Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2022-05-06 Thread Paul Gevers

Hi all,

On Mon, 22 Feb 2021 18:41:15 +0100 Dennis Filder  wrote:

Fix was in v2.13.91 (c4324f54ee16e648ba91f3e9c66af13ab3b1754c) [1]
which removed the relevant codepath.


Is the current phase of the bookworm release a good moment to apply this?


If anyone still deems this worth addressing in 2.13.1, the attached
patch fontconfig-2.13.1-909750-access-w_ok.patch silences the warning
through an added writability check.


It's policy violation, I think it's worth to try and fix it.


However, while looking into this I ran into test suite issues:

- test/run-test-conf.sh needs dash.patch to work with dash as /bin/sh

- test/run-test.sh fails if /bin/bwrap (package bubblewrap) is
  installed; disable-bwrap.patch patches it out.


This last one can probably be dealt with via an Build-Conflicts stanza?


1: 
https://gitlab.freedesktop.org/fontconfig/fontconfig/-/commit/c4324f54ee16e648ba91f3e9c66af13ab3b1754c


Paul


OpenPGP_signature
Description: OpenPGP digital signature


Processed: Re: Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2021-02-22 Thread Debian Bug Tracking System
Processing control commands:

> tag -1 + patch
Bug #909750 [libfontconfig1] applications tries to write to /usr/* directories 
via libfontconfig1
Added tag(s) patch.

-- 
909750: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=909750
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2021-02-22 Thread Dennis Filder
Control: tag -1 + patch

Fix was in v2.13.91 (c4324f54ee16e648ba91f3e9c66af13ab3b1754c) [1]
which removed the relevant codepath.

If anyone still deems this worth addressing in 2.13.1, the attached
patch fontconfig-2.13.1-909750-access-w_ok.patch silences the warning
through an added writability check.

However, while looking into this I ran into test suite issues:

- test/run-test-conf.sh needs dash.patch to work with dash as /bin/sh

- test/run-test.sh fails if /bin/bwrap (package bubblewrap) is
  installed; disable-bwrap.patch patches it out.

IMO this bug is also a good candidate for a bullseye-ignore if no new
upload is made because it only manifested with a non-Debian AppArmor
profile for Firefox, breaks essentially nothing, and also because I
had to manually delete .uuid files below /usr/share/fonts/* to get it
to reproduce.

Regards,
Dennis.

1: 
https://gitlab.freedesktop.org/fontconfig/fontconfig/-/commit/c4324f54ee16e648ba91f3e9c66af13ab3b1754c


fontconfig-2.13.1-909750-access-w_ok.patch.gz
Description: application/gzip


dash.patch.gz
Description: application/gzip


disable-bwrap.patch.gz
Description: application/gzip


Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2021-02-06 Thread Paul Gevers
Hi all,

On Wed, 17 Apr 2019 17:46:19 +0200 Chris Hofstaedtler 
wrote:
> * Niels Thykier  [190413 18:28]:
> > Vincas Dargis:
> > > On 2019-04-13 12:50, Niels Thykier wrote:
> > >> What is the status of this bug? AFAICT, we have *some* fixes from
> > >> upstream but Chris's mail implies that the bug is not completely fixed.
> > > 
> > > This bug disappeared from my logs long time ago, at least haven't seen
> > > any application reproducing it so far.
> > 
> > Interestingly, Chris (just Cc'ed) claims to have reproduced it about a
> > week ago with libfontconfig1:amd64 using strace and to my knowledge
> > libfontconfig1 hasn't changed for months in sid/buster.
> > 
> > @Chris: Just to confirm: Do you still see the issue?
> 
> I've given this another try, and can hopefully shed some light:
> 
> In a local X session with fluxbox, I don't see the EACCESS in
> strace.
> 
> In an ssh session with X11 forwarding to an XQuartz server, I still
> get the EACCESS.
> 
> Couldn't try with a remote Xorg server though, maybe someone else
> can verify this.

