[Bug 208141] New: AppArmor and symlinked directories
https://bugzilla.novell.com/show_bug.cgi?id=208141 Summary: AppArmor and symlinked directories Product: openSUSE 10.2 Version: Alpha 4 plus Platform: Other OS/Version: Other Status: NEW Severity: Enhancement Priority: P5 - None Component: AppArmor AssignedTo: dreynolds@novell.com ReportedBy: suse-beta@cboltz.de QAContact: dreynolds@novell.com AppArmor has a problem with symlinked directories: It always uses the symlink target when matching the ruleset. The same happens for mount --bind mounted directories. This means you have to change lots of profiles if you symlink /tmp to /var/roottmp for example. I'd like to see an option to allow symlinks and mount --bind - of course with a well-defined list of allowed symlinks to keep it secure. For example, there could be a global config file with something like Alias /tmp /var/roottmp which basically has the same results as changing the /tmp directory in all profiles, but with less work (which would probably also be less error-prone). (Variables don't really do this job - people can move and symlink nearly every directory.) (This was discussed on apparmor-general some weeks ago: http://forge.novell.com/pipermail/apparmor-general/2006-August/000120.html ) -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=208141 ------- Comment #1 from andreas.hanke@gmx-topmail.de 2006-09-25 16:55 MST ------- *** Bug 208142 has been marked as a duplicate of this bug. *** -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=208141 seth.arnold@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution| |INVALID ------- Comment #2 from seth.arnold@novell.com 2007-02-21 16:26 MST ------- FATE #302009: AppArmor centralized "symlink" handling It won't be easy to implement, so product management should be allowed to raise/lower priority as they wish. Thanks -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
participants (1)
-
bugzilla_noreply@novell.com