Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
FS#54637 - [linux-hardened] Apparmor support
Attached to Project:
Community Packages
Opened by Dimos Dimoulis (dimosd) - Thursday, 29 June 2017, 11:57 GMT
Last edited by Daniel Micay (thestinger) - Thursday, 29 June 2017, 18:21 GMT
Opened by Dimos Dimoulis (dimosd) - Thursday, 29 June 2017, 11:57 GMT
Last edited by Daniel Micay (thestinger) - Thursday, 29 June 2017, 18:21 GMT
|
Detailslinux-hardened currently includes support for SELinux. Since more than one MAC can be built in the kernel and one of them enabled at boot time, I would like to ask for Apparmor to be included as well, as an option.
|
This task depends upon
Closed by Daniel Micay (thestinger)
Thursday, 29 June 2017, 18:21 GMT
Reason for closing: Won't implement
Additional comments about closing: The chosen path is integrating SELinux, not AppArmor, which isn't capable replacing previously available features. It's intentional that the extremely limited resources are being directed towards supporting only one choice. If you want that to change, make substantial contributions to reduce the existing workload.
Thursday, 29 June 2017, 18:21 GMT
Reason for closing: Won't implement
Additional comments about closing: The chosen path is integrating SELinux, not AppArmor, which isn't capable replacing previously available features. It's intentional that the extremely limited resources are being directed towards supporting only one choice. If you want that to change, make substantial contributions to reduce the existing workload.
Comment by Daniel Micay (thestinger) -
Thursday, 29 June 2017, 18:17 GMT
I don't plan on enabling it because I don't want to fragment the minimal amount of time and interest among multiple MAC systems.