[Bug 1785414] Re: Backport seccomp sandbox fixes to 18.04

2018-10-23 Thread Launchpad Bug Tracker
This bug was fixed in the package man-db - 2.8.3-2ubuntu0.1 --- man-db (2.8.3-2ubuntu0.1) bionic; urgency=medium * Backport seccomp sandbox improvements from 2.8.4 (LP: #1785414): - Allow sched_getaffinity, used by xz in some cases. - Allow some shared memory operations, req

[Bug 1785414] Re: Backport seccomp sandbox fixes to 18.04

2018-10-23 Thread Colin Watson
Thanks. Sounds like I still missed something but it's at least no worse than before, so I think that's good enough for verification-done. ** Tags removed: verification-needed verification-needed-bionic ** Tags added: verification-done verification-done-bionic -- You received this bug notificati

[Bug 1785414] Re: Backport seccomp sandbox fixes to 18.04

2018-09-24 Thread Bernd Wagner
Thanks, Colin, for providing the fixes+backport and Brian, for including them into the repository. I hope the following serves at least as a regression test. [Test Cases] 1) ESET NOD32 Antivirus4 4.0.90.0 with /etc/ld.so.preload (which serves to files scanning on access) 1a) man-db 2.8.3-2 and

[Bug 1785414] Re: Backport seccomp sandbox fixes to 18.04

2018-08-24 Thread Simon Déziel
I couldn't reproduce the problem with XZ_DEFAULTS=--threads=0 but according to [1], it requires xz-utils >= 5.2.3 and 18.04 has 5.2.2-1.3. I found no regression but I have NOT tested the ESET/VPN cases. 1: https://git.savannah.gnu.org/cgit/man- db.git/commit/?id=8fa6fb5eca612600b3a3d8da811f8345afe

[Bug 1785414] Re: Backport seccomp sandbox fixes to 18.04

2018-08-09 Thread Brian Murray
Hello Colin, or anyone else affected, Accepted man-db into bionic-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/man- db/2.8.3-2ubuntu0.1 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See https://w

[Bug 1785414] Re: Backport seccomp sandbox fixes to 18.04

2018-08-04 Thread Amr Ibrahim
** Summary changed: - Backport seccomp sandbox fixes to 16.04 + Backport seccomp sandbox fixes to 18.04 ** Description changed: I applied several fixes to the seccomp sandbox in man-db 2.8.4, and I - think they would all be worth backporting to 16.04. They're all corner + think they would all