home.social

#apparmor — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #apparmor, aggregated by home.social.

  1. BTW, @BrodieOnLinux - I have to repeat my problems with #snap packages:

    * single vendor repos, the vendor being canonical
    * #AppArmor is painful - and "not invented here syndrome" in regards to SELinux (and is also a bit painful to configure)
    * Desktop integration was an afterthought, as evident by how the modal boxes and UI for snaps look tacked on and out of place, because snaps was meant as an alternative to docker

    Flatpak won because of not doing all this.

  2. [Перевод] От capabilities к AppArmor: что реально остановит атакующего в контейнере

    Скомпрометированный контейнер — это момент истины для всех настроек безопасности: злоумышленник уже внутри, команды выполняются, и дальше важно понять, что действительно ограничит его действия. В этой статье на одной рабочей нагрузке разбирается, как capabilities, seccomp и AppArmor закрывают разные участки атаки в Kubernetes, где каждый механизм упирается в свои пределы и почему защита контейнеров работает только как набор слоёв. Разобрать защиту

    habr.com/ru/companies/otus/art

    #безопасность_Kubernetes #безопасность_контейнеров #container_security #capabilities #seccomp #LSM #AppArmor #securityContext #защита_кластера

  3. Firefox crashes after replacing snap with APT build on Ubuntu 26.04 LTS - Sandbox: CanCreateUserNamespace() EPERM, Wayland bind error, AppArmor denial #firefox #wayland #apparmor #2604

    askubuntu.com/q/1566816/612

  4. @zhenech

    Why #AppArmor and sysctl hardening makes a good job by breaking exploit chains:

    Ubuntu note: AppArmor restricts unprivileged user namespaces by default. You must first run:
    
    sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0
    
  5. These #apparmor profiles are checked when running 'apt update' on #Ubuntu and #LinuxMint, so the kernel log/dmesg would fill up just from the update manager running it periodically.

  6. 🛡️ MariaDB's new AppArmor profile is now enforcing in Debian unstable and heading to Ubuntu 26.04. I developed it against 7,000+ tests to minimize false positives, full story at optimizedbyotto.com/post/new-a

    If you are a dba/sysadmin, check your logs and share feedback via the Debian bug tracker.

    #AppArmor #MariaDB #opensource

  7. A 7-year-old Linux flaw dubbed #CrackArmor exposes 12.6 million systems using AppArmor. Researchers found that it can enable root access, container escape, and security bypass. Patch immediately.

    Read: hackread.com/crackarmor-vulner

    #Linux #CyberSecurity #AppArmor #Vulnerability

  8. #apparmor local root: who's going to watch the watchers episode 202603! #ubuntu people should bump their #kernel and consider switching to unprivileged alternatives such as #sydbox ;): openwall.com/lists/oss-securit #linux #security

  9. CrackArmor: Multiple vulnerabilities in #AppArmor "Bypassing Ubuntu's user-namespace restrictions
    AppArmor + Sudo + Postfix = root
    Kernel vulnerabilities". seclists.org/oss-sec/2026/q1/3 #infosec #qualys

  10. #CrackArmor: Multiple vulnerabilities in #AppArmor

    Blogpost: blog.qualys.com/vulnerabilitie

    Advisory: cdn2.qualys.com/advisory/2026/

    These vulnerabilities allow a local attacker to bypass the security normally provided by AppArmor. Also, in some situations, it allows privilege escalation to root by selectively blocking specific syscalls.

    #infosec #cybersecurity #qualys

  11. What's that? #ubuntusnaps are badly designed for desktop usage? Who knew?

    Scroll my feed whydontcha.

    #Flatpak, #AppImage, take your pick. Much better integration and uses standard #SELinux - instead of having to suffer #Canonical and their #NotInventedHere syndrome with #AppArmor.

    Microsoft's VS Code in Ubuntu's Snap Format Eats Up Disk Space Like Bloatware Even After Removal
    itsfoss.com/news/vscode-snap-d

  12. #apparmor error in #debian after update:

    AppArmor-Analysefehler f?r /etc/apparmor.d in profile /etc/apparmor.d/tunables/home in Zeile 15: syntax error, unexpected TOK_EQUALS, expecting TOK_MODE

    It seems, that I am not the only one:

    forums.debian.net/viewtopic.ph

    Any tips?

  13. I have developed mping-sender over the last few days. It is a simple program that sends a UDP packet to a (freely selectable) multicast address every second. It is therefore well suited for testing multicast. It is partially compatible with the mping client.

    Furthermore, it is protected by landlock, seccomp, libcap-ng, AppArmor, and systemd.

    Source code: codeberg.org/mark22k/mping-sen

    #Networking #Programming #dn42 #Multicast #landlock #AppArmor #libseccomp #seccomp #systemd #libcapng

  14. I have developed mping-sender over the last few days. It is a simple program that sends a UDP packet to a (freely selectable) multicast address every second. It is therefore well suited for testing multicast. It is partially compatible with the mping client.

    Furthermore, it is protected by landlock, seccomp, libcap-ng, AppArmor, and systemd.

    Source code: codeberg.org/mark22k/mping-sen

    #Networking #Programming #dn42 #Multicast #landlock #AppArmor #libseccomp #seccomp #systemd #libcapng

  15. I have developed mping-sender over the last few days. It is a simple program that sends a UDP packet to a (freely selectable) multicast address every second. It is therefore well suited for testing multicast. It is partially compatible with the mping client.

    Furthermore, it is protected by landlock, seccomp, libcap-ng, AppArmor, and systemd.

