[ubuntu-hardened] a question
Seth Arnold
seth.arnold at canonical.com
Thu Dec 12 07:40:36 UTC 2013
On Thu, Dec 12, 2013 at 08:07:10AM +0100, js at johest.de wrote:
> Yep, debfx pointed me to the page yesterday in the chat, and i took
> some of his code cause it looked good :-)
> Or looked at that stage better then mine.
Yeah, debfx does good work :)
> i just switched apparmor to complain mode and so took all the used
> files from the syslog. Even with the abstract rules above it still
> complained about the files i added below than.
Normally, in complain mode, AppArmor will not log a request that is
already allowed in the policy. If you can get this to happen reliably,
we should fix that. :) I _suspect_ that you might have found those
accesses with an earlier version of your policy that did not include
<abstractions/base> -- but mostly because I have trouble explaining the
events otherwise.
Thanks
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 490 bytes
Desc: Digital signature
URL: <https://lists.ubuntu.com/archives/ubuntu-hardened/attachments/20131211/f117859f/attachment.pgp>
More information about the ubuntu-hardened
mailing list