Change logs for apparmor-easyprof-ubuntu source package in Vivid

  • apparmor-easyprof-ubuntu (1.3.10) vivid; urgency=medium
    
      * templates/*: explicitly deny noisy access to accountsservice
        (LP: #1433590)
     -- Jamie Strandboge <email address hidden>   Tue, 07 Apr 2015 11:29:08 -0500
  • apparmor-easyprof-ubuntu (1.3.9) vivid; urgency=medium
    
      * templates/ubuntu-sdk|ubuntu-webapp: explicitly deny noisy /dev/tty access
      * policygroups/accounts: also deny 'r' to /{,var/}run/user/*/signond/socket
        to silence expected noisy denial (LP: #1415492)
     -- Jamie Strandboge <email address hidden>   Mon, 30 Mar 2015 08:42:47 -0500
  • apparmor-easyprof-ubuntu (1.3.8) vivid; urgency=medium
    
      * hardware/video.d/apparmor-easyprof-ubuntu_mako: add accesses for
        video4linux 1 and 2 devices needed by mediascanner2 (gst-plugin-scanner)
        et al
     -- Jamie Strandboge <email address hidden>   Wed, 04 Mar 2015 08:42:23 -0600
  • apparmor-easyprof-ubuntu (1.3.7) vivid; urgency=medium
    
      * ubuntu/webview: allow oxide_helper read access to /sys/devices/system/cpu/
        and /sys/devices/system/cpu/cpu[0-9]*/cpufreq/cpuinfo_max_freq
     -- Jamie Strandboge <email address hidden>   Thu, 26 Feb 2015 08:22:04 -0600
  • apparmor-easyprof-ubuntu (1.3.6) vivid; urgency=medium
    
      * ubuntu/1.0/ubuntu-{sdk,webapp}: also allow access to mir libraries via
        the new mir abstraction for 1.0 templates (LP: #1422521)
    
    apparmor-easyprof-ubuntu (1.3.5) vivid; urgency=medium
    
      * ubuntu/1.[123]/ubuntu-{sdk,webapp}: allow access to mir libraries via
        the new mir abstraction (LP: #1422521)
      * debian/control: update version dependency to ensure the mir
        abstraction exists
     -- Steve Beattie <email address hidden>   Wed, 18 Feb 2015 12:28:55 -0800
  • apparmor-easyprof-ubuntu (1.3.4) vivid; urgency=medium
    
      [ Alberto Mardegan ]
      * ubuntu/accounts: explictly deny access to the p2p socket. This will now be
        available only to unconfined apps to support a trusted socket for
        privileged processes (LP: #1415492)
    
      [ Jamie Strandboge ]
      * add ubuntu/1.2/ubuntu-account-plugin template and add to 1.3 policy
        (LP: #1219644)
      * adjust expected_templates_12 in autopkgtests to have ubuntu-account-plugin
      * ubuntu/webview: allow /sys/devices/system/cpu/*/cpufreq/cpuinfo_max_freq
        readonly access
     -- Jamie Strandboge <email address hidden>   Tue, 03 Feb 2015 16:24:15 -0600
  • apparmor-easyprof-ubuntu (1.3.3) vivid; urgency=medium
    
      * ubuntu/{music,pictures,video}_files*: temporarily allow read access to
        global SD card user directory (LP: #1392368). This can be removed once
        there is a proper API for apps to find the SD card label.
     -- Jamie Strandboge <email address hidden>   Thu, 08 Jan 2015 14:24:42 -0600
  • apparmor-easyprof-ubuntu (1.3.2) vivid; urgency=medium
    
      [ Ricardo Salveti de Araujo ]
      * Adding hardware/video.d/apparmor-easyprof-ubuntu_manta to allow rw on
        /dev/video*, needed for hardware video decoding (LP: #1408130). (Note: we
        may need to add rw on /dev/v4l-subdev*, but this seems to be enough for
        now)
     -- Jamie Strandboge <email address hidden>   Thu, 08 Jan 2015 11:41:57 -0600
  • apparmor-easyprof-ubuntu (1.3.1) vivid; urgency=medium
    
      * ubuntu/ubuntu-sdk:
        - explicitly deny reads on ~/.cache/QML/Apps/ to silence noisy denials.
          Undo this when LP: 1381620 is fixed in qtdeclarative-opensource-src
        - explicitly deny dbus bind on name="org.freedesktop.Application" since
          it is noisy. Undo this when LP: 1378823 is fixed in ubuntu-ui-toolkit
      * ubuntu/1.3/ubuntu-sdk: drop html5-container policy. html5 apps should use
        webapp-container and specify the 'webview' policy group with 1.3 (15.04)
        policy (LP: #1392461)
      * ubuntu/ubuntu-scope-network, pending/ubuntu-scope-local-content: allow
        scopes to read data from the apps data dir (LP: #1384286)
      * adjust all dbus rules to use peer=(label=unconfined) to prevent
        coordinated communications between apps over DBus (LP: #1383824)
      * ubuntu/{music,pictures,video}_files*: allow access to global SD card
        directories (LP: #1391930)
      * debian/control: Depends on apparmor >= 2.8.98-0ubuntu2~ for the dbus peer
        changes (we need at least apparmor_parser 2.9.beta4 for these)
     -- Jamie Strandboge <email address hidden>   Mon, 15 Dec 2014 15:53:32 +0000
  • apparmor-easyprof-ubuntu (1.3.0) vivid; urgency=medium
    
      * debian/control:
        - add Vcs-Bzr and Vcs-Browser now that we have them
        - adjust Standards-Version
      * add debian/make-new-version.sh and document how to use it
      * create policy version 1.3
      * adjust autopkgtests:
        - add tests for policy version 1.3
        - fix lintian warnings in naming of the tests
      * debian/apparmor-easyprof-ubuntu.postinst: add #DEBHELPER# token
     -- Jamie Strandboge <email address hidden>   Wed, 29 Oct 2014 07:52:45 -0500
  • apparmor-easyprof-ubuntu (1.2.38) utopic; urgency=medium
    
      * ubuntu/networking: add rules for app-specific ubuntu-download-manager
        file downloads (LP: #1384349)
     -- Jamie Strandboge <email address hidden>   Wed, 22 Oct 2014 14:13:44 -0400