[ubuntu/noble-proposed] apparmor 4.0.0~alpha4-0ubuntu1 (Accepted)

Georgia Garcia georgia.garcia at canonical.com
Thu Feb 8 05:26:10 UTC 2024


apparmor (4.0.0~alpha4-0ubuntu1) noble; urgency=medium

  [Georgia Garcia]
  * New upstream release.
  * Add unconfined profiles to support the use unprivileged user namespace
    (LP: #2052297, LP: #2046844)
    - d/p/u/add-keybase-unconfined-profile.patch
    - d/p/u/add-more-unconfined-profiles.patch
  * Fix regression tests failures on regex.sh, exec.sh and userns.sh
    - d/p/u/tests-fix-usr-merge-failures-on-exec-and-regex-tests.patch
    - d/p/u/tests-handle-unprivileged_userns-transition-in-usern.patch
  * Drop patches which have now been applied upstream
    - d/p/u/userns-unconfined-profiles.patch
    - d/p/u/tests-fix-userns-setns-opening-pipe-order.patch
    - d/p/u/tests-replace-individual-socket-permissions.patch
    - d/p/u/tests-fix-test-specifying-path-on-attach-disconnected.patch
    - d/p/u/binutils-aa_status.c-quiet-verbose-outputs-when-json.patch
    - d/p/u/oot-unconfined-profiles.patch
  * Refresh patches
    - d/p/d/etc-writable.patch
    - d/p/u/profiles-grant-access-to-systemd-resolved.patch
    - d/p/u/userns-runtime-disable.patch
  * d/apparmor.install
    - install new profiles
      - plasmashell
      - surfshark
      - unprivileged_userns
      - keybase
      - devhelp
      - epiphany
      - evolution
      - opam
    - renamed profiles
      - ch-checkns
      - ch-run
      - crun
      - flatpak
      - linux-sandbox
      - busybox
      - buildah
      - cam
      - ipa_verify
      - lc-compliance
      - libcamerify
      - qcam
      - podman
      - lxc-attach
      - lxc-create
      - lxc-destroy
      - lxc-execute
      - lxc-stop
      - lxc-unshare
      - lxc-usernsexec
      - mmdebstrap
      - vpnns
      - QtWebEngineProcess
      - systemd-coredump
      - rootlesskit
      - rpm
      - runc
      - virtiofsd
      - sbuild
      - sbuild-abort
      - sbuild-adduser
      - sbuild-apt
      - sbuild-checkpackages
      - sbuild-clean
      - sbuild-createchroot
      - sbuild-destroychroot
      - sbuild-distupgrade
      - sbuild-hold
      - sbuild-shell
      - sbuild-unhold
      - sbuild-update
      - sbuild-upgrade
      - slirp4netns
      - stress-ng
      - thunderbird
      - toybox
      - trinity
      - tup
      - userbindmount
      - uwsgi-core
      - vdens
      - chrome
      - msedge
      - brave
      - vivaldi-bin
  * d/apparmor.maintscript
    - add renamed profiles so they are removed on upgrade
  * d/libapache2-mod-apparmor.install
    - remove etc/apparmor.d/local/usr.sbin.apache2, no longer needed

  [John Johansen]
  * debian/rules:
    - don't run debian/put-all-profiles-in-complain-mode.sh on install

  [Alex Murray]
  * debian/apparmor.lintian-overrides:
    - suppress false-positive warning about needing a Depends: on adduser
      for the apparmor binary package

