apparmor: cleanup

- cleanup template
- enable more checks
- remove old custom php-fpm profile
- allow cross building perl library
- move apparmor syscall and library man pages to libapparmor-devel
- add missing python dependencies
- add patch for xbps .new-* style files
This commit is contained in:
Duncaen
2026-08-15 19:07:28 +02:00
committed by Duncan Overbruck
parent 7cd50f49c4
commit 909fbb4b3e
4 changed files with 145 additions and 91 deletions
@@ -1,45 +0,0 @@
# vim:syntax=apparmor
abi <abi/3.0>,
# NOTE: This profile uses TCP sockets by default
# If you wish for php-fpm to listen to unix socket,
# add the following permission to local/usr.bin.php-fpm
# /path/to/your/unix/socket w,
include <tunables/global>
# This is PHP open_basedir where script can only be executed from.
# /home, /tmp have been removed to not open permissions too widely
# /usr/share/pear have been removed to have its own permission
@{PHP_BASEDIRS} = /srv/www/ /var/www/ /usr/share/webapps/
profile php-fpm /usr/bin/php-fpm {
include <abstractions/base>
include <abstractions/nameservice>
include <abstractions/openssl>
include <abstractions/php>
capability setgid,
capability setuid,
capability kill,
/etc/php/php-fpm.conf r,
/etc/php/php-fpm.d/* r,
# This is set to make php-fpm work by default, but if you don't use these paths
# add "deny @{PHP_BASEDIRS}/** r," to local.usr.bin.php-fpm and add read rights
# to where your PHP app is located
@{PHP_BASEDIRS}/** r,
/usr/bin/php-fpm mr,
/usr/share/pear/** r,
/usr/share/php/fpm/status.html r,
/var/log/php-fpm.log w,
# Site-specific additions and overrides. See local/README for details.
include if exists <local/usr.bin.php-fpm>
}
@@ -0,0 +1,85 @@
From cb4141646e5fd58261cc345e02a7f0c88e24a07d Mon Sep 17 00:00:00 2001
From: Duncan Overbruck <mail@duncano.de>
Date: Sat, 1 Aug 2026 17:47:11 +0200
Subject: [PATCH] add xbps style backup files for void linux
---
libraries/libapparmor/src/private.c | 4 ++++
parser/apparmor_parser.pod | 2 +-
utils/apparmor/common.py | 3 +++
utils/test/test-aa.py | 3 +++
4 files changed, 11 insertions(+), 1 deletion(-)
diff --git a/libraries/libapparmor/src/private.c b/libraries/libapparmor/src/private.c
index 39b578972..afca9cc5f 100644
--- a/libraries/libapparmor/src/private.c
+++ b/libraries/libapparmor/src/private.c
@@ -17,6 +17,7 @@
#include <dirent.h>
#include <endian.h>
#include <errno.h>
+#include <fnmatch.h>
#include <fcntl.h>
#include <stdarg.h>
#include <stdbool.h>
@@ -179,6 +180,9 @@ int _aa_is_blacklisted(const char *name)
}
}
+ if (fnmatch(name, "*.new-*", 0) == 0)
+ return 1;
+
return 0;
}
diff --git a/parser/apparmor_parser.pod b/parser/apparmor_parser.pod
index 470585202..b5a788ab2 100644
--- a/parser/apparmor_parser.pod
+++ b/parser/apparmor_parser.pod
@@ -47,7 +47,7 @@ name containing a set of profiles. If a directory is specified then the
B<apparmor_parser> will try to do a profile load for each file in the
directory that is not a dot file, or explicitly black listed (*.dpkg-new,
*.dpkg-old, *.dpkg-dist, *.dpkg-bak, *.dpkg-remove, *.pacsave, *.pacnew,
-*.rpmnew, *.rpmsave, *.orig, *.rej, *~).
+*.rpmnew, *.rpmsave, *.orig, *.rej, *~, *.new-*).
