The suggested apparmor changes from Message 10 on bug #1130690 are
insecure and incomplete (and too wide).
However, as Firefox (and Tor Browser) both use glycin under the hood
*and* use `bwrap` for sandboxing, there is a set of policies in
`abstractions/glycin` on AppArmor that include proper glycin:bwrap
settings AND all other related glycin requirements.
A patched version of the package is in the process of being uploaded,
0.3.9-2, which includes modifications to the torbrowser.Browser.firefox
AppArmor policies that includes the glycin abstractions, and should
solve this issue.