Date: Fri, 02 Feb 2024 16:12:21 -0300
Changed-By: Georgia Garcia <georgia.garcia at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Alex Murray <alex.murray at canonical.com>
https://launchpad.net/ubuntu/+source/apparmor/4.0.0~alpha4-0ubuntu1
-------------- next part --------------
Format: 1.8
Date: Fri, 02 Feb 2024 16:12:21 -0300
Source: apparmor
Built-For-Profiles: noudeb
Architecture: source
Version: 4.0.0~alpha4-0ubuntu1
Distribution: noble
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Georgia Garcia <georgia.garcia at canonical.com>
Launchpad-Bugs-Fixed: 2046844 2052297
Changes:
 apparmor (4.0.0~alpha4-0ubuntu1) noble; urgency=medium
 .
   [Georgia Garcia]
   * New upstream release.
   * Add unconfined profiles to support the use unprivileged user namespace
     (LP: #2052297, LP: #2046844)
     - d/p/u/add-keybase-unconfined-profile.patch
     - d/p/u/add-more-unconfined-profiles.patch
   * Fix regression tests failures on regex.sh, exec.sh and userns.sh
     - d/p/u/tests-fix-usr-merge-failures-on-exec-and-regex-tests.patch
     - d/p/u/tests-handle-unprivileged_userns-transition-in-usern.patch
   * Drop patches which have now been applied upstream
     - d/p/u/userns-unconfined-profiles.patch
     - d/p/u/tests-fix-userns-setns-opening-pipe-order.patch
     - d/p/u/tests-replace-individual-socket-permissions.patch
     - d/p/u/tests-fix-test-specifying-path-on-attach-disconnected.patch
     - d/p/u/binutils-aa_status.c-quiet-verbose-outputs-when-json.patch
     - d/p/u/oot-unconfined-profiles.patch
   * Refresh patches
     - d/p/d/etc-writable.patch
     - d/p/u/profiles-grant-access-to-systemd-resolved.patch
     - d/p/u/userns-runtime-disable.patch
   * d/apparmor.install
     - install new profiles
       - plasmashell
       - surfshark
       - unprivileged_userns
       - keybase
       - devhelp
       - epiphany
       - evolution
       - opam
     - renamed profiles
       - ch-checkns
       - ch-run
       - crun
       - flatpak
       - linux-sandbox
       - busybox
       - buildah
       - cam
       - ipa_verify
       - lc-compliance
       - libcamerify
       - qcam
       - podman
       - lxc-attach
       - lxc-create
       - lxc-destroy
       - lxc-execute
       - lxc-stop
       - lxc-unshare
       - lxc-usernsexec
       - mmdebstrap
       - vpnns
       - QtWebEngineProcess
       - systemd-coredump
       - rootlesskit
       - rpm
       - runc
       - virtiofsd
       - sbuild
       - sbuild-abort
       - sbuild-adduser
       - sbuild-apt
       - sbuild-checkpackages
       - sbuild-clean
       - sbuild-createchroot
       - sbuild-destroychroot
       - sbuild-distupgrade
       - sbuild-hold
       - sbuild-shell
       - sbuild-unhold
       - sbuild-update
       - sbuild-upgrade
       - slirp4netns
       - stress-ng
       - thunderbird
       - toybox
       - trinity
       - tup
       - userbindmount
       - uwsgi-core
       - vdens
       - chrome
       - msedge
       - brave
       - vivaldi-bin
   * d/apparmor.maintscript
     - add renamed profiles so they are removed on upgrade
   * d/libapache2-mod-apparmor.install
     - remove etc/apparmor.d/local/usr.sbin.apache2, no longer needed
 .
   [John Johansen]
   * debian/rules:
     - don't run debian/put-all-profiles-in-complain-mode.sh on install
 .
   [Alex Murray]
   * debian/apparmor.lintian-overrides:
     - suppress false-positive warning about needing a Depends: on adduser
       for the apparmor binary package
Checksums-Sha1:
 9ea98082c2b6578428380766e50ebb7d755de914 3048 apparmor_4.0.0~alpha4-0ubuntu1.dsc
 35e1d0418f2a9137287eb1b3b89f61f8aa1d8f6d 6957671 apparmor_4.0.0~alpha4.orig.tar.gz
 fab1990406c80a9f30d5c0ad7690ac4578854983 97568 apparmor_4.0.0~alpha4-0ubuntu1.debian.tar.xz
 7f347db239881c3e1c31bbf0698380e455bfe97a 8758 apparmor_4.0.0~alpha4-0ubuntu1_source.buildinfo
Checksums-Sha256:
 35b7d7a8758f199241d6fef97ccb632d7e24936a0e9a0c1e6f15bcc6d411e776 3048 apparmor_4.0.0~alpha4-0ubuntu1.dsc
 03782c2417c0584e2ca9417cad651617de28792d419c90b7d271b5eedc654d5c 6957671 apparmor_4.0.0~alpha4.orig.tar.gz
 dd796a180b81dca8f79849009a6bf4fe3b34e57bc48c7a25f9f5723dc7271a25 97568 apparmor_4.0.0~alpha4-0ubuntu1.debian.tar.xz
 73efe765883ce784ae55932055f92a00beb060379acd45c6ce4f30fa343829d3 8758 apparmor_4.0.0~alpha4-0ubuntu1_source.buildinfo
Files:
 9e2ad1286eaf60fc0176b625ebb7f39e 3048 admin optional apparmor_4.0.0~alpha4-0ubuntu1.dsc
 d87bc59d8819a3a6bdd05dca1403f03e 6957671 admin optional apparmor_4.0.0~alpha4.orig.tar.gz
 22dff799562e41d2c9419687523464d0 97568 admin optional apparmor_4.0.0~alpha4-0ubuntu1.debian.tar.xz
 03fd0ac933d728d9690a8a1567307cf6 8758 admin optional apparmor_4.0.0~alpha4-0ubuntu1_source.buildinfo
Original-Maintainer: Debian AppArmor Team <pkg-apparmor-team at lists.alioth.debian.org>


More information about the noble-changes mailing list