[apparmor] Bug#735470: Fwd: Bug#735470: Could be implemented centrally with a dpkg trigger instead of requiring every package shipping an apparmor file to use dh_apparmor

Didier 'OdyX' Raboud odyx at debian.org
Thu Jan 16 18:37:04 UTC 2014

Le jeudi, 16 janvier 2014 10.14:14, vous avez écrit :
> On Thu, Jan 16, 2014 at 11:11:22AM +0100, Didier 'OdyX' Raboud wrote:
> > As far as I understand deb-triggers' manpage, this can be enforced
> > using 'activate /etc/apparmor.d/', which will then make the trigger
> > run "at the start of the configure operation", which ensures
> > exactly what you want.
> Per-policy reloads must happen before a daemon restarts, so they
> cannot be triggers.


man deb-trigggers contradicts you, in my reading; an 'activate 
/etc/apparmor.d' triggers' file in apparmor would make its action run 
_before_ cups (which would have shipped /etc/apparmor.d/usr.sbin.cupsd) 
would be 'configured' (hence its postinst run).

Isn't it?

Anyway, I now intend to try to implement this, just out of curiosity… 
I'll report to this bug with my attempts, may they happen.



More information about the AppArmor mailing list