Format: 1.8 Date: Thu, 08 Feb 2024 12:05:44 +0100 Source: linux Binary: linux-buildinfo-6.8.0-7-generic linux-headers-6.8.0-7-generic linux-image-6.8.0-7-generic linux-libc-dev linux-modules-6.8.0-7-generic linux-modules-extra-6.8.0-7-generic linux-tools-6.8.0-7 linux-tools-6.8.0-7-generic Built-For-Profiles: noudeb Architecture: ppc64el ppc64el_translations Version: 6.8.0-7.7 Distribution: noble Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Paolo Pisati Description: linux-buildinfo-6.8.0-7-generic - Linux kernel buildinfo for version 6.8.0 on PowerPC 64el SMP linux-headers-6.8.0-7-generic - Linux kernel headers for version 6.8.0 on PowerPC 64el SMP linux-image-6.8.0-7-generic - Linux kernel image for version 6.8.0 on PowerPC 64el SMP linux-libc-dev - Linux Kernel Headers for development linux-modules-6.8.0-7-generic - Linux kernel extra modules for version 6.8.0 on PowerPC 64el SMP linux-modules-extra-6.8.0-7-generic - Linux kernel extra modules for version 6.8.0 on PowerPC 64el SMP linux-tools-6.8.0-7 - Linux kernel version specific tools for version 6.8.0-7 linux-tools-6.8.0-7-generic - Linux kernel version specific tools for version 6.8.0-7 Launchpad-Bugs-Fixed: 2028253 2032602 2052691 Changes: linux (6.8.0-7.7) noble; urgency=medium . * noble/linux: 6.8.0-7.7 -proposed tracker (LP: #2052691) . * update apparmor and LSM stacking patch set (LP: #2028253) - SAUCE: apparmor4.0.0 [01/87]: LSM stacking v39: integrity: disassociate ima_filter_rule from security_audit_rule - SAUCE: apparmor4.0.0 [02/87]: LSM stacking v39: SM: Infrastructure management of the sock security - SAUCE: apparmor4.0.0 [03/87]: LSM stacking v39: LSM: Add the lsmblob data structure. - SAUCE: apparmor4.0.0 [04/87]: LSM stacking v39: IMA: avoid label collisions with stacked LSMs - SAUCE: apparmor4.0.0 [05/87]: LSM stacking v39: LSM: Use lsmblob in security_audit_rule_match - SAUCE: apparmor4.0.0 [06/87]: LSM stacking v39: LSM: Add lsmblob_to_secctx hook - SAUCE: apparmor4.0.0 [07/87]: LSM stacking v39: Audit: maintain an lsmblob in audit_context - SAUCE: apparmor4.0.0 [08/87]: LSM stacking v39: LSM: Use lsmblob in security_ipc_getsecid - SAUCE: apparmor4.0.0 [09/87]: LSM stacking v39: Audit: Update shutdown LSM data - SAUCE: apparmor4.0.0 [10/87]: LSM stacking v39: LSM: Use lsmblob in security_current_getsecid - SAUCE: apparmor4.0.0 [11/87]: LSM stacking v39: LSM: Use lsmblob in security_inode_getsecid - SAUCE: apparmor4.0.0 [12/87]: LSM stacking v39: Audit: use an lsmblob in audit_names - SAUCE: apparmor4.0.0 [13/87]: LSM stacking v39: LSM: Create new security_cred_getlsmblob LSM hook - SAUCE: apparmor4.0.0 [14/87]: LSM stacking v39: Audit: Change context data from secid to lsmblob - SAUCE: apparmor4.0.0 [15/87]: LSM stacking v39: Netlabel: Use lsmblob for audit data - SAUCE: apparmor4.0.0 [16/87]: LSM stacking v39: LSM: Ensure the correct LSM context releaser - SAUCE: apparmor4.0.0 [17/87]: LSM stacking v39: LSM: Use lsmcontext in security_secid_to_secctx - SAUCE: apparmor4.0.0 [18/87]: LSM stacking v39: LSM: Use lsmcontext in security_lsmblob_to_secctx - SAUCE: apparmor4.0.0 [19/87]: LSM stacking v39: LSM: Use lsmcontext in security_inode_getsecctx - SAUCE: apparmor4.0.0 [20/87]: LSM stacking v39: LSM: Use lsmcontext in security_dentry_init_security - SAUCE: apparmor4.0.0 [21/87]: LSM stacking v39: LSM: security_lsmblob_to_secctx module selection - SAUCE: apparmor4.0.0 [22/87]: LSM stacking v39: Audit: Create audit_stamp structure - SAUCE: apparmor4.0.0 [23/87]: LSM stacking v39: Audit: Allow multiple records in an audit_buffer - SAUCE: apparmor4.0.0 [24/87]: LSM stacking v39: Audit: Add record for multiple task security contexts - SAUCE: apparmor4.0.0 [25/87]: LSM stacking v39: audit: multiple subject lsm values for netlabel - SAUCE: apparmor4.0.0 [26/87]: LSM stacking v39: Audit: Add record for multiple object contexts - SAUCE: apparmor4.0.0 [27/87]: LSM stacking v39: LSM: Remove unused lsmcontext_init() - SAUCE: apparmor4.0.0 [28/87]: LSM stacking v39: LSM: Improve logic in security_getprocattr - SAUCE: apparmor4.0.0 [29/87]: LSM stacking v39: LSM: secctx provider check on release - SAUCE: apparmor4.0.0 [31/87]: LSM stacking v39: LSM: Exclusive secmark usage - SAUCE: apparmor4.0.0 [32/87]: LSM stacking v39: LSM: Identify which LSM handles the context string - SAUCE: apparmor4.0.0 [33/87]: LSM stacking v39: AppArmor: Remove the exclusive flag - SAUCE: apparmor4.0.0 [34/87]: LSM stacking v39: LSM: Add mount opts blob size tracking - SAUCE: apparmor4.0.0 [35/87]: LSM stacking v39: LSM: allocate mnt_opts blobs instead of module specific data - SAUCE: apparmor4.0.0 [36/87]: LSM stacking v39: LSM: Infrastructure management of the key security blob - SAUCE: apparmor4.0.0 [37/87]: LSM stacking v39: LSM: Infrastructure management of the mnt_opts security blob - SAUCE: apparmor4.0.0 [38/87]: LSM stacking v39: LSM: Correct handling of ENOSYS in inode_setxattr - SAUCE: apparmor4.0.0 [39/87]: LSM stacking v39: LSM: Remove lsmblob scaffolding - SAUCE: apparmor4.0.0 [40/87]: LSM stacking v39: LSM: Allow reservation of netlabel - SAUCE: apparmor4.0.0 [41/87]: LSM stacking v39: LSM: restrict security_cred_getsecid() to a single LSM - SAUCE: apparmor4.0.0 [42/87]: LSM stacking v39: Smack: Remove LSM_FLAG_EXCLUSIVE - SAUCE: apparmor4.0.0 [43/87]: LSM stacking v39: UBUNTU: SAUCE: apparmor4.0.0 [12/95]: add/use fns to print hash string hex value - SAUCE: apparmor4.0.0 [44/87]: patch to provide compatibility with v2.x net rules - SAUCE: apparmor4.0.0 [45/87]: add unpriviled user ns mediation - SAUCE: apparmor4.0.0 [46/87]: Add sysctls for additional controls of unpriv userns restrictions - SAUCE: apparmor4.0.0 [47/87]: af_unix mediation - SAUCE: apparmor4.0.0 [48/87]: Add fine grained mediation of posix mqueues - SAUCE: apparmor4.0.0 [49/87]: setup slab cache for audit data - SAUCE: apparmor4.0.0 [50/87]: Improve debug print infrastructure - SAUCE: apparmor4.0.0 [51/87]: add the ability for profiles to have a learning cache - SAUCE: apparmor4.0.0 [52/87]: enable userspace upcall for mediation - SAUCE: apparmor4.0.0 [53/87]: prompt - lock down prompt interface - SAUCE: apparmor4.0.0 [54/87]: prompt - allow controlling of caching of a prompt response - SAUCE: apparmor4.0.0 [55/87]: prompt - add refcount to audit_node in prep or reuse and delete - SAUCE: apparmor4.0.0 [56/87]: prompt - refactor to moving caching to uresponse - SAUCE: apparmor4.0.0 [57/87]: prompt - Improve debug statements - SAUCE: apparmor4.0.0 [58/87]: prompt - fix caching - SAUCE: apparmor4.0.0 [59/87]: prompt - rework build to use append fn, to simplify adding strings - SAUCE: apparmor4.0.0 [60/87]: prompt - refcount notifications - SAUCE: apparmor4.0.0 [61/87]: prompt - add the ability to reply with a profile name - SAUCE: apparmor4.0.0 [62/87]: prompt - fix notification cache when updating - SAUCE: apparmor4.0.0 [63/87]: prompt - add tailglob on name for cache support - SAUCE: apparmor4.0.0 [64/87]: prompt - allow profiles to set prompts as interruptible - SAUCE: apparmor4.0.0 [65/87] v6.8 prompt:fixup interruptible - SAUCE: apparmor4.0.0 [69/87]: add io_uring mediation - SAUCE: apparmor4.0.0 [70/87]: apparmor: fix oops when racing to retrieve notification - SAUCE: apparmor4.0.0 [71/87]: apparmor: fix notification header size - SAUCE: apparmor4.0.0 [72/87]: apparmor: fix request field from a prompt reply that denies all access - SAUCE: apparmor4.0.0 [73/87]: apparmor: open userns related sysctl so lxc can check if restriction are in place - SAUCE: apparmor4.0.0 [74/87]: apparmor: cleanup attachment perm lookup to use lookup_perms() - SAUCE: apparmor4.0.0 [75/87]: apparmor: remove redundant unconfined check. - SAUCE: apparmor4.0.0 [76/87]: apparmor: switch signal mediation to using RULE_MEDIATES - SAUCE: apparmor4.0.0 [77/87]: apparmor: ensure labels with more than one entry have correct flags - SAUCE: apparmor4.0.0 [78/87]: apparmor: remove explicit restriction that unconfined cannot use change_hat - SAUCE: apparmor4.0.0 [79/87]: apparmor: cleanup: refactor file_perm() to provide semantics of some checks - SAUCE: apparmor4.0.0 [80/87]: apparmor: carry mediation check on label - SAUCE: apparmor4.0.0 [81/87]: apparmor: convert easy uses of unconfined() to label_mediates() - SAUCE: apparmor4.0.0 [82/87]: apparmor: add additional flags to extended permission. - SAUCE: apparmor4.0.0 [83/87]: apparmor: add support for profiles to define the kill signal - SAUCE: apparmor4.0.0 [84/87]: apparmor: fix x_table_lookup when stacking is not the first entry - SAUCE: apparmor4.0.0 [85/87]: apparmor: allow profile to be transitioned when a user ns is created - SAUCE: apparmor4.0.0 [86/87]: apparmor: add ability to mediate caps with policy state machine - SAUCE: apparmor4.0.0 [87/87]: fixup notify - [Config] disable CONFIG_SECURITY_APPARMOR_RESTRICT_USERNS . * update apparmor and LSM stacking patch set (LP: #2028253) // [FFe] apparmor-4.0.0-alpha2 for unprivileged user namespace restrictions in mantic (LP: #2032602) - SAUCE: apparmor4.0.0 [66/87]: prompt - add support for advanced filtering of notifications - SAUCE: apparmor4.0.0 [67/87]: userns - add the ability to reference a global variable for a feature value - SAUCE: apparmor4.0.0 [68/87]: userns - make it so special unconfined profiles can mediate user namespaces Checksums-Sha1: 1b797a4a589d3ca91b69510f3f29830ce8cb9013 639794 linux-buildinfo-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb f78ceee6553d42de58fec8902923d472a22f90f7 3727564 linux-headers-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb d5f9cffe0624f8625bd0b4cb44acb03e824c252e 1613455016 linux-image-6.8.0-7-generic-dbgsym_6.8.0-7.7_ppc64el.ddeb dee1eaed11be16abe331c6d24e8c2ee3c0b41e5b 63856832 linux-image-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb 7a5b67f7c133699d45ff156ff59f11b9b5919def 1584008 linux-libc-dev_6.8.0-7.7_ppc64el.deb b16f520d8314cb2195f8af53abd120b54b95bceb 31303872 