Skip to content

Add AppArmor support to the install script#6647

Merged
kit-ty-kate merged 1 commit intoocaml:masterfrom
kit-ty-kate:apparmor-install
Oct 16, 2025
Merged

Add AppArmor support to the install script#6647
kit-ty-kate merged 1 commit intoocaml:masterfrom
kit-ty-kate:apparmor-install

Conversation

@kit-ty-kate
Copy link
Copy Markdown
Member

@kit-ty-kate kit-ty-kate commented Aug 22, 2025

Fixes #5968
Was tested with success in #5968 (comment)

For reference, here is the upstream apparmor profile for opam (when located at /usr/bin/opam): https://gitlab.com/apparmor/apparmor/-/blob/65e6620014759ac1b671bf982b8c67eac2e789fe/profiles/apparmor.d/opam

@kit-ty-kate kit-ty-kate added this to the 2.5.0~alpha1 milestone Aug 22, 2025
@kit-ty-kate kit-ty-kate requested a review from rjbou October 1, 2025 12:38
@smorimoto
Copy link
Copy Markdown
Member

Gentle ping!

Copy link
Copy Markdown
Collaborator

@rjbou rjbou left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Light approval. This PR was tested successfully by users that had the issue, and i tested it locally successfully too. But I'm not an apparmor expert, it's difficult for me to validate if it is the good level of permission (though it is mimicking official opam one).
Let's merge it and use the 2.5 alpha to supervise and have feedback on it.

@kit-ty-kate kit-ty-kate merged commit 2c4d38c into ocaml:master Oct 16, 2025
3 checks passed
@kit-ty-kate kit-ty-kate deleted the apparmor-install branch October 16, 2025 17:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

opam broken on ubuntu 24.04 (bwrap: operation not permitted)

3 participants