Seems like not much has happened on this bug for about two years and I
don't see anything in the changelog pointing at potential fixes, so I
*assume* the bug still applies. Can somebody confirm?

Has anybody tried to find the upstream commit that may exist based on
the quote that Niels pasted?

Paul



OpenPGP_signature
Description: OpenPGP digital signature


Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2019-05-20 Thread Laurent Bigonville

Le 20/05/19 à 15:28, Vincent Lefevre a écrit :

After upgrading fontconfig to 2.13.1-2, I now have lots of .uuid files:

[...]


This is expected as dpkg postinst scripts calls fc-cache



Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2019-05-20 Thread Vincent Lefevre
After upgrading fontconfig to 2.13.1-2, I now have lots of .uuid files:

-rw-r--r-- 1 root staff 36 2019-05-20 13:08:26 /usr/local/share/fonts/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:26 /usr/share/fonts/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 /usr/share/fonts/X11/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 /usr/share/fonts/X11/Type1/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 
/usr/share/fonts/X11/encodings/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:31 
/usr/share/fonts/X11/encodings/large/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 /usr/share/fonts/X11/misc/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 /usr/share/fonts/X11/util/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 /usr/share/fonts/cMap/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 /usr/share/fonts/cmap/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 /usr/share/fonts/eot/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 
/usr/share/fonts/eot/font-awesome/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 /usr/share/fonts/fonts-go/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 /usr/share/fonts/opentype/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 
/usr/share/fonts/opentype/cabin/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 
/usr/share/fonts/opentype/ebgaramond/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 
/usr/share/fonts/opentype/font-awesome/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 
/usr/share/fonts/opentype/fonts-hosny-amiri/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 
/usr/share/fonts/opentype/freefont/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 
/usr/share/fonts/opentype/gentiumplus/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 
/usr/share/fonts/opentype/ipaexfont-gothic/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 
/usr/share/fonts/opentype/ipaexfont-mincho/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 
/usr/share/fonts/opentype/ipafont-gothic/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 
/usr/share/fonts/opentype/ipafont-mincho/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 
/usr/share/fonts/opentype/linux-libertine/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 
/usr/share/fonts/opentype/lobster/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/opentype/lobstertwo/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/opentype/noto/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/opentype/stix-word/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/opentype/stix/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/opentype/tlwg/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 /usr/share/fonts/svg/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/svg/font-awesome/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:27 /usr/share/fonts/truetype/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/adf/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/arphic-bkai00mp/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/arphic-bsmi00lp/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/arphic-gbsn00lp/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/arphic-gkai00mp/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/artemisia/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/asana-math/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/baekmuk/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/baskerville/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/bodoni-classic/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/comfortaa/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/complutum/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/croscore/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/crosextra/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/dejavu/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/didot-classic/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/didot/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/droid/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/ebgaramond/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/font-awesome/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/freefont/.uuid
-rw-r--r-- 1 root root  36 2019-05-20 13:08:28 
/usr/share/fonts/truetype/gazis/.uuid
-rw-r--r-- 1 root root  36 2019-0

Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2019-04-17 Thread Chris Hofstaedtler
* Niels Thykier  [190413 18:28]:
> Vincas Dargis:
> > On 2019-04-13 12:50, Niels Thykier wrote:
> >> What is the status of this bug? AFAICT, we have *some* fixes from
> >> upstream but Chris's mail implies that the bug is not completely fixed.
> > 
> > This bug disappeared from my logs long time ago, at least haven't seen
> > any application reproducing it so far.
> 
> Interestingly, Chris (just Cc'ed) claims to have reproduced it about a
> week ago with libfontconfig1:amd64 using strace and to my knowledge
> libfontconfig1 hasn't changed for months in sid/buster.
> 
> @Chris: Just to confirm: Do you still see the issue?

I've given this another try, and can hopefully shed some light:

In a local X session with fluxbox, I don't see the EACCESS in
strace.

