mirror of
https://gitlab.com/apparmor/apparmor.git
synced 2025-03-04 00:14:44 +01:00
1
IRC_meeting_2024 01 09
John Johansen edited this page 2024-01-09 18:28:47 +00:00
(10:01:32 AM) jjohansen: cboltz, sarnold, sbeattie, georgiag:meeting time
(10:01:38 AM) ***georgiag is here
(10:02:04 AM) ***cboltz hides in another meeting, but will do multitasking
(10:02:27 AM) jjohansen: not sure the is much to multi-task about
(10:02:53 AM) jjohansen: we currently have nothing on the agenda, so I will give a quick update
(10:03:31 AM) jjohansen: we are behind (as always) on apparmor 4, we really can't slip anymore so we are looking at having to cut
(10:03:46 AM) jjohansen: just what exactly, I am not sure
(10:04:22 AM) jjohansen: at the moment I am trying to sort out some issues around unprivileged user namespace mediation
(10:05:49 AM) jjohansen: this is currently ubuntu specific and I doubt it will make the 4.0 release, because Ubuntu is currently relying on some kernel patches to hard code certain behaviors. For upstream we want to make the restriction through policy
(10:06:13 AM) jjohansen: which means bringing the conditions that are hardcoded in the kernel to policy
(10:06:50 AM) jjohansen: we will see some of this work land in 4.0 but some of it just won't make it before the deadline, eg. replacement of unconfined
(10:07:31 AM) jjohansen: the plan is anything that misses is a 4.1 feature
(10:08:26 AM) jjohansen: for networking, we are still working on it, and hopefully we will have the time to get it up for testing in the next week or two
(10:09:28 AM) jjohansen: the move_mount regression has been addressed in 6.7 kernel, and will begin working its way back to stable kernels
(10:09:55 AM) jjohansen: hopefully this will go smooth
(10:11:02 AM) jjohansen: unfortunately it can lead to breakage, when something that is confined is mediating mount, and doesn't have rules covering the move_mount
(10:11:34 AM) jjohansen: policy has to be updated, that is unfortunately the only fix
(10:11:56 AM) jjohansen: we don't have a wiki page up documenting this, but we will work on it
(10:12:42 AM) jjohansen: network, and improvements to userns mediation are the current priorities for 4.0 development
(10:13:17 AM) jjohansen: and how much more time they take will govern how much time we have for other features that were planned
(10:14:34 AM) jjohansen: we are open to requests for prioritization of the remaining features, no promises though
(10:14:44 AM) jjohansen: I don't have anything else
(10:15:00 AM) jjohansen: does anyone have something they would like to raise?
(10:15:08 AM) cboltz: thanks for the update!
(10:15:43 AM) cboltz: do you have plans for 3.x releases? There have been quite some fixes since the last release
(10:17:14 AM) jjohansen: no specific plans, we do want to get new releases out soon, I have a patch for detached mounts I would like to be considered for backport, since the move_mount regression is going to be pulled back into stable kernels
(10:18:04 AM) cboltz: "soon" would be nice, but (assuming your patch doesn't take too long) we can wait for that
(10:18:15 AM) jjohansen: I would like to see 3.x release updates before the 4.0 release
(10:18:58 AM) jjohansen: the patch isn't big, I just need to add a couple more cases, it should happen this week
(10:19:50 AM) cboltz: ok
(10:21:59 AM) jjohansen: do anyone have any other issues to bring up?
(10:23:41 AM) cboltz: nothing from me
(10:23:57 AM) georgiag: nothing from me either
(10:24:50 AM) jjohansen: alright then, lets call it meeting adjourned
(10:24:50 AM) jjohansen: next meeting is planned for Feb 13, @ 18:00 utc