It does not matter. with symlinks and without.

apparmor blocks libreoffice no matter what is set, thats the point. and
that after the updates.

if libreoffice is enabled in apparmor, libreoffice is not able to oben
any files. ouput from logwhere apparmor was enabled:



eb 22 10:58:07 kid kernel: [  721.264143] audit: type=1400 
audit(1519293487.771:238): apparmor="DENIED" operation="open" 
profile="libreoffice-soffice" name="/etc/kde4rc" pid=3383 comm="soffice.bin" 
requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
Feb 22 10:58:07 kid kernel: [  721.264147] audit: type=1400 
audit(1519293487.771:239): apparmor="DENIED" operation="open" 
profile="libreoffice-soffice" name="/home/torsten/.kde/share/config/kdeglobals" 
pid=3383 comm="soffice.bin" requested_mask="r" denied_mask="r" fsuid=1000 
ouid=1000
Feb 22 10:58:07 kid kernel: [  721.265771] audit: type=1400 
audit(1519293487.772:240): apparmor="DENIED" operation="open" 
profile="libreoffice-soffice" name="/etc/kde4rc" pid=3383 comm="soffice.bin" 
requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
Feb 22 10:58:07 kid kernel: [  721.265796] audit: type=1400 
audit(1519293487.772:241): apparmor="DENIED" operation="open" 
profile="libreoffice-soffice" name="/home/torsten/.kde/share/config/kdeglobals" 
pid=3383 comm="soffice.bin" requested_mask="r" denied_mask="r" fsuid=1000 
ouid=1000
Feb 22 10:58:07 kid kernel: [  721.271664] audit: type=1400 
audit(1519293487.778:242): apparmor="DENIED" operation="exec" 
profile="libreoffice-soffice" name="/usr/lib/kde4/libexec/lnusertemp" pid=3394 
comm="sh" requested_mask="x" denied_mask="x" fsuid=1000 ouid=0
Feb 22 10:58:07 kid kernel: [  721.276967] audit: type=1400 
audit(1519293487.783:243): apparmor="DENIED" operation="exec" 
profile="libreoffice-soffice" name="/usr/bin/kdeinit4" pid=3396 
comm="soffice.bin" requested_mask="x" denied_mask="x" fsuid=1000 ouid=0
Feb 22 10:58:07 kid kernel: [  721.282745] audit: type=1400 
audit(1519293487.789:244): apparmor="DENIED" operation="open" 
profile="libreoffice-soffice" name="/home/torsten/.config/Trolltech.conf" 
pid=3383 comm="soffice.bin" requested_mask="wrc" denied_mask="wrc" fsuid=1000 
ouid=1000
Feb 22 10:58:07 kid kernel: [  721.282754] audit: type=1400 
audit(1519293487.789:245): apparmor="DENIED" operation="open" 
profile="libreoffice-soffice" name="/home/torsten/.config/Trolltech.conf" 
pid=3383 comm="soffice.bin" requested_mask="r" denied_mask="r" fsuid=1000 
ouid=1000

-- 
You received this bug notification because you are a member of AppArmor
Developers, which is subscribed to AppArmor Profiles.
https://bugs.launchpad.net/bugs/1284507

Title:
  apparmor profile for libreoffice

Status in AppArmor Profiles:
  Invalid
Status in libreoffice package in Ubuntu:
  Fix Released

Bug description:
  Support for apparmor profile for lo . Would be nice, if this was
  included under disabled until this receives wider testing.

  Why  -
  To limit the amount of damage from "virus" - 
  http://www.openoffice.org/press/statement-proof-of-concept-virus.html

To manage notifications about this bug go to:
https://bugs.launchpad.net/apparmor-profiles/+bug/1284507/+subscriptions

-- 
AppArmor mailing list
AppArmor@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/apparmor

Reply via email to