The suggested apparmor changes from Message 10 on bug #1130690 are insecure and incomplete (and too wide).

However, as Firefox (and Tor Browser) both use glycin under the hood *and* use `bwrap` for sandboxing, there is a set of policies in `abstractions/glycin` on AppArmor that include proper glycin:bwrap settings AND all other related glycin requirements.

A patched version of the package is in the process of being uploaded, 0.3.9-2, which includes modifications to the torbrowser.Browser.firefox AppArmor policies that includes the glycin abstractions, and should solve this issue.

Reply via email to