Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upenable AppArmor by default #4088
Comments
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
adrelanos
Jul 16, 2018
Member
In case this is a no or inconclusive I would back up to a separate ticket enable AppArmor by default for Qubes-Whonix.
For Whonix it's sane to enable AppArmor by default since we don't ship AppArmor profiles by default which have potential to break in bad ways. (Such as for Tor Browser which has its own updater so Tor Browser might rush ahead and do things which are not covered by apparmor-profile-torbrowser.) We only ship AppArmor profiles for packages which are upgraded through Debian apt package management which undergo testing before flowing into the stable repository (such as for Tor, sdwdate, ...).
AppArmor enabled by default in Non-Qubes-Whonix for many releases.
Package https://github.com/Whonix/grub-enable-apparmor only works when using VM kernel.
Related:
|
In case this is a For Whonix it's sane to enable AppArmor by default since we don't ship AppArmor profiles by default which have potential to break in bad ways. (Such as for Tor Browser which has its own updater so Tor Browser might rush ahead and do things which are not covered by apparmor-profile-torbrowser.) We only ship AppArmor profiles for packages which are upgraded through Debian apt package management which undergo testing before flowing into the stable repository (such as for Tor, sdwdate, ...). AppArmor enabled by default in Non-Qubes-Whonix for many releases. Package https://github.com/Whonix/grub-enable-apparmor only works when using VM kernel. Related: |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
marmarek
Jul 16, 2018
Member
What is the plan regarding 'VM kernel by default'?
For now it is blocked by being incompatible with PVH :/
For now it is blocked by being incompatible with PVH :/ |
andrewdavidwong
added
enhancement
C: templates
security
labels
Jul 17, 2018
andrewdavidwong
added this to the Release 4.1 milestone
Jul 17, 2018
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
lunarthegrey
Jul 19, 2018
AppArmor works good in my PVH VMs, been using it for a while now. I don't think it's installed by default in the Debian template if I can remember correctly.
lunarthegrey
commented
Jul 19, 2018
|
AppArmor works good in my PVH VMs, been using it for a while now. I don't think it's installed by default in the Debian template if I can remember correctly. |
adrelanos commentedJul 16, 2018
Technically, add
apparmor=1 security=apparmortokernelopts.For Debian templates I don't foresee any issues. For Whonix templates I foresee even less issues. Other templates, no idea.
What is the plan regarding 'VM kernel by default'?
(I am not advocating either dom0 or VM kernel. Just asking.)