Hi Philippe,

I'm sending my reply both to you and #1138831.

Ср 19 авг 2026 @ 22:08 Philippe Caillaud <[email protected]>:

> Hello Lev,
>
> and first, thank you for your efforts on Debian !
>
> You declared this bug report (TOR browser crashing when saving a page) :
> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138831
>
> ...which looks to describe exactly the same problem as this older one :
> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1130690
> where two workarounds were proposed (the 2nd workaround proposed in the 
> other bug report is to add two lines to the AppArmor rules in 
> /etc/apparmor.d/torbrowser.Browser.firefox but it doesn't seem to work 
> on my system -- too bad !).
>
> ...so I've just send a merge resquest to the maintainer.
> You would probably want to merge them ?
>
> It's a really annoying bug, being unable to save/download from TOR browser !
> I hope that a real bug correction will be possible soon.
>
> I wonder if there would not be a problem with the package 
> glycin-loaders, because when I run :
> /usr/lib/x86_64-linux-gnu/gdk-pixbuf-2.0/gdk-pixbuf-query-loaders
>
> ...it gives me the list of glycin loaders in 
> /usr/lib/x86_64-linux-gnu/gdk-pixbuf-2.0/2.10.0/loaders :
> - avif
> - heif
> - jxl
> - webp
> - svg
> ...but not png or jpg.
>
> I understand that they are now compiled (or should be) in the main 
> library of libgdk-pixbuf-2.0-0, but I'm surprised that they don't appear 
> with this command.
>
> Anyway, that may be to a problem with AppArmor rules, as you suggested.

Thank you for your message.

As I see, #1138831 was merged with #1130690 and downgraded (from grave
to important) today by Thomas Ward.

I don't think that merging the suggested workaround into the package is
a good idea, since it downgrades security. The proper fix would be to
compare Apparmor rules for Mozilla Firefox and adopting them for
Torbrowser. (Since _probably_ Firefox does the same thing when saving
files to disk.)

With regards,
Lev

Reply via email to