Changelog for
libapparmor-devel-4.0.3-551.1.x86_64.rpm :
* Tue Oct 01 2024 Christian Boltz
- add mesa-cachedir.diff: new cachedir in Mesa 24.2.2
* Fri Aug 23 2024 Christian Boltz - update to AppArmor 4.0.3 - several small bugfixes - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_4.0.3 for the full release notes
* Thu Aug 22 2024 pgajdosAATTsuse.com- remove dependency on /usr/bin/python3 using %python3_fix_shebang macro, [bsc#1212476]
* Wed Jul 24 2024 Christian Boltz - update to AppArmor 4.0.2 - bugfix release with lots of fixes in all areas - add new userns profiles for balena-etcher, chromium and wike - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_4.0.2 for the detailed upstream changelog- drop upstream(ed) patches: - aa-remove-unknown-fix-unconfined.diff - logprof-mount-empty-source.diff - plasmashell.diff - sampa-rpcd-witness.diff - sddm-xauth.diff - teardown-unconfined.diff - test-aa-notify.diff - tools-fix-redefinition.diff - utils-relax-mount-rules-2.diff - utils-relax-mount-rules.diff- refresh GPG key (was expired)
* Tue Jun 25 2024 Christian Boltz - add sampa-rpcd-witness.diff: allow samba-dcerpcd to execute rpcd_witness (boo#1225811)
* Tue Jun 11 2024 Christian Boltz - add logprof-mount-empty-source.diff: add support for mount rules with quoted paths and empty source (boo#1226031)
* Tue Jun 04 2024 Christian Boltz - add sddm-xauth.diff - sddm uses a new path for xauth (boo#1223900)- add plasmashell.diff - fix QtWebEngineProcess path to prevent a crash in plasmashell (boo#1225961)
* Thu May 30 2024 Guillaume GARDET - Also exclude podman profile - boo#1225608
* Wed May 29 2024 Fabian Vogt - Exclude the crun profile in addition to runc
* Tue May 28 2024 Christian Boltz - add utils-relax-mount-rules.diff and utils-relax-mount-rules-2.diff: Relax handling of mount rules in utils to avoid errors when parsing valid profiles- add teardown-unconfined.diff to fix aa-teardown for \'unconfined\' profiles (boo#1225457)
* Tue May 28 2024 Christian Boltz - exclude runc profile until updated runc packages (including updated profile with \"signal peer=runc\") have arrived
* Sat May 25 2024 Christian Boltz - add aa-remove-unknown-fix-unconfined.diff to fix aa-remove-unknown for \'unconfined\' profiles (boo#1225457)- set permissions for %ghost files (boo#1223578)
* Fri May 24 2024 Christian Boltz - fix bashism in %post profiles
* Sun May 05 2024 Christian Boltz - Update to AppArmor 4.0.1 Too many changes to list them here. See https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_4.0.1 for the detailed upstream release notes- add tools-fix-redefinition.diff: fix redefinition of _ in tools- add test-aa-notify.diff: relax test-aa-notify to avoid a mismatch with argparse on Leap 15.5- drop upstreamed patches: - apparmor-abstractions-openssl-allow-version-specific-en.patch - dovecot-unix_chkpwd.diff - smbd-unix_chkpwd.diff- apparmor-lessopen-profile.patch: update lessopen profile to abi/4.0- mark local/
* as %ghost so that these dummy files don\'t get installed anymore (changed existing local/files will be kept, unchanged files will be deleted)- switch to gitlab tarballs (without pregenerated libapparmor configure script and prebuilt techdoc.pdf) - run libapparmor autogen.sh (needs additional BuildRequires autoconf, autoconf-archive, automake and libtool) - no longer package techdoc.pdf - old documentation, not worth the texlive BuildRequires we would need to build it- drop old (up to 2.12) cache location /var/lib/apparmor/ and the /etc/apparmor.d/cache symlink pointing to it- drop apparmor-samba-include-permissions-for-shares.diff - no longer needed, update-apparmor-samba-profile in Tumbleweed works without a pre-existing local/usr.sbin.smbd-shares file- drop ruby-2_0-mkmf-destdir.patch - this ancient patch doesn\'t change a single bit in the resulting build (anymore?)- drop apparmor-lessopen-nfs-workaround.diff - no longer needed since Kernel 6.0 (see https://bugs.launchpad.net/bugs/1784499)- drop ancient, unused update-trans.sh
* Fri Apr 05 2024 Atri Bhattacharya - Use full URLs for source tarball and signature.
* Fri Mar 01 2024 Christian Boltz - Remove workaround for boo#853019 in %postun parser - apparmor.service contains a more safe workaround. This also fixes boo#1220708 (missing daemon-reload).
* Tue Feb 27 2024 Noel Power - Add smbd-unix_chkpwd.diff to allow smbd to execute unix_chkpwd and fix other pam related denies; (boo#1220032).
