[Bug 1884980] Re: patch so apparmor complain->enforcing

2020-08-25 Thread Launchpad Bug Tracker
[Expired for sssd (Ubuntu) because there has been no activity for 60 days.] ** Changed in: sssd (Ubuntu) Status: Incomplete => Expired -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1884980 Tit

[Bug 1884980] Re: patch so apparmor complain->enforcing

2020-06-26 Thread Harry Coin
Christian, Since to test whether the fix I provided was complete you'd have to install freeipa-server to see all the bloat from apparmor, then try the fix and tweak it that would be enough given the sample error message. But, since you asked, here's a zmore /var/log/syslog.7.gz | grep appa > It

[Bug 1884980] Re: patch so apparmor complain->enforcing

2020-06-25 Thread Christian Ehrhardt 
** Changed in: sssd (Ubuntu) Status: New => Incomplete ** Tags removed: server-next -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1884980 Title: patch so apparmor complain->enforcing To man

[Bug 1884980] Re: patch so apparmor complain->enforcing

2020-06-25 Thread Christian Ehrhardt 
Thanks Harry, to understand and group the rules better - if you'd have an attachment for these "thousands of varied examples" from your log, please attach them. Also if you happen to know that some of them only trigger with a particular config that will be useful. If you can't relate apparmor- de

[Bug 1884980] Re: patch so apparmor complain->enforcing

2020-06-25 Thread Harry Coin
Seth, Thanks for the note! I've made the change. Harry Coin -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1884980 Title: patch so apparmor complain->enforcing To manage notifications about this

[Bug 1884980] Re: patch so apparmor complain->enforcing

2020-06-25 Thread Seth Arnold
Hello Harry, thanks for the profile additions. Note that the "//null-" portion of the profiles represents a missing execution permission line in the profile. When in enforce mode, the execution would be denied. When in complain mode, the execution is allowed, and the //null- is tacked on, with the