mirror of
synced 2025-03-04 00:14:44 +01:00
(11:01:49 AM) jjohansen: cboltz, georgiag, sbeattie, sarnold, anyone else who is interested meeting time
(11:02:05 AM) ***georgiag is here
(11:02:21 AM) ***cboltz hides in a comment for !1109
(11:02:33 AM) ***sbeattie is here as well.
(11:03:00 AM) jjohansen: cboltz: well if its in !1109 /me won't look and won't find you ;)
(11:03:23 AM) cboltz: ;-)
(11:03:43 AM) jjohansen: we have nothing on the agenda, so its wing it as usual
(11:04:49 AM) cboltz: let me continue a topic from the last meeting - !1095 (fine grained network)
(11:05:23 AM) cboltz: I see the tests were all updated to network peer=(ip= port=)
(11:05:25 AM) jjohansen: shoot, that is not !1109 so I guess ...
(11:05:57 AM) cboltz: that's fine, but I wonder if there's also a way to specify the local port (might be useful especial when a daemon listens on that port)
(11:06:21 AM) jjohansen: yes, the plan is to be able to specify the local port on service rules
(11:06:44 AM) cboltz: jjohansen: no worries, I already put two questions to 1109 ;-)
(11:06:45 AM) jjohansen: maybe on other rules but definitely on service rules
(11:06:57 AM) darix: I want more px rules. And secmark. Pretty please
(11:07:43 AM) cboltz: darix: IIRC your first wish (allowing more px targets) is already possible in 4.0
(11:07:53 AM) cboltz: if you want to test - home:cboltz:aa4 has packages
(11:08:05 AM) jjohansen: darix: more px rules are coming (2^24 possible), they exist in 6.2+, we still need to land support in the parser for the 4.0 release
(11:08:36 AM) cboltz: ok, then I was a bit ahead of time ;-)
(11:08:39 AM) jjohansen: secmark is coming as well, but we may not land it for 4.0
(11:09:14 AM) jjohansen: it just depends on how the next couple of weeks go
(11:09:41 AM) jjohansen: we would like to have network stuff up for people to test, and report bugs etc in the next couple of weeks
(11:09:51 AM) darix: Jj I am sure curl won’t keep us busy much
(11:10:03 AM) jjohansen: sooner the better, but well interrupts seem to be constant
(11:10:21 AM) jjohansen: :)
(11:11:37 AM) jjohansen: as for 4.0, we are back to working on it (largely the networking side atm) and hope to do the next alpha the week of 22-28
(11:12:17 AM) jjohansen: Ideally that will be the last alpha and we will have a beta in early November
(11:13:48 AM) jjohansen: in addition to the network stuff we have the compiler fixes/improvements to land that let us take advantage of the extended perms
(11:14:04 AM) jjohansen: so increased px rules ...
(11:15:40 AM) jjohansen: we have another new flag addition https://gitlab.com/apparmor/apparmor/-/merge_requests/1109
(11:16:45 AM) cboltz: since you begged for it ;-) I'll repeat my question from that MR here: what's the difference between this flag and a profile with an all, rule?
(11:17:10 AM) jjohansen: syntax is not finalized so feedback is welcome. It is meant to replace the use of the unconfined flag for ubuntu as ubuntu has recently picked up several dozen profiles that use it, and long term they really should be functional profiles instead of these weird hybrids
(11:18:20 AM) jjohansen: cboltz: ah, I hadn't noticed the question. Functionally nothing, but I don't want to carry the delta in just ubuntu
(11:18:55 AM) cboltz: can't Ubuntu just use the all, rule in these profiles?
(11:19:02 AM) jjohansen: that is to so Ubuntu is picking up the flag for various reasons, and I want to make sure policy stays compatible
(11:19:17 AM) jjohansen: atm no
(11:19:41 AM) cboltz: so we now get a second way to do something that is not recommended? ;-)
(11:20:51 AM) jjohansen: sigh, yeah. Its not ideal but its better than the proliferation of the unconfined mode which while useful for debugggin is planned to be phased out
(11:21:08 AM) jjohansen: as we are working on removing unconfined as a special entity kernel side
(11:21:46 AM) jjohansen: this means simpler code, and mediation for every profile gets some performance lift when possible
(11:22:18 AM) jjohansen: eventually the unconfined flag will map to a special default allow profile
(11:22:54 AM) jjohansen: and the unconfined profile will be replaceable
(11:24:38 AM) jjohansen: do we have anything else to discuss?
(11:26:02 AM) cboltz: nothing from me
(11:27:39 AM) sbeattie: not from me
(11:27:46 AM) georgiag: me neither
(11:28:45 AM) jjohansen: alright, the plan is to skip the November meeting unless something urgent comes up, so next meeting is Dec 12, same time (utc) and place
(11:28:54 AM) jjohansen: meeting adjourned
(11:28:57 AM) jjohansen: thanks everyone