/srv/irclogs.ubuntu.com/2024/08/30/#ubuntu-devel.txt

vpa1977@pilot out02:15
=== ChanServ changed the topic of #ubuntu-devel to: Archive: Feature Freeze | Devel of Ubuntu (not support) | Build failures: http://qa.ubuntuwire.com/ftbfs/ | #ubuntu for support and discussion of Focal-Noble | Patch Pilots: vorlon
fheimes_hello, could an #archive-admins please approve https://launchpad.net/ubuntu/+source/s390-tools/2.34.0-0ubuntu2 for s390x (needed due to signing) - ty08:41
=== utkarsh40 is now known as utkarsh2102
arraybolt3georgiag: so I'm guessing the profile is *not* loaded. This is in a live session.16:50
georgiagarraybolt3: ah, that's exactly why then. apparmor doesn't load the profiles in a live session16:50
arraybolt3aha16:50
arraybolt3I assume that's done intentionally, could I inquire why?16:51
georgiagwe didn't want apparmor blocking anything on a live image... but that's becomes an issue for the userns restriction that we never addressed16:52
arraybolt3mmm16:52
arraybolt3so it was meant to avoid blocking things but now it is blocking things.16:52
arraybolt3how badly could it backfire to just go ahead and load the profiles anyway?16:52
* arraybolt3 attempts said stunt in a VM16:53
arraybolt3doing that doesn't seem to immediately make anything go haywire, but the evolution profile now shows up and Evolution launches.16:54
georgiagarraybolt3: there's been some discussion in https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/206508816:54
-ubottu:#ubuntu-devel- Launchpad bug 2065088 in apparmor (Ubuntu) "AppArmor profiles allowing userns not immediately active in 24.04 live image" [Undecided, Confirmed]16:54
arraybolt3georgiag: added an idea to that bug, to me it seems like if the goal is to keep AppArmor from doing much of anything on the live ISO, just disable the user namespace restrictions too. The release notes have instructions on how to do so.17:00
arraybolt3tl;dr: ``echo 0 | sudo tee /proc/sys/kernel/apparmor_restrict_unprivileged_userns``17:00
=== utkarsh34 is now known as utkarsh2102
=== matttbe1 is now known as matttbe

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!