On 2017-12-04 16:52, Christian Boltz wrote:
> I'm afraid you have to coordinate the change better - declaring a
> variable twice causes a parser error:
Thanks! Duplicate rules manages to merge, but not variables...
1. We have to be aware for profiles that _already_ includes tunables/sys then...
"Downgrade" them to not use "@{sys}" (remove include "tunables/sys" too!).
2. Then, update "tunables/global" together with "apparmor.d/abstractios" and "apparmor.d/*" profiles in one go.
3. Finally, only after all these have been shipped on all relevant distributions, we can update profiles from
"profiles/extra" directory and "apparmor-profiles" repository, and the else (Libreoffice that has it's own, etc).
On 2017-12-04 16:52, Christian Boltz wrote:
> I'm afraid you have to coordinate the change better - declaring a
> variable twice causes a parser error:
Thanks! Duplicate rules manages to merge, but not variables...
1. We have to be aware for profiles that _already_ includes tunables/sys then...
"Downgrade" them to not use "@{sys}" (remove include "tunables/sys" too!).
2. Then, update "tunables/global" together with "apparmor. d/abstractios" and "apparmor.d/*" profiles in one go.
3. Finally, only after all these have been shipped on all relevant distributions, we can update profiles from
"profiles/extra" directory and "apparmor-profiles" repository, and the else (Libreoffice that has it's own, etc).