[ubuntu/plucky-proposed] apparmor 4.1.0~beta4-0ubuntu3 (Accepted)

Ryan Lee ryan.lee at canonical.com
Tue Feb 18 12:46:17 UTC 2025


apparmor (4.1.0~beta4-0ubuntu3) plucky; urgency=medium

  * Add patch to fix build path leaking into generated polkit file:
    - d/p/u/aa-notify-fix-packaging-polkit.patch
  * Add patch to enable environment variable overrides in utils Makefile:
    - d/p/u/utils-allow-install-locations-to-be-overridden-in-Make.patch

apparmor (4.1.0~beta4-0ubuntu2) plucky; urgency=medium

  * Add patch to fix libapparmor SWIG build on 32-bit systems:
    - d/p/u/libapparmor-swig-various-fixes-for-32-bit-and-older.patch
  * Add patch for aa-notify GUI fallback when python3-ttkthemes is
    unavailable:
    - d/p/u/aa-notify-ttkthemes-fallback-mr1324-partial.patch
  * Add patch with another new AppArmor profile for testing:
    - d/p/u/mosquitto_mr_1506.patch
  * debian/apparmor.install: add entry for the mosquitto profile
  * debian/control: remove python3-ttkthemes from Build-Depends to fix
    i386 build now that fallback is available

apparmor (4.1.0~beta4-0ubuntu1) plucky; urgency=medium

  * New upstream release.
  * Auto-refreshed patches via quilt refresh:
    - d/p/u/profiles-grant-access-to-systemd-resolved.patch
    - d/p/u/samba-systemd-interaction.patch
    - d/p/u/parser-fix-pam_apparmor-regression-test-failures.patch
  * Drop patches that were applied upstream:
    - d/p/u/utils-change-os.mkdir-to-self.mkpath-to-create-inter.patch
    - d/p/u/parser-fix-rule-priority-destroying-rule-permissions.patch
    - d/p/u/libapparmor-make-af_protos.h-consistent-in-different.patch
    - d/p/u/fix-abi-break-record-for-aa-log-record.patch
    - d/p/u/handle-missing-cgitb.patch
  * Drop patches that were superseded upstream:
    - d/p/u/parser-fix-integer-overflow-bug-in-rule-priority-com.patch
    - d/p/u/parser-revert-removal-of-second-minimization-pass.patch
    - d/p/u/parser-update-tsts-for-explicit-deny-and-filtering-c.patch
  * Add patches containing new AppArmor profiles for more testing:
    - d/p/u/znc_mr_1376.patch
    - d/p/u/tfntp_mr_1363.patch
    - d/p/u/socat_mr_1319.patch
    - d/p/u/rygel_mr_1311.patch
    - d/p/u/remmina_mr_1348.patch
    - d/p/u/lsusb_mr_1433.patch
    - d/p/u/lsblk_mr_1437.patch
    - d/p/u/mbsync_mr_1372.patch
    - d/p/u/openvpn_mr_1263.patch
    - d/p/u/tshark_mr_1384.patch
    - d/p/u/wireguard_mr_1323.patch
    - d/p/u/irssi_mr_1332.patch
    - d/p/u/netcat-openbsd_mr_1327.patch
    - d/p/u/tar_mr_1453.patch
    - d/p/u/alsamixer_mr_1517.patch
    - d/p/u/tinyproxy_mr_1477.patch
    - d/p/u/frr_mr_1380.patch
    - d/p/u/iotop_c_mr_1520.patch
    - d/p/u/wpa_supplicant_mr_1385.patch
    - d/p/u/fusermount3_mr_1514.patch
    - d/p/u/dnstracer_mr_1366.patch
  * Add a patch to enable the *-userns-restrict profiles by default:
    - d/p/u/Move-the-bwrap-userns-restrict-profile-out-of-extras.patch
    - d/p/u/Move the unshare-userns-restrict-profile-out-of-extras.patch
  * Add a patch that deletes the busybox and nautilus profiles:
    - d/p/u/delete-the-busybox-and-nautilus-profiles.patch
  * debian/apparmor.dirs: remove /lib/apparmor as it would already be
    created by the file installation process
  * debian/apparmor.install:
    - Install some files into /usr directory instead of under root
      directory (as per the /usr merge):
      - lib/apparmor/profile-load
      - sbin/apparmor_parser
      - parser/apparmor.systemd
      - lib/apparmor/rc.apparmor/functions
    - Install newly added profiles from profile patches above, with
      the exception of the socat profile (d/p/u/socat_mr_1319.patch)
    - Add installation of the *-userns-restrict profiles to install
      them to /etc/apparmor.d/
    - Remove entries for the busybox and nautilus profiles
  * debian/apparmor.manpages: add upstream aa-load.8 man page
  * debian/apparmor-profiles.install:
    - Add entry for new upstream postfix-tlsproxy profile
    - Add entry for the socat profile (d/p/u/socat_mr_1319.patch)
    - Remove entries for *-userns-restrict profiles (moved to debian/
      apparmor.install)
  * debian/control:
    - Add utils Build-Depends under a !nocheck condition for tests:
      - flake8
      - python3-gi
      - python3-notify2
      - python3-psutil
      - python3-tk
      - python3-ttkthemes
  * debian/rules:
    - override_dh_auto_build
      - No longer create libraries/libapparmor/testsuite/test_multi/
        testcase_mqueue_0[1-8].err empty files, as the patch they were
        supposed to accompany was applied upstream
    - override_dh_auto_test
      - Test libapparmor in override_dh-auto-test before the parser and
        binutils
      - Add step that runs tests for utils
    - override_dh_install-arch
      - Fixup chmod call for lib/apparmor/apparmor.systemd for /usr
        install location
  * debian/libpam-apparmor.install:
    - Install lib/security/pam_apparmor.so into /usr directory (as per
      the /usr merge)
  * debian/usr/lib/sysctl.d/10-apparmor.conf: Set sysctl
    kernel.apparmor_restrict_unprivileged_unconfined=1

