Bug 588185 - AppArmor: network rule
Summary: AppArmor: network rule
Status: RESOLVED FIXED
Alias: None
Product: openSUSE 11.2
Classification: openSUSE
Component: AppArmor (show other bugs)
Version: Final
Hardware: x86 openSUSE 11.2
: P5 - None : Normal (vote)
Target Milestone: ---
Assignee: Jeff Mahoney
QA Contact: E-mail List
URL:
Whiteboard: .
Keywords:
Depends on:
Blocks:
 
Reported: 2010-03-13 19:08 UTC by Matwey Kornilov
Modified: 2016-04-15 10:54 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matwey Kornilov 2010-03-13 19:08:01 UTC
User-Agent:       Mozilla/5.0 (X11; U; Linux i686; ru; rv:1.9.1.8) Gecko/20100204 SUSE/3.5.8-0.1.1 Firefox/3.5.8


I suppose that there is a bug in AppArmor 2.3.1(bundled with opensuse 11.2). The 'network' rule is described in man page and openSUSE Security Guide for 11.2, but It doesn't work for me at all. Network connections aren't blocked and there aren't 'socket_create' messages in my /var/log/audit.log. 

I created threads in forum and some users confirmed the AppArmor behavior:

http://forums.opensuse.org/applications/434684-apparmor-network-rule.html
http://forums.novell.com/novell-product-support-forums/apparmor/404069-apparmor-network-rule.html

Reproducible: Always
Comment 1 Jeff Mahoney 2010-03-15 15:34:59 UTC
This is a documentation error. The kernel doesn't call security hooks for anything other than inet or inet6 and apparmor-parser denies these keywords accordingly.

AppArmor itself _could_ support them, but since the hooks aren't called, it doesn't have the opportunity to do so. I'll update the manpage for factory.
Comment 2 Jeff Mahoney 2010-03-15 15:59:52 UTC
Scratch that. There was a build issue with apparmor-parser that caused it to miss the domain definitions. It's a bug.

Thanks for the report.
Comment 3 Jeff Mahoney 2010-03-15 19:37:32 UTC
I've committed the fix for this to security:apparmor:factory, openSUSE 11.2, and SLE11 SP1.

Anja, I have three fixes queued up for apparmor-parser. SR 34867
Comment 5 Swamp Workflow Management 2010-03-18 18:10:50 UTC
The SWAMPID for this issue is 32010.
Please submit the patch and patchinfo file using this ID.
(https://swamp.suse.de/webswamp/wf/32010)
Comment 6 Swamp Workflow Management 2010-04-06 11:53:47 UTC
Update released for: apparmor-parser, apparmor-parser-debuginfo, apparmor-parser-debugsource, apparmor-utils
Products:
openSUSE 11.2 (debug, i586, x86_64)
Comment 7 Jeff Mahoney 2010-12-01 14:29:35 UTC
Closing as FIXED.
Comment 8 Bernhard Wiedemann 2016-04-15 10:54:20 UTC
This is an autogenerated message for OBS integration:
This bug (588185) was mentioned in
https://build.opensuse.org/request/show/34867 11.2:Test / apparmor-parser