Project

General

Profile

Feature #6198

Feature #5370: AppArmor confinement

Have AppArmor support stacked filesystems

Added by intrigeri about 6 years ago. Updated almost 5 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
-
Target version:
Start date:
07/27/2013
Due date:
08/24/2014
% Done:

100%

Feature Branch:
Type of work:
Code
Blueprint:
Starter:
No
Affected tool:

Description

The current plan is to use aliases as a workaround, see https://bugs.launchpad.net/apparmor/+bug/888077


Subtasks

Feature #6199: Test AppArmor aliases patchResolvedintrigeri

Feature #6201: Wait for fixed AppArmor alias patchRejectedintrigeri

History

#1 Updated by intrigeri over 5 years ago

  • Target version set to Hardening_M1

#2 Updated by intrigeri over 5 years ago

  • Target version changed from Hardening_M1 to Sustainability_M1

#3 Updated by intrigeri about 5 years ago

#4 Updated by intrigeri almost 5 years ago

  • Blocks deleted (Feature #5385: Have 3 AppArmor profiles in enforce mode)

#5 Updated by intrigeri almost 5 years ago

#9 Updated by intrigeri almost 5 years ago

  • Status changed from Confirmed to Resolved

As explained in our design doc:

  • the alias rules way was actually not the best option;
  • it is actually doable to support AppArmor in Tails, without alias rules nor special support from upstream.

So I'm calling this done.

Also available in: Atom PDF