#773357 Update MySQL AppArmor profiles

Package:
mysql-server
Source:
mysql-8.0
Description:
MySQL database server and system database setup
Submitter:
u
Date:
2014-12-17 21:39:08 UTC
Severity:
wishlist
#773357#5
Date:
2014-12-17 12:41:25 UTC
From:
To:
Talking about the documentation at wiki.d.o/AppArmor/Progress,
I've been asked to report this bug here by cboltz.

<cboltz> it lists "mysql 5.5" in the "included in the Jessie package"
section
<cboltz> there is also a mysql profile in upstream extra-profiles directory
<cboltz> and I have a patch pending on the ML to improve it
<cboltz> it would probably be a good idea to merge all this and to
include it in the upstream set of active  profiles ;-)

#773357#10
Date:
2014-12-17 17:01:07 UTC
From:
To:
Hi,

u wrote (17 Dec 2014 12:41:25 GMT) :

!= "upstream extra-profiles directory"

(The latter lands in /usr/share/doc/apparmor-profiles/extras/,
shipped by the apparmor-profiles package.)

This is correct.

Right. We don't ship it in any Debian package as far as I know.
IMO it's better to keep shipping the same profile as Ubuntu, directly
via the MySQL packages.

We ship /etc/apparmor.d/abstractions/mysql in the apparmor package,
though, which is expected since it lives in profiles/apparmor.d/ in
the main upstream bzr.

Right, the changes in the profile shipped in Ubuntu/Debian's MySQL
packages should be merged with upstream' ones => this bug should be
reassigned to the corresponding package, and probably usertagged so
that it's on our (pkg-apparmor-team's) radar.

Also, I don't think this is RC for Jessie, so likely this bug should
be retitled too. And IMO it should be severity = minor or wishlist.

Cheers,

#773357#23
Date:
2014-12-17 19:38:12 UTC
From:
To:
Hi,

intrigeri:

ack.

ack.

You are absolutely correct, I should have verified this before filing
someone else's bug report. I reassigned the bug to the correct package.

Concerning the usertag, I think this could be "aa-update-profile", what
do you think?

Triaged accordingly.

Cheers,
u.