<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=4329&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / Kernel upgrade: apparmor and tomoyo]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=4329</link>
		<description><![CDATA[The most recent posts in Kernel upgrade: apparmor and tomoyo.]]></description>
		<lastBuildDate>Tue, 18 May 2021 09:42:14 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: Kernel upgrade: apparmor and tomoyo]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=29847#p29847</link>
			<description><![CDATA[<p>I went off Debian when they foisted systemd onto its users, I&#039;ve been using a non systemd version/distro, but they have been adding too many things to the already full menu, which just makes it look tatty now.........</p><p>So here I am, back to Devuan, (I tried it a couple of times in the past), using the regular &#039;live&#039; version installed to disk. </p><p>Seems to be working well, but haven&#039;t looked below the surface, so to speak, (&amp; I&#039;m not so sure I can be bothered messing with altering things on distros any more).</p><p>I just needed to find a decent replacement for my previous distro. <img src="https://dev1galaxy.org/img/smilies/smile.png" width="15" height="15" alt="smile" /></p>]]></description>
			<author><![CDATA[dummy@example.com (Camtaf)]]></author>
			<pubDate>Tue, 18 May 2021 09:42:14 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=29847#p29847</guid>
		</item>
		<item>
			<title><![CDATA[Re: Kernel upgrade: apparmor and tomoyo]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=29838#p29838</link>
			<description><![CDATA[<p>Hello:</p><div class="quotebox"><cite>Camtaf wrote:</cite><blockquote><div><p>Everything not needed to run a system should remain optional ...<br />... don&#039;t foist these things onto ordinary desktop users ...</p></div></blockquote></div><p>Evidently that&#039;s <em>not</em> the vision of those who are in a position to run the Debian show and decide the hows, why&#039;s and whens.</p><div class="quotebox"><cite>Camtaf wrote:</cite><blockquote><div><p>... a good working distro to do my daily tasks ..</p></div></blockquote></div><p>I&#039;m glad to see we&#039;re more than <em>one</em>.</p><p>But I&#039;m afraid the dice have already been rolled.<br />And the result was not in our favour.</p><p>Hence the very existence of Devuan.</p><p>Best,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Mon, 17 May 2021 18:30:18 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=29838#p29838</guid>
		</item>
		<item>
			<title><![CDATA[Re: Kernel upgrade: apparmor and tomoyo]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=29837#p29837</link>
			<description><![CDATA[<p>Everything not needed to run a system should remain optional - we don&#039;t all run servers - if this is what it is meant for.</p><p>If the devs want to have a version for servers, that&#039;s fine by me, but please don&#039;t foist these things onto ordinary desktop users the likes of me, as I have no idea about them, &amp; don&#039;t want them. </p><p>I just want a good working distro to do my daily tasks, thankyou. <img src="https://dev1galaxy.org/img/smilies/wink.png" width="15" height="15" alt="wink" /></p>]]></description>
			<author><![CDATA[dummy@example.com (Camtaf)]]></author>
			<pubDate>Mon, 17 May 2021 17:53:29 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=29837#p29837</guid>
		</item>
		<item>
			<title><![CDATA[Re: Kernel upgrade: apparmor and tomoyo]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=29836#p29836</link>
			<description><![CDATA[<p>Hello:</p><div class="quotebox"><cite>dice wrote:</cite><blockquote><div><p>... this sort of config should be opt in even at the kernel level.</p></div></blockquote></div><p>Exactly my point.</p><div class="quotebox"><cite>Altoid wrote:</cite><blockquote><div><p>If and when I want/need to install a Mandatory Access Control scheme for my rig&#039;s security, I&#039;ll just apt install the required modules and configure.</p></div></blockquote></div><div class="quotebox"><cite>Altoid wrote:</cite><blockquote><div><p>Makes no sense to call it a security feature ...</p></div></blockquote></div><p>I could not care less about what it is called.</p><p>It is being made part of the kernel just because some DH <em>decided</em> it should be.<br />Why? On the basis of what?</p><p>Next thing you know you&#039;ll have to set it up/configure <em>if</em> you want the kernel to work.<br />eg: no apparmor/tomoyo/SELinux? No WAN/LAN.</p><p>This has all the colourings of one of Poettering&#039;s <em>diktats</em>.<br />Like this other one:</p><p><a href="https://dev1galaxy.org/viewtopic.php?id=4136" rel="nofollow">https://dev1galaxy.org/viewtopic.php?id=4136</a></p><p>Bad, bad, bad ...</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Mon, 17 May 2021 15:51:26 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=29836#p29836</guid>
