[pkg-apparmor] Fwd: Re: aa-unconfined shows tor as being unconfined, aa-status says different

u u at 451f.org
Mon Feb 2 16:05:33 UTC 2015


Hi,

Christian Boltz:
> Am Montag, 2. Februar 2015 schrieb u:
>> While playing around with `aa-unconfined` i saw that /usr/bin/tor is
>> marked as not being confined.

> Does it work if you change aa-unconfined line 66? Untested pseudo-patch:
> -                if line.startswith("/") or line.startswith("null"):
> +               if line.strip() != "unconfined":

Actually, yes!
If I use your line, i get:

1609 /usr/bin/tor confined by 'system_tor (enforce)'

instead of

1609 /usr/bin/tor not confined

Best,
Ulrike



More information about the pkg-apparmor-team mailing list