    Source code: codeberg.org/mark22k/mping-sen

    #Networking #Programming #dn42 #Multicast #landlock #AppArmor #libseccomp #seccomp #systemd #libcapng

  16. I have developed mping-sender over the last few days. It is a simple program that sends a UDP packet to a (freely selectable) multicast address every second. It is therefore well suited for testing multicast. It is partially compatible with the mping client.

    Furthermore, it is protected by landlock, seccomp, libcap-ng, AppArmor, and systemd.

    Source code: codeberg.org/mark22k/mping-sen

    #Networking #Programming #dn42 #Multicast #landlock #AppArmor #libseccomp #seccomp #systemd #libcapng

  17. I have developed mping-sender over the last few days. It is a simple program that sends a UDP packet to a (freely selectable) multicast address every second. It is therefore well suited for testing multicast. It is partially compatible with the mping client.

    Furthermore, it is protected by landlock, seccomp, libcap-ng, AppArmor, and systemd.

    Source code: codeberg.org/mark22k/mping-sen

    #Networking #Programming #dn42 #Multicast #landlock #AppArmor #libseccomp #seccomp #systemd #libcapng

  18. #apparmor output on my system and according to my search as seen on a lot of #ubuntu based systems:

    apparmor="STATUS" operation="profile_load" profile="unconfined" name=4D6F6E676F444220436F6D70617373

    So where does this entry "4D..." reside ?
    All the other entries in the otuput of dmesg have an equivalent in /etc/apparmor.d
    And no, there is no such profile with that name on my machine.

  19. crazytrace, my network simulation program that generates a crazy topology behind a TAP device to test traceroute implementations, now has an apparmor profile.

    Furthermore, I have now implemented capability dropping with libcap-ng, landlock sandboxing (via a blacklist), and seccomp sandboxing (via a blacklist).

    codeberg.org/mark22k/crazytrac
    codeberg.org/mark22k/crazytrac

    #crazytrace #traceroute #Networking #Programming #Security #apparmor #libcap #libcapng #landlock #seccomp

  20. 🚀 Oh, the thrilling saga of playing Russian nesting dolls with #containers on Proxmox! 🤯 Watch as our hero battles #AppArmor and cryptic errors, only to discover the ancient scrolls of #GitHub held the mystical solution all along. 🎉 Apparently, the answer was just a version upgrade – who would've thought? 🙄
    blog.vasi.li/adventures-in-upg #Proxmox #VersionUpgrade #TechSaga #HackerNews #ngated

  21. I switched from to on my desktop. For me Firejail's configuration is much less cryptic than AppArmor's :) But I noticed there was no syntax highlighting for Firejail config files in , so I created a simple mode using SMIE:

    github.com/grafov/firejail-mode

    Because GNU/Emacs should have a mode for any task, you know!

  22. I switched from #AppArmor to #Firejail on my desktop. For me Firejail's configuration is much less cryptic than AppArmor's :) But I noticed there was no syntax highlighting for Firejail config files in #Emacs, so I created a simple mode using SMIE:

    github.com/grafov/firejail-mode

    Because GNU/Emacs should have a mode for any task, you know! #butterfly

  23. I switched from #AppArmor to #Firejail on my desktop. For me Firejail's configuration is much less cryptic than AppArmor's :) But I noticed there was no syntax highlighting for Firejail config files in #Emacs, so I created a simple mode using SMIE:

    github.com/grafov/firejail-mode

    Because GNU/Emacs should have a mode for any task, you know! #butterfly

  24. I switched from #AppArmor to #Firejail on my desktop. For me Firejail's configuration is much less cryptic than AppArmor's :) But I noticed there was no syntax highlighting for Firejail config files in #Emacs, so I created a simple mode using SMIE:

    github.com/grafov/firejail-mode

    Because GNU/Emacs should have a mode for any task, you know! #butterfly

  25. I switched from #AppArmor to #Firejail on my desktop. For me Firejail's configuration is much less cryptic than AppArmor's :) But I noticed there was no syntax highlighting for Firejail config files in #Emacs, so I created a simple mode using SMIE:

    github.com/grafov/firejail-mode

    Because GNU/Emacs should have a mode for any task, you know! #butterfly

  26. Flatpak is broken in Ubuntu 25.10 Questing Quokka. Here's a temporary solution to fix broken flatpak issue in Ubuntu 25.10.

    Step-by-Step: ostechnix.com/fix-broken-flatp

    #Ubuntu2510 #Flatpak #Apparmor #Troubleshooting #Linux

  27. [Перевод] Как защитить Kubernetes на уровне ядра Linux

    Как защитить Kubernetes, если злоумышленник попытается выбраться из контейнера на хост? Рафаэль Натали предлагает многоуровневый подход: настройка Security Context, отказ от лишних прав, запуск контейнеров без root-доступа, а также усиление защиты с помощью AppArmor и seccomp.

    habr.com/ru/companies/flant/ar

    #security_contexts #apparmor #seccomp #kubernetes #noroot_containers #linux_namespace #runAsUser #безопасность_kubernetes #linux

  28. [Перевод] Как защитить Kubernetes на уровне ядра Linux

    Как защитить Kubernetes, если злоумышленник попытается выбраться из контейнера на хост? Рафаэль Натали предлагает многоуровневый подход: настройка Security Context, отказ от лишних прав, запуск контейнеров без root-доступа, а также усиление защиты с помощью AppArmor и seccomp.

    habr.com/ru/companies/flant/ar

    #security_contexts #apparmor #seccomp #kubernetes #noroot_containers #linux_namespace #runAsUser #безопасность_kubernetes #linux