The B<apparmor_parser> will fall back to taking input from standard input if
a profile or directory is not supplied.
diff --git a/utils/apparmor/common.py b/utils/apparmor/common.py
index 73d1c6fe3..8f6bbbb45 100644
--- a/utils/apparmor/common.py
+++ b/utils/apparmor/common.py
@@ -18,6 +18,7 @@ import signal
import sys
import termios
import tty
+import fnmatch
from tempfile import NamedTemporaryFile
DEBUGGING = False
@@ -183,6 +184,8 @@ def is_skippable_file(path):
'.pacsave', '.pacnew', '.rpmnew', '.rpmsave', '.orig', '.rej', '~')
if basename.endswith(skippable_suffix):
return True
+ if fnmatch.fnmatch(basename, "*.new-*"):
+ return True
return False
diff --git a/utils/test/test-aa.py b/utils/test/test-aa.py
index c51d18671..44a788073 100644
--- a/utils/test/test-aa.py
+++ b/utils/test/test-aa.py
@@ -505,6 +505,9 @@ class AaTest_is_skippable_file(AATest):
def test_skippable_16(self):
self.assertTrue(is_skippable_file('README'))
+ def test_skippable_17(self):
+ self.assertTrue(is_skippable_file('bin.ping.new-1.0_1'))
+
class AaTest_parse_profile_data(AATest):
def test_parse_empty_profile_01(self):
--
2.55.0
@@ -0,0 +1,11 @@
--- a/libraries/libapparmor/swig/perl/Makefile.am
+++ b/libraries/libapparmor/swig/perl/Makefile.am
@@ -11,7 +11,7 @@
LibAppArmor.pm: libapparmor_wrap.c
Makefile.perl: Makefile.PL LibAppArmor.pm
- $(PERL) $< PREFIX=$(prefix) MAKEFILE=$@
+ $(PERL) $< PREFIX=$(prefix) MAKEFILE=$@ CC=$(CC) LD=$(CC)
sed -ie 's/LD_RUN_PATH="\x24(LD_RUN_PATH)"//g' Makefile.perl
sed -ie 's/^LD_RUN_PATH.*//g' Makefile.perl
+49 -46
View File
@@ -1,18 +1,18 @@
# Template file for 'apparmor'
pkgname=apparmor
version=4.1.7
revision=1
revision=2
build_wrksrc=libraries/libapparmor
build_helper="python3"
build_style=gnu-configure
conf_files="/etc/apparmor.d/local/* /etc/apparmor/*"
make_dirs="/etc/apparmor.d/disable 0755 root root"
configure_args="$(vopt_with python) $(vopt_with perl)"
hostmakedepends="bison flex gettext python3 which python3-setuptools pkg-config
perl autoconf-archive automake libtool python3-packaging-bootstrap $(vopt_if python swig)"
makedepends="$(vopt_if python python3-devel)"
depends="runit-void-apparmor libapparmor-${version}_${revision} python3-notify2
python3-psutil python3-dbus iproute2"
checkdepends="dejagnu"
hostmakedepends="bison flex gettext pkg-config autoconf-archive automake which libtool
python3 python3-setuptools python3-packaging-bootstrap $(vopt_if perl perl)"
makedepends="$(vopt_if python python3-devel) pam-devel $(vopt_if perl perl)"
depends="runit-void-apparmor iproute2"
checkdepends="dejagnu "
short_desc="Mandatory access control to restrict programs"
maintainer="Orphaned <orphan@voidlinux.org>"
license="GPL-2.0-only"
@@ -27,56 +27,58 @@ CFLAGS="-D_LARGEFILE64_SOURCE"
CXXFLAGS="-D_LARGEFILE64_SOURCE"
build_options="python perl"
build_options_default="python"
case "$XBPS_TARGET_MACHINE" in
x86_64*|aarch64*|i686*)
build_options_default+=" python"
;;
esac
if [ -z "$CROSS_BUILD" ]; then
build_options_default+=" perl"
if [ "${build_option_perl}" -o "${build_option_python}" ]; then
hostmakedepends+=" swig"
fi
if [ "${build_option_python}" ]; then
depends+=" python3-notify2 python3-psutil python3-dbus python3-tkinter python3-gobject"
checkdepends+=" flake8 python3-notify2 python3-psutil python3-dbus python3-tkinter python3-gobject"
fi
post_patch() {
# add custom profiles
cp -vn "${FILESDIR}"/profiles/* "${wrksrc}/profiles/apparmor.d/"
}
pre_configure() {
cd ${wrksrc}/libraries/libapparmor
autoreconf -fiv
}
pre_build() {
# Replace release profiles with our own
cd ${wrksrc}
cp ${FILESDIR}/profiles/* profiles/apparmor.d/
}
post_build() {
cd ${wrksrc}
make ${makejobs} -C binutils
make ${makejobs} -C utils
make ${makejobs} -C parser
make ${makejobs} -C profiles
make ${makejobs} -C "${wrksrc}/binutils"
make ${makejobs} -C "${wrksrc}/parser"
make ${makejobs} -C "${wrksrc}/utils"
make ${makejobs} -C "${wrksrc}/changehat/pam_apparmor"
make ${makejobs} -C "${wrksrc}/profiles"
}
post_install() {
cd ${wrksrc}
commonflags="DESTDIR=\"${DESTDIR}\" SBINDIR=\"${DESTDIR}/usr/bin\" USR_SBINDIR=\"${DESTDIR}/usr/bin\""
make $commonflags install -C binutils
make $commonflags \
BINDIR="${DESTDIR}/usr/bin" \
VIM_INSTALL_PATH="${DESTDIR}/usr/share/vim/vimfiles/syntax" \
install -C utils
make $commonflags \
APPARMOR_BIN_PREFIX="${DESTDIR}/usr/lib/apparmor" \
install -C parser
make DESTDIR="${DESTDIR}" install -C profiles
do_check() {
make ${makejobs} -C "${wrksrc}/libraries/libapparmor" check
make ${makejobs} -C "${wrksrc}/binutils" check
make ${makejobs} -C "${wrksrc}/parser" check
make ${makejobs} -C "${wrksrc}/utils" check
# make ${makejobs} -C "${wrksrc}/profiles" check # broken
make ${makejobs} -C "${wrksrc}/profiles" check-parser
make ${makejobs} -C "${wrksrc}/profiles" check-abstractions.d
}
# requires perl bindings not generated when cross-compiling
if [ -z "$build_option_perl" ]; then
rm -f ${DESTDIR}/usr/bin/aa-notify
fi
do_install() {
local _args=(
"DESTDIR=\"${DESTDIR}\""
"SBINDIR=\"${DESTDIR}/usr/bin\""
"BINDIR=\"${DESTDIR}/usr/bin\""
"USR_SBINDIR=\"${DESTDIR}/usr/bin\""
)
make -C "${wrksrc}/libraries/libapparmor" "${_args[@]}" install
make -C "${wrksrc}/binutils" "${_args[@]}" install
make -C "${wrksrc}/utils" "${_args[@]}" VIM_INSTALL_PATH="${DESTDIR}/usr/share/vim/vimfiles/syntax" install
make -C "${wrksrc}/parser" "${_args[@]}" APPARMOR_BIN_PREFIX="${DESTDIR}/usr/lib/apparmor" install
make -C "${wrksrc}/profiles" "${_args[@]}" install
vinstall utils/aa-notify.desktop 644 usr/share/applications
vinstall "${wrksrc}/utils/aa-notify.desktop" 644 usr/share/applications
vdoc "${FILESDIR}/README.voidlinux"
}
@@ -90,6 +92,7 @@ libapparmor_package() {
fi
if [ "$build_option_python" ]; then
vmove "${py3_sitelib}/LibAppArmor*"
vmove "${py3_sitelib}/_LibAppArmor*.so"
fi
vmove usr/share/man/man2
vmove usr/share/man/man3
@@ -99,7 +102,7 @@ libapparmor_package() {
libapparmor-devel_package() {
short_desc+=" - Library development files"
license="LGPL-2.1-only"
depends="lib${sourcepkg}-${version}_${revision}"
depends="libapparmor-${version}_${revision}"
pkg_install() {
vmove usr/include
vmove "usr/lib/*.a"