Merge lp://qastaging/~sdeziel/apparmor-profiles/unbound-profile into lp://qastaging/apparmor-profiles

Proposed by Simon Déziel
Status: Superseded
Proposed branch: lp://qastaging/~sdeziel/apparmor-profiles/unbound-profile
Merge into: lp://qastaging/apparmor-profiles
Diff against target: 35 lines (+31/-0)
1 file modified
ubuntu/12.04/usr.sbin.unbound (+31/-0)
To merge this branch: bzr merge lp://qastaging/~sdeziel/apparmor-profiles/unbound-profile
Reviewer Review Type Date Requested Status
Jamie Strandboge Approve
Review via email: mp+83842@code.qastaging.launchpad.net

This proposal has been superseded by a proposal from 2011-11-30.

Description of the change

This adds a profile for Unbound. It supports chroot'ing (in /var/lib/unbound) as well as privilege downgrade.

To post a comment you must log in.
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

ACK. Thanks!

review: Approve
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Can you comment why this is needed:
  capability dac_override,

I added a note in the profile in the meantime.

76. By Simon Déziel

remove the useless dac_override capability (thanks Jamie for pointing this out)

77. By Simon Déziel

remove the useless chow capability

78. By Simon Déziel

Unify rules to cover chroot'ed and non-chroot'ed configurations..
Audit/deny write access to unbound_(control|server).key while still
allowing write access to *.key to support the "auto-trust-anchor-file"
mechanism.

79. By Simon Déziel

Merged master branch

80. By Simon Déziel

The pid creation requires the dac_override and chown capabilities. Thanks Felix for pointing this out.

81. By Simon Déziel

Authorize mmap'ing /etc/{passwd,group} as Unbound insists on this. Thanks Felix for pointing this out.

82. By Simon Déziel

The root.key handling is not perfect. Ideally, this file should reside in the chroot
jail but that's not possible until LP: #898287 is addressed. For now, lets allow to
write to the file when not chroot'ed (the default is to run without chroot anyways).

83. By Simon Déziel

Merged lp:apparmor-profiles

Unmerged revisions

Preview Diff

[H/L] Next/Prev Comment, [J/K] Next/Prev File, [N/P] Next/Prev Hunk
The diff is not available at this time. You can reload the page or download it.

Subscribers

People subscribed via source and target branches

to status/vote changes: