Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Install apparmor profiles in sd-svs-disp #118

Merged
merged 1 commit into from
Jan 3, 2020

Conversation

emkll
Copy link
Contributor

@emkll emkll commented Dec 20, 2019

closes freedomofpress/securedrop-workstation#384
This will ensure upstream apparmor profiles are installed and enforced. This includes profiles for:

  • libreoffice
  • totem
  • evince

It appears that in compat level 10 (default for buster), files are not copied to /etc . Since we want to automatically squash the paxctld configuration, let's move it to /opt and move in place to /etc in postinst.

Test plan

  • check out this branch
  • package successfully builds (PKG_VERSION=0.1.4 make securedrop-workstation-svs-disp)
  • move package to sd-svs-disp-buster-template and install package in that template (sudo apt-get -f install to resolve dependencies)
  • package installs successfully, sudo aa-status shows profiles
  • in sd-svs-disp, open a pdf in evince
  • evince apparmor profile is enforced for the process (when evince is open, sudo aa-status)

This will ensure upstream apparmor profiles are installed and enforced. This includes profiles for:
* libreoffice
* totem
* evince
@emkll emkll changed the title [wip] Install apparmor profiles in sd-svs-disp Install apparmor profiles in sd-svs-disp Dec 20, 2019
@emkll emkll marked this pull request as ready for review December 20, 2019 21:26
Copy link
Contributor

@kushaldas kushaldas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tested as

  • package successfully builds (PKG_VERSION=0.1.4 make securedrop-workstation-svs-disp)
  • move package to sd-svs-disp-buster-template and install package in that template (sudo apt-get -f install to resolve dependencies)
  • package installs successfully, sudo aa-status shows profiles
  • in sd-svs-disp, open a pdf in evince
  • evince apparmor profile is enforced for the process (when evince is open, sudo aa-status)

Works as suggested, the PR is good visually too.

@kushaldas kushaldas merged commit d562693 into master Jan 3, 2020
@kushaldas kushaldas deleted the 384-svs-disp-apparmor-profiles branch January 3, 2020 10:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Install upstream apparmor profiles in sd-svs-disp
2 participants