Move apparmor-info, apparmor-watch to security-misc, enable systemd-journald audit transport

This commit is contained in:
Aaron Rainbolt 2025-10-30 23:05:19 -05:00
parent b168c37e84
commit d1e148eba7
No known key found for this signature in database
GPG key ID: A709160D73C79109
9 changed files with 164 additions and 0 deletions

5
debian/rules vendored
View file

@ -8,5 +8,10 @@
%:
dh $@ --with=config-package
override_dh_installman:
mkdir --parents -- debian/security-misc-shared/usr/share/man/man8
gzip -c -9 -- auto-generated-man-pages/apparmor-info.8 > debian/security-misc-shared/usr/share/man/man8/apparmor-info.8.gz
gzip -c -9 -- auto-generated-man-pages/apparmor-watch.8 > debian/security-misc-shared/usr/share/man/man8/apparmor-watch.8.gz
override_dh_installchangelogs:
dh_installchangelogs changelog.upstream upstream

View file

@ -118,6 +118,8 @@ usr/lib/sysctl.d/30_silent-kernel-printk.conf#security-misc-shared => /usr/lib/s
usr/lib/sysctl.d/990-security-misc.conf#security-misc-shared => /usr/lib/sysctl.d/990-security-misc.conf
usr/lib/sysctl.d/30_security-misc_kexec-disable.conf#security-misc-shared => /usr/lib/sysctl.d/30_security-misc_kexec-disable.conf
usr/lib/sysctl.d/30_security-misc_ptrace-disable.conf#security-misc-shared => /usr/lib/sysctl.d/30_security-misc_ptrace-disable.conf
usr/sbin/apparmor-info#security-misc-shared => /usr/sbin/apparmor-info
usr/sbin/apparmor-watch#security-misc-shared => /usr/sbin/apparmor-watch
usr/share/glib-2.0/schemas/30_security-misc.gschema.override#security-misc-shared => /usr/share/glib-2.0/schemas/30_security-misc.gschema.override
usr/share/doc/security-misc/fstab-vm#security-misc-shared => /usr/share/doc/security-misc/fstab-vm
usr/share/pam-configs/faillock-preauth-security-misc#security-misc-shared => /usr/share/pam-configs/faillock-preauth-security-misc

View file

@ -103,6 +103,9 @@ case "$1" in
chmod 0600 "${usbguard_config_file}"
fi
done
## Enable systemd-journald audit transport
deb-systemd-helper enable systemd-journald-audit.socket
;;
abort-upgrade|abort-remove|abort-deconfigure)