Date: Thu, 13 Feb 2025 14:30:46 -0800
Changed-By: Ryan Lee <ryan.lee at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Alex Murray <alex.murray at canonical.com>
https://launchpad.net/ubuntu/+source/apparmor/4.1.0~beta4-0ubuntu3
-------------- next part --------------
Format: 1.8
Date: Thu, 13 Feb 2025 14:30:46 -0800
Source: apparmor
Built-For-Profiles: noudeb
Architecture: source
Version: 4.1.0~beta4-0ubuntu3
Distribution: plucky
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Ryan Lee <ryan.lee at canonical.com>
Changes:
 apparmor (4.1.0~beta4-0ubuntu3) plucky; urgency=medium
 .
   * Add patch to fix build path leaking into generated polkit file:
     - d/p/u/aa-notify-fix-packaging-polkit.patch
   * Add patch to enable environment variable overrides in utils Makefile:
     - d/p/u/utils-allow-install-locations-to-be-overridden-in-Make.patch
 .
 apparmor (4.1.0~beta4-0ubuntu2) plucky; urgency=medium
 .
   * Add patch to fix libapparmor SWIG build on 32-bit systems:
     - d/p/u/libapparmor-swig-various-fixes-for-32-bit-and-older.patch
   * Add patch for aa-notify GUI fallback when python3-ttkthemes is
     unavailable:
     - d/p/u/aa-notify-ttkthemes-fallback-mr1324-partial.patch
   * Add patch with another new AppArmor profile for testing:
     - d/p/u/mosquitto_mr_1506.patch
   * debian/apparmor.install: add entry for the mosquitto profile
   * debian/control: remove python3-ttkthemes from Build-Depends to fix
     i386 build now that fallback is available
 .
 apparmor (4.1.0~beta4-0ubuntu1) plucky; urgency=medium
 .
   * New upstream release.
   * Auto-refreshed patches via quilt refresh:
     - d/p/u/profiles-grant-access-to-systemd-resolved.patch
     - d/p/u/samba-systemd-interaction.patch
     - d/p/u/parser-fix-pam_apparmor-regression-test-failures.patch
   * Drop patches that were applied upstream:
     - d/p/u/utils-change-os.mkdir-to-self.mkpath-to-create-inter.patch
     - d/p/u/parser-fix-rule-priority-destroying-rule-permissions.patch
     - d/p/u/libapparmor-make-af_protos.h-consistent-in-different.patch
     - d/p/u/fix-abi-break-record-for-aa-log-record.patch
     - d/p/u/handle-missing-cgitb.patch
   * Drop patches that were superseded upstream:
     - d/p/u/parser-fix-integer-overflow-bug-in-rule-priority-com.patch
     - d/p/u/parser-revert-removal-of-second-minimization-pass.patch
     - d/p/u/parser-update-tsts-for-explicit-deny-and-filtering-c.patch
   * Add patches containing new AppArmor profiles for more testing:
     - d/p/u/znc_mr_1376.patch
     - d/p/u/tfntp_mr_1363.patch
     - d/p/u/socat_mr_1319.patch
     - d/p/u/rygel_mr_1311.patch
     - d/p/u/remmina_mr_1348.patch
     - d/p/u/lsusb_mr_1433.patch
     - d/p/u/lsblk_mr_1437.patch
     - d/p/u/mbsync_mr_1372.patch
     - d/p/u/openvpn_mr_1263.patch
     - d/p/u/tshark_mr_1384.patch
     - d/p/u/wireguard_mr_1323.patch
     - d/p/u/irssi_mr_1332.patch
     - d/p/u/netcat-openbsd_mr_1327.patch
     - d/p/u/tar_mr_1453.patch
     - d/p/u/alsamixer_mr_1517.patch
     - d/p/u/tinyproxy_mr_1477.patch
     - d/p/u/frr_mr_1380.patch
     - d/p/u/iotop_c_mr_1520.patch
     - d/p/u/wpa_supplicant_mr_1385.patch
     - d/p/u/fusermount3_mr_1514.patch
     - d/p/u/dnstracer_mr_1366.patch
   * Add a patch to enable the *-userns-restrict profiles by default:
     - d/p/u/Move-the-bwrap-userns-restrict-profile-out-of-extras.patch
     - d/p/u/Move the unshare-userns-restrict-profile-out-of-extras.patch
   * Add a patch that deletes the busybox and nautilus profiles:
     - d/p/u/delete-the-busybox-and-nautilus-profiles.patch
   * debian/apparmor.dirs: remove /lib/apparmor as it would already be