* Mon Feb 26 2024 Ludwig Nussel - Fix systemd userdb access in unix-chkpwd
* Tue Feb 20 2024 Dominique Leuenberger - Use %patch -P N instead of deprecated %patchN.
* Tue Feb 20 2024 David Disseldorp - Only run utils and profiles make check if kernel LSM is enabled (bsc#1220084)
* Thu Feb 08 2024 David Disseldorp - Add apparmor-abstractions-openssl-allow-version-specific-en.patch to allow version specific engdef & engines openssl paths (boo#1219571)
* Mon Feb 05 2024 Christian Boltz - Update to AppArmor 3.1.7 - aa-logprof: don\'t skip exec events in hats - fix aa-cleanprof to work with named profiles - add permissions in various abstractions - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.1.7 for the full list of changes- drop upstreamed apparmor-systemd-sessions.patch
* Mon Jan 29 2024 Christian Boltz - Add dovecot-unix_chkpwd.diff to allow dovecot-auth to execute unix_chkpwd, and add a profile for unix_chkpwd. This is needed for PAM 1.6 (boo#1219139)- Refresh apparmor.keyring - the key was renewed
* Wed Nov 08 2023 Christian Boltz - Actually apply the previously added patch for bsc#1216878
* Wed Nov 08 2023 Julio Gonzalez Gil - Add apparmor-systemd-sessions.patch to allow read access to /run/systemd/sessions/ (bsc#1216878)
* Mon Sep 25 2023 David Disseldorp - Fix pam_apparmor %post and %postun scripts to handle pam-config errors (bsc#1215596)
* Tue Jul 25 2023 David Disseldorp - Add pam_apparmor README, referenced from online cha-apparmor-pam.html documentation (bsc#1213472)
* Thu Jun 22 2023 Christian Boltz - update to AppArmor 3.1.6 (jsc#PED-5600) - fix regression in mount rules (boo#1211989) - some additions to the base and authentification abstractions - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.1.6 for the full upstream changelog
* Sun Jun 11 2023 Christian Boltz - update to AppArmor 3.1.5 - fix handling of mount rules in apparmor_parser - minor additions to abstractions/base and snap_browsers - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.1.5 for the full upstream changelog- remove upstreamed aa-status-fix-json-mr1046.patch- split off apparmor-enable-precompiled-cache.diff from apparmor-enable-profile-cache.diff so that the precompiled cache path doesn\'t get added in parser.conf for Tumbleweed builds. This prevents a warning about the non-existing directory when loading profiles.
* Tue Jun 06 2023 Christian Boltz - fix aa-status --json output (aa-status-fix-json-mr1046.patch, boo#1211980#c12)
* Mon May 29 2023 Christian Boltz - update to AppArmor 3.1.4 - parser: fix mount rules encoding (CVE-2016-1585) - aa-logprof: fix error when choosing named exec with plain profile names - aa-status: fix json output - several fixes for profiles and abstractions - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.1.4 for the full upstream changelog
* Thu May 04 2023 Frederic Crozat - Add _multibuild to define additional spec files as additional flavors. Eliminates the need for source package links in OBS.
* Tue Feb 28 2023 Christian Boltz - update to AppArmor 3.1.3 - add support for more audit.log formats in libapparmor - add abstractions/groff (boo#1065388) - various additions in abstractions and profiles - several bug fixes in parser and utils - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.1.3 for the detailed upstream changelog- drop upstreamed patches: - abstractions-openssl-1_1.diff - dnsmasq-cpu-possible.diff - nscd-systemd-userdb.diff
* Mon Feb 06 2023 Christian Boltz - add abstractions-openssl-1_1.diff: allow to read /etc/ssl/openssl-1_1.cnf in abstractions/openssl (boo#1207911)
* Mon Jan 30 2023 Christian Boltz - add nscd-systemd-userdb.diff: allow nscd to read systemd-userdb (boo#1207698)
* Tue Dec 27 2022 Ludwig Nussel - Replace transitional %usrmerged macro with regular version check (boo#1206798)
* Fri Dec 23 2022 Samuel Cabrero - Add samba-4-17.patch to update the samba profiles for samba version 4.17 (bsc#1206626); - samba-4-17.patch superseded by upstream merge: https://gitlab.com/apparmor/apparmor/-/merge_requests/926
* Tue Nov 22 2022 Christian Boltz - update to AppArmor 3.1.2 - lots of cleanups, improvements and bugfixes in all areas - rework internal profile storage and handling in the aa-
* tools - support boolean variable definitions in the aa-
* tools - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.1.1 and https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.1.2 for the detailed upstream changelog- remove upstream(ed) patches: - apparmor-3.0.7-egrep.patch - dnsmasq.diff - profiles-permit-php-fpm-pid-files-directly-under-run.patch - zgrep-profile-mr870.diff- no longer ship precompiled profile cache for Tumbleweed (boo#1205659)- BuildRequire iproute2 (needed for aa-unconfined tests)