		</item>
		<item>
			<title><![CDATA[Re: Kernel upgrade: apparmor and tomoyo]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=29835#p29835</link>
			<description><![CDATA[<p>If not activated then this sort of config should be opt in even at the kernel level. Makes no sense to call it a security feature if it is not running as a security feature. Hope i got that right in my understanding?</p>]]></description>
			<author><![CDATA[dummy@example.com (dice)]]></author>
			<pubDate>Mon, 17 May 2021 14:49:36 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=29835#p29835</guid>
		</item>
		<item>
			<title><![CDATA[Re: Kernel upgrade: apparmor and tomoyo]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=29828#p29828</link>
			<description><![CDATA[<p>Hello:</p><div class="quotebox"><cite>Altoid wrote:</cite><blockquote><div><p>I think not:<br /><a href="https://wiki.archlinux.org/title/TOMOYO_Linux#" rel="nofollow">https://wiki.archlinux.org/title/TOMOYO_Linux#</a></p></div></blockquote></div><p>You were quite right, I stand corrected.</p><p>In spite of what <span class="bbc">wiki.archlinux</span> says, adding <span class="bbc">security=none</span> disables <span class="bbc">tomoyo</span> as there are no entries for it in <span class="bbc">dmesg</span>, <span class="bbc">kern.log</span> or <span class="bbc">syslog</span>.</p><p><span class="bbu">Edit:</span> <span class="bbc">security=none</span> not only disables <span class="bbc">tomoyo</span>, it also makes <span class="bbc">apparmor=0</span> unneccesary. 8^D</p><p>Thanks for the heads up.&#160; 8^)<br />Best,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Sun, 16 May 2021 22:46:29 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=29828#p29828</guid>
		</item>
		<item>
			<title><![CDATA[Re: Kernel upgrade: apparmor and tomoyo]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=29827#p29827</link>
			<description><![CDATA[<p>Hello:</p><div class="quotebox"><cite>ralph.ronnquist wrote:</cite><blockquote><div><p>... Way Too Many.</p></div></blockquote></div><p>Indeed ...</p><div class="quotebox"><cite>ralph.ronnquist wrote:</cite><blockquote><div><p><span class="bbc">tomoyo-tools</span> ...<br />... why that is enabled in debian&#039;s standard linux-image is unkown to me ...</p></div></blockquote></div><p>Hmm ...<br />Maybe it&#039;s yet <em>another</em> one of Poettering&#039;s brillant ideas?</p><div class="quotebox"><cite>ralph.ronnquist wrote:</cite><blockquote><div><p>Apparently adding <span class="bbc">security=none</span> to the boot command should disable this one.</p></div></blockquote></div><p>I was wondering about that.<br />A bit for disabling <span class="bbc">apparmor</span> but none for disabling <span class="bbc">tomoyo</span>? </p><p>I think not:<br /><a href="https://wiki.archlinux.org/title/TOMOYO_Linux#" rel="nofollow">https://wiki.archlinux.org/title/TOMOYO_Linux#</a></p><div class="quotebox"><cite>wiki.archlinux wrote:</cite><blockquote><div><p>TOMOYO Linux 2.x is the Linux mainline kernel branch of development. In June 2009, TOMOYO was merged into the Linux kernel version 2.6.30 and it uses standard Linux Security Module (LSM) hooks. However, the LSM hooks must be extended further in order to port the full MAC functionality of TOMOYO Linux into the Linux kernel. Thus, it does not yet provide equal functionality with the 1.x branch of development. This chart compares the differences between each branch.</p></div></blockquote></div><div class="quotebox"><cite>wiki.archlinux wrote:</cite><blockquote><div><p>Disabling<br />For kernels 5.1 and above remove tomoyo from the lsm= kernel parameter or remove lsm= entirely.&#160; &lt;- | x | <br />For kernels 3.2 to 5.0 change the kernel parameter security=tomoyo to security=none.</p></div></blockquote></div><p>I&#039;ll try it out and report.</p><p>-------&gt; I_don&#039;t_like_this.&#160; 8^|</p><p><em>If</em> and <em>when</em> I want/need to install a Mandatory Access Control scheme for my rig&#039;s security, I&#039;ll just <span class="bbc">apt install</span> the required modules and configure. <br />Why do I have to have the kernel looking to run something that is not there?</p><p>Thanks for your input.</p><p>Best,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Sun, 16 May 2021 22:30:18 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=29827#p29827</guid>
