Bug#999551: Support Landlock by default in Debian kernels

2021-11-12 Thread Mickaël Salaün
On 12/11/2021 13:34, Yves-Alexis Perez wrote: > Hey Mickaël, kernel team, > > On Fri, 2021-11-12 at 12:23 +0100, Mickaël Salaün wrote: >> - >> CONFIG_LSM="lockdown,yama,loadpin,safesetid,integrity,apparmor,selinux,smack >> ,to >> moyo" >> +CON

Bug#999551: Support Landlock by default in Debian kernels

2021-11-12 Thread Mickaël Salaün
On 12/11/2021 13:45, Bastian Blank wrote: > Control: tag -1 wontfix > > On Fri, Nov 12, 2021 at 12:23:13PM +0100, Mickaël Salaün wrote: >> The Landlock security feature is built in Debian kernel since >> 5.13.12-1~exp1 which is great! However, it is not

Bug#999551: Support Landlock by default in Debian kernels

2021-11-12 Thread Mickaël Salaün
Package: src:linux Version: 5.14.16-1 Severity: normal Tags: patch X-Debbugs-Cc: landl...@lists.linux.dev Hi, The Landlock security feature is built in Debian kernel since 5.13.12-1~exp1 which is great! However, it is not enough to enable the CONFIG_SECURITY_LANDLOCK option as described in the r

Bug#605090:

2015-12-21 Thread Mickaël Salaün
On 21/12/2015 00:14, Jacob Appelbaum wrote: > I was left with: > > [ 1802.373906] grsec: denied untrusted exec (due to not being in > trusted group and file in non-root-owned directory) of > /run/user/1000/orcexec.bCtW1V by > /usr/bin/pulseaudio[alsa-source-ALC:3038] uid/euid:1000/1000 > gid/egid:

Bug#747444: libc6-dev: Missing O_TMPFILE in

2014-05-08 Thread Mickaël Salaün
Package: libc6-dev Version: 2.18-5 Severity: normal Tags: patch The new O_TMPFILE open(2) flag introduced in Linux 3.11 [1] is missing in . Andreas Schwab pushed the update in upstream last year [2]. I reformatted his patch in attachment. 1. http://kernelnewbies.org/Linux_3.11#head-8be09d59438b31