linux-modules-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb b468553d28e8fa1619775833116060942cfde64f 102645952 linux-modules-extra-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb 7e6ab5f4683124f261c84203c30e06d2c1df6daf 1720 linux-tools-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb 9da9753ca38f7a2fe72e705fbdf613f8bf3f7f06 2921542 linux-tools-6.8.0-7_6.8.0-7.7_ppc64el.deb ea8f50ccb0dd838e0bfad8fa20fdd5c1b14d7aad 13027 linux_6.8.0-7.7_ppc64el.buildinfo 6326894ed758ec619723763ccd2a4ef31110945e 44898 linux_6.8.0-7.7_ppc64el_translations.tar.gz Checksums-Sha256: ad9f458e8aea8d29ac4f84fb9df49aeaac992c0c28f3a3b6aefb6f03ad3a4148 639794 linux-buildinfo-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb 51a39af7868d51572868f487afceb6e5b92ca64b020dc6db5bde0a69516f8200 3727564 linux-headers-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb 7158f11f3b0fd4999a0cd3b2cf7efdefa0130fdafc02ab83005f6bb3f53c000c 1613455016 linux-image-6.8.0-7-generic-dbgsym_6.8.0-7.7_ppc64el.ddeb 3962aa87bb4e5141fea15659e0da27f389a2f1afb31e04d02e925f6af0a84346 63856832 linux-image-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb 674d840cb4237e28268ec9974e15b467e8e677090866bb140344cb007043c4c0 1584008 linux-libc-dev_6.8.0-7.7_ppc64el.deb a99248521b543d6740f6d443df1325f4fee8359f239b64a29446c9f2225087d1 31303872 linux-modules-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb 4e862f33bceb0b5d08df319060c71f9b08185236aee893d0bedadc7cc678268c 102645952 linux-modules-extra-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb 50aa44b865ea8e3fb371a5550c1b30e021b9c5a0888207a1f016a8d7859ac2dd 1720 linux-tools-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb 4f0ea21416f7dcd48f867485b1bd0b3b05794f210884211e416f2396f65f67de 2921542 linux-tools-6.8.0-7_6.8.0-7.7_ppc64el.deb 2e1837e107de3a78b7370ebf3cdde0cfe779b610c79b1758b10ab3fbc8fb54ea 13027 linux_6.8.0-7.7_ppc64el.buildinfo 3b6b4e08aa63338b61c0316a90a3b544b4066f65ce4189cee58224528eb65d35 44898 linux_6.8.0-7.7_ppc64el_translations.tar.gz Files: 0fe7031b15fed4b698df72a013647c40 639794 kernel optional linux-buildinfo-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb 9752f8b1a70ea1e5c438cd8849dda850 3727564 devel optional linux-headers-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb f15a5815b8c339459263572a5e3e18f5 1613455016 devel optional linux-image-6.8.0-7-generic-dbgsym_6.8.0-7.7_ppc64el.ddeb 67131609fc80576607e2bec25e3cc291 63856832 kernel optional linux-image-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb daa4f7797d3ba25619d0bb25cc90d90d 1584008 devel optional linux-libc-dev_6.8.0-7.7_ppc64el.deb dd2863c5a191562dc1868da94691eb88 31303872 kernel optional linux-modules-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb 190afe34373cff02145896b6d7f426e0 102645952 kernel optional linux-modules-extra-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb fde380da70e02978db072962f9fe5c0d 1720 devel optional linux-tools-6.8.0-7-generic_6.8.0-7.7_ppc64el.deb 00b541ba691ee3e08144ac8486329091 2921542 devel optional linux-tools-6.8.0-7_6.8.0-7.7_ppc64el.deb 9dbff164c895f9eb588b6040983caaea 13027 devel optional linux_6.8.0-7.7_ppc64el.buildinfo f04a9afdba30a6a5848595f9c56def89 44898 raw-translations - linux_6.8.0-7.7_ppc64el_translations.tar.gz Ubuntu-Compatible-Signing: ubuntu/4 pro/3