* Drop the following change now that click-apparmor has been updated:
- Continue installing aa-exec into /usr/sbin/ for now since
click-apparmor's aa-exec-click autopkgtest expects it to be there
* debian/patches/allow-stacking-tests-to-use-system.patch,
debian/patches/r3430-allow-stacking-tests-to-use-system.patch: Replace
patch with the final version that landed upstream and annotate the patch
headers accordingly
* debian/patches/r3460-ignore-file-events-with-send-or-receive-request.patch:
Prevent an aa-logprof crash by ignoring file events that contains
send or receive in the request mask. (LP: #1577051, LP: #1582374)
* debian/patches/r3463-r3475-change-profile-exec-modes.patch: Allow policy
authors to specify if the environment should scrubbed during exec
transitions allowed by a change_profile rule. (LP: #1584069)
* debian/patches/r3478-make-overlapping-safe-and-unsafe-rules-conflict.patch:
Make sure that multiple change_profile rules with overlapping safe and
unsafe exec modes conflict when they share the same exec conditional
(LP: #1588069)
* debian/patches/r3479-create-fcitx-abstractions.patch: Include fcitx and
fcitx-strict abstractions that fcitx client profiles can reuse.
* debian/control: Do a conffile move of /etc/apparmor.d/abstractions/fcitx
from the fcitx-data to apparmor by setting up the correct Breaks and
Replaces.
* debian/patches/r3480-create-mozc-abstraction.patch: Include a mozc
abstraction that mozc client profiles can reuse.
* debian/patches/r3488-r3489-fix-racy-onexec-test.patch: Fix racy regression
test so that the kernel SRU process is not interrupted by the onexec.sh
periodically failing
* debian/patches/r3490-utils-handle-change-profile-exec-modes.patch: Update
the Python utilities to handle the new exec mode keywords in
change_profile rules. (LP: #1584069)
* debian/patches/r3492-allow-dbus-user-session-path.patch: Allow read/write
access to the dbus-user-session socket file. (LP: #1604872)
This bug was fixed in the package apparmor - 2.10.95-4ubuntu2
---------------
apparmor (2.10.95-4ubuntu2) yakkety; urgency=medium
* Drop the following change now that click-apparmor has been updated: apparmor' s aa-exec-click autopkgtest expects it to be there patches/ allow-stacking- tests-to- use-system. patch, patches/ r3430-allow- stacking- tests-to- use-system. patch: Replace patches/ r3460-ignore- file-events- with-send- or-receive- request. patch: patches/ r3463-r3475- change- profile- exec-modes. patch: Allow policy patches/ r3478-make- overlapping- safe-and- unsafe- rules-conflict. patch: patches/ r3479-create- fcitx-abstracti ons.patch: Include fcitx and d/abstractions/ fcitx patches/ r3480-create- mozc-abstractio n.patch: Include a mozc patches/ r3488-r3489- fix-racy- onexec- test.patch: Fix racy regression patches/ r3490-utils- handle- change- profile- exec-modes. patch: Update patches/ r3492-allow- dbus-user- session- path.patch: Allow read/write
- Continue installing aa-exec into /usr/sbin/ for now since
click-
* debian/
debian/
patch with the final version that landed upstream and annotate the patch
headers accordingly
* debian/
Prevent an aa-logprof crash by ignoring file events that contains
send or receive in the request mask. (LP: #1577051, LP: #1582374)
* debian/
authors to specify if the environment should scrubbed during exec
transitions allowed by a change_profile rule. (LP: #1584069)
* debian/
Make sure that multiple change_profile rules with overlapping safe and
unsafe exec modes conflict when they share the same exec conditional
(LP: #1588069)
* debian/
fcitx-strict abstractions that fcitx client profiles can reuse.
* debian/control: Do a conffile move of /etc/apparmor.
from the fcitx-data to apparmor by setting up the correct Breaks and
Replaces.
* debian/
abstraction that mozc client profiles can reuse.
* debian/
test so that the kernel SRU process is not interrupted by the onexec.sh
periodically failing
* debian/
the Python utilities to handle the new exec mode keywords in
change_profile rules. (LP: #1584069)
* debian/
access to the dbus-user-session socket file. (LP: #1604872)
-- Tyler Hicks <email address hidden> Tue, 26 Jul 2016 23:03:05 -0500