     created by the file installation process
   * debian/apparmor.install:
     - Install some files into /usr directory instead of under root
       directory (as per the /usr merge):
       - lib/apparmor/profile-load
       - sbin/apparmor_parser
       - parser/apparmor.systemd
       - lib/apparmor/rc.apparmor/functions
     - Install newly added profiles from profile patches above, with
       the exception of the socat profile (d/p/u/socat_mr_1319.patch)
     - Add installation of the *-userns-restrict profiles to install
       them to /etc/apparmor.d/
     - Remove entries for the busybox and nautilus profiles
   * debian/apparmor.manpages: add upstream aa-load.8 man page
   * debian/apparmor-profiles.install:
     - Add entry for new upstream postfix-tlsproxy profile
     - Add entry for the socat profile (d/p/u/socat_mr_1319.patch)
     - Remove entries for *-userns-restrict profiles (moved to debian/
       apparmor.install)
   * debian/control:
     - Add utils Build-Depends under a !nocheck condition for tests:
       - flake8
       - python3-gi
       - python3-notify2
       - python3-psutil
       - python3-tk
       - python3-ttkthemes
   * debian/rules:
     - override_dh_auto_build
       - No longer create libraries/libapparmor/testsuite/test_multi/
         testcase_mqueue_0[1-8].err empty files, as the patch they were
         supposed to accompany was applied upstream
     - override_dh_auto_test
       - Test libapparmor in override_dh-auto-test before the parser and
         binutils
       - Add step that runs tests for utils
     - override_dh_install-arch
       - Fixup chmod call for lib/apparmor/apparmor.systemd for /usr
         install location
   * debian/libpam-apparmor.install:
     - Install lib/security/pam_apparmor.so into /usr directory (as per
       the /usr merge)
   * debian/usr/lib/sysctl.d/10-apparmor.conf: Set sysctl
     kernel.apparmor_restrict_unprivileged_unconfined=1
Checksums-Sha1:
 2695a893fae1e336513f4b2eadfdb7f90a66a926 3444 apparmor_4.1.0~beta4-0ubuntu3.dsc
 551f79315b2544bf7b2bf561e7d4b8e14bff616b 7071731 apparmor_4.1.0~beta4.orig.tar.gz
 3a63be65ef57c8e00ccdf5cb883389e9b503fdb3 870 apparmor_4.1.0~beta4.orig.tar.gz.asc
 0a720034ea3359cd7f8296fffefc5239e2bcbde4 116228 apparmor_4.1.0~beta4-0ubuntu3.debian.tar.xz
 d0afbc99f2050088189151c8f55b5ca5b5af4e00 9906 apparmor_4.1.0~beta4-0ubuntu3_source.buildinfo
Checksums-Sha256:
 42525d552f8d9a8c3f561ca03d38970827e58cfba82c5dabb08f1f63f0ec9159 3444 apparmor_4.1.0~beta4-0ubuntu3.dsc
 57ae4d1fc96a46461a6bb9e7341bf24b2f85bcd9dd2681894364e53caefb5315 7071731 apparmor_4.1.0~beta4.orig.tar.gz
 025efd473f7158573d4e20e015b5d3fc20d67cff8a8b3096daece38ba6e04f85 870 apparmor_4.1.0~beta4.orig.tar.gz.asc
 e9abb0641f87d6074643aa174548779bdab0a5ac811307e8ead762abba1ba9ff 116228 apparmor_4.1.0~beta4-0ubuntu3.debian.tar.xz
 cde325d6be222a99bddb8f5be70e3030281a28bf696015ece1293dbf57fd9438 9906 apparmor_4.1.0~beta4-0ubuntu3_source.buildinfo
Files:
 a40f41a66d573a34a865007214cd44db 3444 admin optional apparmor_4.1.0~beta4-0ubuntu3.dsc
 2cbe9e3a7b9ddd5f7025ce884f537173 7071731 admin optional apparmor_4.1.0~beta4.orig.tar.gz
 70bb85539aa3444853aedea0fd436392 870 admin optional apparmor_4.1.0~beta4.orig.tar.gz.asc
 092958f9a32245e83a277a81cbbc90a0 116228 admin optional apparmor_4.1.0~beta4-0ubuntu3.debian.tar.xz
 8996dd468f5f41ec6036cf644b69f23b 9906 admin optional apparmor_4.1.0~beta4-0ubuntu3_source.buildinfo
Original-Maintainer: Debian AppArmor Team <pkg-apparmor-team at lists.alioth.debian.org>


More information about the plucky-changes mailing list