor-profiles-extra was always meant to be a temporary hack. The amount
of profiles shipped in that package has been decreasing a fair bit and we're now
down to 2 profiles + 1 abstraction that's not used anywhere, except by
fwknop-apparmor-profile (#1147157).
Additionally, it's always been awkward to maintain the profiles shipped in this
package, with no automated mechanism to track the multiple sources of input we
use here.
Finally, and this is the last nail in the coffin for me, the main source of
AppArmor profiles for this is deprecated. Not only it was dormant since a year
or 3, with no capacity available for reviewing fixes, but more recently the
corresponding GitLab project was repurposed and does not include the profiles
that we have in apparmor-profiles-extra anymore:
https://lists.ubuntu.com/archives/apparmor/2026-August/014935.html
Thanks!
More information about the pkg-apparmor-team
mailing list