		</item>
		<item>
			<title><![CDATA[Re: Kernel upgrade: apparmor and tomoyo]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=29826#p29826</link>
			<description><![CDATA[<div class="quotebox"><blockquote><div><p>What is all this about?<br />Is it just me or am I seeing far too many (unrequired) Mandatory Access Control instances in the Linux kernel?</p></div></blockquote></div><p>I would call it Way Too Many.</p><p><span class="bbc">tomoyo-tools</span> seems to be to be upstreamed from <a href="http://tomoyo.osdn.jp/" rel="nofollow">http://tomoyo.osdn.jp/</a> (and why that is enabled in debian&#039;s standard linux-image is unkown to me). Apparently adding <span class="bbc">security=none</span> to the boot command should disable this one.</p>]]></description>
			<author><![CDATA[dummy@example.com (ralph.ronnquist)]]></author>
			<pubDate>Sun, 16 May 2021 22:00:15 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=29826#p29826</guid>
		</item>
		<item>
			<title><![CDATA[Kernel upgrade: apparmor and tomoyo]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=29825#p29825</link>
			<description><![CDATA[<p>Hello:</p><p>My 4.19 Devuan Beowulf, unlike ascii which had it disabled by default, set up apparmor as if I had actually asked for it.</p><p>I let it stay on and after reading around a bit, decided that it was not worth keeping around.<br />So I uninstalled it and added <span class="bbc">apparmor=0</span> to my kernel command line so it would not be asking for it.</p><p>Fast forward to my upgrading the installation to the 5.10 kernel: </p><div class="codebox"><pre><code>groucho@devuan:~$ uname -a
Linux devuan 5.10.0-0.bpo.3-amd64 #1 SMP Debian 5.10.13-1~bpo10+1 (2021-02-11) x86_64 GNU/Linux
groucho@devuan:~$ </code></pre></div><p>The 5.10 kernel also recommends <span class="bbc">apparmor</span>:</p><div class="codebox"><pre><code>groucho@devuan:~$ aptitude why apparmor
i   linux-image-5.10.0-0.bpo.3-amd64 Recommends apparmor
groucho@devuan:~$ </code></pre></div><p>So it does as the upgrade from <span class="bbc">ascii</span> to <span class="bbc">Beowulf</span> did and installs <span class="bbc">apparmor</span>.</p><p>Now ...<br />Seeing that my kernel command line had the <span class="bbc">apparmor=0</span> bit, you&#039;d think that it would leave it alone and skip installing <span class="bbc">apparmor</span>.<br />After all, it left the <em>rest</em> of the command line stanzas as they were.</p><p>But no ...<br />Not only did it install <span class="bbc">apparmor</span> but it <em>also</em> removed the <span class="bbc">apparmor=0</span> bit from the kernel command line.</p><p>No big deal: I just uninstalled it and returned the kernel command line to what I had set it.</p><p>Then while looking for clues as to what goes on in my system when I get a bad shutdown, I found this in <span class="bbc">dmesg</span>:</p><p>In <span class="bbc">dmesg</span> ie: at boot</p><div class="codebox"><pre><code>[   21.906451] Not activating Mandatory Access Control as /sbin/tomoyo-init does not exist.</code></pre></div><p>Also at shutdown:</p><p>In <span class="bbc">kern.log</span> and <span class="bbc">syslog</span>:</p><div class="codebox"><pre><code>May 16 13:57:16 devuan kernel: [14429.313238] Not activating Mandatory Access Control as /sbin/tomoyo-init does not exist.</code></pre></div><p>I had to look it up as I had no idea as to what <span class="bbc">tomoyo</span> was, let alone of its existence.</p><p>What is all this about?<br />Is it just me or am I seeing far too many (unrequired) Mandatory Access Control instances in the Linux kernel?</p><p>Cheers,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Sun, 16 May 2021 19:29:46 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=29825#p29825</guid>
		</item>
	</channel>
</rss>
