[apparmor] Bug#735470: Fwd: Bug#735470: Could be implemented centrally with a dpkg trigger instead of requiring every package shipping an apparmor file to use dh_apparmor
Didier 'OdyX' Raboud
odyx at debian.org
Thu Jan 16 18:37:04 UTC 2014
Le jeudi, 16 janvier 2014 10.14:14, vous avez écrit :
> On Thu, Jan 16, 2014 at 11:11:22AM +0100, Didier 'OdyX' Raboud wrote:
> > As far as I understand deb-triggers' manpage, this can be enforced
> > using 'activate /etc/apparmor.d/', which will then make the trigger
> > run "at the start of the configure operation", which ensures
> > exactly what you want.
>
> Per-policy reloads must happen before a daemon restarts, so they
> cannot be triggers.
Err…
man deb-trigggers contradicts you, in my reading; an 'activate
/etc/apparmor.d' triggers' file in apparmor would make its action run
_before_ cups (which would have shipped /etc/apparmor.d/usr.sbin.cupsd)
would be 'configured' (hence its postinst run).
Isn't it?
Anyway, I now intend to try to implement this, just out of curiosity…
I'll report to this bug with my attempts, may they happen.
Cheers,
OdyX
More information about the AppArmor
mailing list