UbuntuUpdates.org

Package "apparmor"




Name: apparmor

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • AppArmor easyprof profiling tool
  • AppArmor debhelper routines

Latest version: *DELETED*
Release: focal (20.04)
Level: proposed
Repository: universe

Links



Other versions of "apparmor" in Focal

Repository Area Version
base main 2.13.3-7ubuntu5
base universe 2.13.3-7ubuntu5
security main 2.13.3-7ubuntu5.4
security universe 2.13.3-7ubuntu5.4
updates main 2.13.3-7ubuntu5.4
updates universe 2.13.3-7ubuntu5.4

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2.13.3-7ubuntu5.2 2022-12-06 12:06:22 UTC

  apparmor (2.13.3-7ubuntu5.2) focal; urgency=medium

  * Add capability upstream patches to fix LP: #1964636
    - u/cap1-Generate-CAPABILITIES-in-a-script-due-to-make-4.3.patch: move
    code that generates a list of capabilities to a script in common/
    - u/cap2-parser-Move-to-a-pre-generated-cap_names.h.patch: use a
    pre-generated list of capabilities so that all capabilities are
    supported even when building against older kernels.
    - u/cap3-parser-cleanup-capability_table-generation-by-droppi.patch: drop
    sys_log static declaration because it's already in the generated list.
    - u/cap4-parser-unify-capability-name-handling.patch: drop internal
    hardcoded capability table.
    - u/cap5-parser-Makefile-use-LC_ALL-C-when-invoking-sed.patch: use
    LC_ALL=C when invoking sed.
    - u/cap6-parser-Add-warning-to-capability_table-about-the-nee.patch: add
    warning to capability_table about the need to update the Makefile.
    - u/cap7-Add-CAP_BPF-and-CAP_PERFMON-to-severity.db.patch: add
    support for cap_bpf and cap_perfmon
    - u/cap8-parser-Makefile-fix-generated-cap-comparison-against.patch: fix
    generated cap comparison against known list
  * Add upstream patches for abi support. LP: #1728130
    - u/abi1-parser-feature-abi-setup-parser-to-intersect-policy-.patch: add
    the ability to intersect parser and kernel features in the parser.
    - u/abi2-parser-add-basic-support-for-feature-abis.patch: add support
    to specify a feature abi.
    - u/abi3-pin-abi-2.13.patch: add and pin a policy abi for 2.13
    - u/abi4-parser-fix-abi-rule-and-pinned-feature-file-interact.patch: fix
    abi rule and pinned feature file interaction
    - apparmor.install: add 2.13 abi file to be installed in /etc/apparmor.d/abi/
  * Add mqueue patches. LP: #1993353
    - u/mqueue1-parser-add-parser-support-for-message-queue-mediatio.patch:
    add parser support for mqueue mediation
    - u/mqueue2-tests-add-posix-message-queue-regression-tests.patch: add
    posix mqueue regression tests
    - u/mqueue3-utils-add-message-queue-rules-parsing-in-python-tool.patch:
    add support in python tools to parse mqueue rules
    - u/mqueue4-parser-add-parser-simple-tests-for-mqueue-rules.patch: add
    parser simple tests for mqueue
    - u/mqueue5-parser-place-perm-on-name-as-well-as-name-label-comb.patch:
    add permissions on name and also on name + label
    - u/mqueue6-libapparmor-add-support-for-requested-and-denied-on-.patch:
    add parsing support for "denied" and "requested" from audit logs
    - u/mqueue7-libapparmor-add-support-for-class-in-logparsing.patch: add
    parsing support for "class" from audit logs
    - u/mqueue8-utils-add-logparser-support-for-mqueue.patch: add logparser
    support for mqueue rules
    - u/mqueue9-tests-add-sysv-message-queue-regression-tests.patch: add
    sysv mqueue regression tests
    - u/mqueue10-parser-enable-mqueue-rules-when-abi-is-not-set.patch:
    override pinned features for mqueue rules when abi is not set in policy.
    - debian/rules: create mqueue testcase empty files for libapparmor tests.
  * Closes LP: #1994146

 -- Georgia Garcia <email address hidden> Mon, 10 Oct 2022 17:52:45 -0300

1964636 Incorrect handling of apparmor `bpf` capability
1728130 Policy needs improved feature versioning to ensure it is correctly being applied
1993353 Add posix message queue IPC mediation
1994146 [SRU] apparmor - Focal, Jammy

Version: *DELETED* 2020-06-05 17:07:31 UTC
No changelog for deleted or moved packages.

Version: 2.13.3-7ubuntu5.1 2020-05-22 14:06:35 UTC

  apparmor (2.13.3-7ubuntu5.1) focal-proposed; urgency=medium

  * upstream-lp1872564.patch: adjust nameservice abstraction for nss-systemd
    - LP: #1872564

 -- Jamie Strandboge <email address hidden> Tue, 19 May 2020 16:59:49 +0000

1872564 /proc/sys/kernel/random/boot_id rule missing from abstractions/nameservice

Version: *DELETED* 2020-04-14 09:06:21 UTC
No changelog for deleted or moved packages.

Version: 2.13.3-7ubuntu5 2020-04-13 05:07:09 UTC

  apparmor (2.13.3-7ubuntu5) focal; urgency=medium

  * snapd 2.44.3+20.04 introduced an apparmor unit of its own to load snap
    policy in /var/lib/snapd/apparmor/profiles. As such, don't load snapd
    policy twice by not loading it in the apparmor unit (LP: 1871148)
    - ubuntu/stop-loading-snapd-profiles.patch: stop loading snapd profiles
    - debian/control: add Breaks on snapd < 2.44.3+20.04~ since prior snapd
      versions assume that apparmor will load the snapd policy on boot
    - debian/apparmor.service: remove the now unneeded RequiresMountsFor on
      /var/lib/snapd/apparmor/profiles
  * drop ubuntu/parser-conf-no-expr-simplify.patch: Optimize=no-expr-simplify
    was added to parser.conf to mitigate slow snap policy compiles on 32bit
    ARM. These days, snapd calls apparmor_parser with "-O no-expr-simplify"
    and loads its snap policy, so drop this delta with upstream and Debian.

 -- Jamie Strandboge <email address hidden> Sun, 12 Apr 2020 16:11:31 +0000




About   -   Send Feedback to @ubuntu_updates