disable sha-1 hashing for policy for Ubuntu Touch
Bug #1383886 reported by
Jamie Strandboge
This bug affects 1 person
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| AppArmor |
In Progress
|
Medium
|
John Johansen | ||
| linux (Ubuntu) |
Fix Released
|
Medium
|
John Johansen | ||
| linux-flo (Ubuntu) |
Triaged
|
Medium
|
John Johansen | ||
| linux-goldfish (Ubuntu) |
Triaged
|
Medium
|
John Johansen | ||
| linux-hammerhead (Ubuntu) |
Triaged
|
Medium
|
John Johansen | ||
| linux-mako (Ubuntu) |
Triaged
|
Medium
|
John Johansen | ||
| linux-manta (Ubuntu) |
Triaged
|
Medium
|
John Johansen | ||
Bug Description
Currently there is a compile time option to disable/enable sha-1 hashing of profiles. While enabling this option is useful for debugging, it can incur a 1 second cache load penalty on Ubuntu Touch with ~100 profiles. Upstream task is to make this runtime/boot time configurable.
CVE References
| Changed in linux-flo (Ubuntu): | |
| status: | New → Triaged |
| Changed in linux-goldfish (Ubuntu): | |
| status: | New → Triaged |
| Changed in linux-hammerhead (Ubuntu): | |
| status: | New → Triaged |
| Changed in linux-mako (Ubuntu): | |
| status: | New → Triaged |
| Changed in linux-manta (Ubuntu): | |
| status: | New → Triaged |
| importance: | Undecided → Medium |
| Changed in linux-mako (Ubuntu): | |
| importance: | Undecided → Medium |
| Changed in linux-hammerhead (Ubuntu): | |
| importance: | Undecided → Medium |
| Changed in linux-goldfish (Ubuntu): | |
| importance: | Undecided → Medium |
| Changed in linux-flo (Ubuntu): | |
| importance: | Undecided → Medium |
| description: | updated |
| Changed in linux (Ubuntu): | |
| assignee: | nobody → John Johansen (jjohansen) |
| status: | New → Triaged |
| importance: | Undecided → Medium |
| status: | Triaged → Fix Committed |
To post a comment you must log in.

John has written a patch and sent it to the upstream AppArmor list:
https:/ /lists. ubuntu. com/archives/ apparmor/ 2014-October/ 006696. html
This patch now should be sent to the Ubuntu Kernel Team list for inclusion in the Ubuntu kernels.