In an ssh session with X11 forwarding to an XQuartz server, I still
get the EACCESS.

Couldn't try with a remote Xorg server though, maybe someone else
can verify this.

Chris



Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2019-04-13 Thread Niels Thykier
Vincas Dargis:
> On 2019-04-13 12:50, Niels Thykier wrote:
>> What is the status of this bug? AFAICT, we have *some* fixes from
>> upstream but Chris's mail implies that the bug is not completely fixed.
> 
> This bug disappeared from my logs long time ago, at least haven't seen
> any application reproducing it so far.

Interestingly, Chris (just Cc'ed) claims to have reproduced it about a
week ago with libfontconfig1:amd64 using strace and to my knowledge
libfontconfig1 hasn't changed for months in sid/buster.

@Chris: Just to confirm: Do you still see the issue?

Thanks,
~Niels



Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2019-04-13 Thread Vincas Dargis

On 2019-04-13 12:50, Niels Thykier wrote:

What is the status of this bug? AFAICT, we have *some* fixes from
upstream but Chris's mail implies that the bug is not completely fixed.


This bug disappeared from my logs long time ago, at least haven't seen any application reproducing 
it so far.




Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2019-04-13 Thread Niels Thykier
On Sat, 6 Apr 2019 16:38:13 +0200 Chris Hofstaedtler 
wrote:
> * Thierry fa...@linux.ibm.com  [190406 14:35]:
> > > >The only occurrence I'm seeing on my system is:
> > > >
> > > >openat(AT_FDCWD, "/usr/lib/firefox/fonts/.uuid.TMP-EWjEq0", 
> > > >O_RDWR|O_CREAT|O_EXCL|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)
> > > 
> > > Now it's the only occurrence for me, too.
> > > 
> > 
> > With current packages I don't see any more issues of openat()
> > EACESS(...) when tracing firefox-bin
> 
> With libfontconfig1:amd64 2.13.1-2:
> 
> $ strace -o '| grep -w EACCES' /usr/lib/firefox-esr/firefox-bin
> openat(AT_FDCWD, "/usr/lib/firefox-esr/fonts/.uuid.TMP-pZnI7N", 
> O_RDWR|O_CREAT|O_EXCL|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)
> 
> C.
> 

Hi,

What is the status of this bug? AFAICT, we have *some* fixes from
upstream but Chris's mail implies that the bug is not completely fixed.

Related, upstream closed their side of the bug a few days ago with the note:

"""
uuid related code has been gone in git. this should be improved. closing.
"""

(Not sure if that means they committed some recent changes to fix this).

Thanks,
~Niels



Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2019-04-06 Thread Chris Hofstaedtler
* Thierry fa...@linux.ibm.com  [190406 14:35]:
> > >The only occurrence I'm seeing on my system is:
> > >
> > >openat(AT_FDCWD, "/usr/lib/firefox/fonts/.uuid.TMP-EWjEq0", 
> > >O_RDWR|O_CREAT|O_EXCL|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)
> > 
> > Now it's the only occurrence for me, too.
> > 
> 
> With current packages I don't see any more issues of openat()
> EACESS(...) when tracing firefox-bin

With libfontconfig1:amd64 2.13.1-2:

$ strace -o '| grep -w EACCES' /usr/lib/firefox-esr/firefox-bin
openat(AT_FDCWD, "/usr/lib/firefox-esr/fonts/.uuid.TMP-pZnI7N", 
O_RDWR|O_CREAT|O_EXCL|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)

C.



Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2019-03-21 Thread Thierry fa...@linux.ibm.com
On Sun, 11 Nov 2018 12:04:06 +0100 Jakub Wilk  wrote:
> * Laurent Bigonville , 2018-11-11, 11:18:
> >Do you have any .uuid files in these directories?
> 
> IIRC, I didn't have any back then.
> 
> >Can you try to run "fc-cache -s -f -v" (as root) and see if it helps.
> 
> I think I upgraded some font package, which triggered fontconfig, which 
> ran the aforementioned command. Yes, it did help.
> 
> >What file system do you use for /usr/share/fonts/?
> 
> ext4
> 
> >The only occurrence I'm seeing on my system is:
> >
> >openat(AT_FDCWD, "/usr/lib/firefox/fonts/.uuid.TMP-EWjEq0", 
> >O_RDWR|O_CREAT|O_EXCL|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)
> 
> Now it's the only occurrence for me, too.
> 
> -- 
> Jakub Wilk
> 
Hello,

With current packages I don't see any more issues of openat()
EACESS(...) when tracing firefox-bin
Can you confirm and state about that bug
Thanks



Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2018-11-11 Thread Jakub Wilk

* Laurent Bigonville , 2018-11-11, 11:18:

Do you have any .uuid files in these directories?


IIRC, I didn't have any back then.


Can you try to run "fc-cache -s -f -v" (as root) and see if it helps.


I think I upgraded some font package, which triggered fontconfig, which 
ran the aforementioned command. Yes, it did help.



What file system do you use for /usr/share/fonts/?


ext4


The only occurrence I'm seeing on my system is:

openat(AT_FDCWD, "/usr/lib/firefox/fonts/.uuid.TMP-EWjEq0", 
O_RDWR|O_CREAT|O_EXCL|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)


Now it's the only occurrence for me, too.

--
Jakub Wilk



Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2018-11-11 Thread Laurent Bigonville

On Fri, 9 Nov 2018 14:25:12 +0100 Jakub Wilk  wrote:
> Control: found -1 2.13.1-2
>
> It's still reproducible for me:
>
> $ strace -o '| grep -w EACCES' /usr/lib/firefox-esr/firefox-bin
> ...
> openat(AT_FDCWD, 
"/usr/share/fonts/truetype/mononoki/.uuid.TMP-lrzetE", 
O_RDWR|O_CREAT|O_EXCL|O_LARGEFILE|O_CLOEXEC, 0600) = -1 EACCES 
(Permission denied)
> openat(AT_FDCWD, "/usr/share/fonts/truetype/wine/.uuid.TMP-p6l2oU", 
O_RDWR|O_CREAT|O_EXCL|O_LARGEFILE|O_CLOEXEC, 0600) = -1 EACCES 
(Permission denied)
> openat(AT_FDCWD, "/usr/share/fonts/woff/mononoki/.uuid.TMP-S9ygla", 
O_RDWR|O_CREAT|O_EXCL|O_LARGEFILE|O_CLOEXEC, 0600) = -1 EACCES 
(Permission denied)
> openat(AT_FDCWD, 
"/usr/share/fonts/X11/encodings/large/.uuid.TMP-VcWBhq", 
O_RDWR|O_CREAT|O_EXCL|O_LARGEFILE|O_CLOEXEC, 0600) = -1 EACCES 
(Permission denied)
> openat(AT_FDCWD, "/usr/lib/firefox-esr/fonts/.uuid.TMP-uG7neG", 
O_RDWR|O_CREAT|O_EXCL|O_LARGEFILE|O_CLOEXEC, 0600) = -1 EACCES 
(Permission denied)

> ...

>

Do you have any .uuid files in these directories? Can you try to run 
"fc-cache -s -f -v" (as root) and see if it helps. What file system do 
you use for /usr/share/fonts/?


The only occurrence I'm seeing on my system is:

openat(AT_FDCWD, "/usr/lib/firefox/fonts/.uuid.TMP-EWjEq0", 
O_RDWR|O_CREAT|O_EXCL|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)


That one I can understand as firefox is not creating a cache for its 
private font.




Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2018-11-11 Thread Vincas Dargis

On Fri, 9 Nov 2018 14:25:12 +0100 Jakub Wilk  wrote> It's 
still reproducible for me:


$ strace -o '| grep -w EACCES' /usr/lib/firefox-esr/firefox-bin
...
openat(AT_FDCWD, "/usr/share/fonts/truetype/mononoki/.uuid.TMP-lrzetE", 
O_RDWR|O_CREAT|O_EXCL|O_LARGEFILE|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)
openat(AT_FDCWD, "/usr/share/fonts/truetype/wine/.uuid.TMP-p6l2oU", 
O_RDWR|O_CREAT|O_EXCL|O_LARGEFILE|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)
openat(AT_FDCWD, "/usr/share/fonts/woff/mononoki/.uuid.TMP-S9ygla", 
O_RDWR|O_CREAT|O_EXCL|O_LARGEFILE|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)
openat(AT_FDCWD, "/usr/share/fonts/X11/encodings/large/.uuid.TMP-VcWBhq", 
O_RDWR|O_CREAT|O_EXCL|O_LARGEFILE|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)
openat(AT_FDCWD, "/usr/lib/firefox-esr/fonts/.uuid.TMP-uG7neG", 
O_RDWR|O_CREAT|O_EXCL|O_LARGEFILE|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)


That's strange. If I run `sysdig` to monitor access to `.uuid.` files globally, before logging in 
into desktop, I do get EACCES logged:


sysdig "fd.name contains .uuid.TMP" | tee /tmp/log
3952867 12:07:13.859149439 5 thunderbird (2599) < openat fd=-13(EACCES) dirfd=-100(AT_FDCWD) 
name=/usr/lib/thunderbird/fonts/.uuid.TMP-cnzjnu flags=4135(O_EXCL|O_CREAT|O_RDWR|O_CLOEXEC) mode=0600
4307465 12:07:13.953801349 3 firefox (2576) < openat fd=-13(EACCES) dirfd=-100(AT_FDCWD) 
name=/usr/lib/firefox/fonts/.uuid.TMP-6LGM5w flags=4135(O_EXCL|O_CR$AT|O_RDWR|O_CLOEXEC) mode=0600
5734213 12:07:14.789892829 0 firefox (2995) < openat fd=-13(EACCES) dirfd=-100(AT_FDCWD) 
name=/usr/lib/firefox/fonts/.uuid.TMP-5T4pus flags=4135(O_EXCL|O_CR$AT|O_RDWR|O_CLOEXEC) mode=0600
6988435 12:07:16.158318166 7 firefox (3212) < openat fd=-13(EACCES) dirfd=-100(AT_FDCWD) 
name=/usr/lib/firefox/fonts/.uuid.TMP-l3eHEK flags=4135(O_EXCL|O_CR$AT|O_RDWR|O_CLOEXEC) mode=0600
8086425 12:07:18.491988140 0 firefox (3466) < openat fd=-13(EACCES) dirfd=-100(AT_FDCWD) 
name=/usr/lib/firefox/fonts/.uuid.TMP-Nekoxh flags=4135(O_EXCL|O_CR$AT|O_RDWR|O_CLOEXEC) mode=0600


But I no longer get AppArmor DENIED messages. Maybe I modified abstractions/profiles to silence, but 
I can't recall that... I am sure that Thunderbird *is* confined (same pid as in sysdig output) by 
AppArmor:


```
$ sudo aa-status | fgrep thunderbird
   ...
   /usr/lib/thunderbird/thunderbird-bin (2599) thunderbird
```



Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2018-11-09 Thread Jakub Wilk

Control: found -1 2.13.1-2

It's still reproducible for me:

$ strace -o '| grep -w EACCES' /usr/lib/firefox-esr/firefox-bin
...
openat(AT_FDCWD, "/usr/share/fonts/truetype/mononoki/.uuid.TMP-lrzetE", 
O_RDWR|O_CREAT|O_EXCL|O_LARGEFILE|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)
openat(AT_FDCWD, "/usr/share/fonts/truetype/wine/.uuid.TMP-p6l2oU", 
O_RDWR|O_CREAT|O_EXCL|O_LARGEFILE|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)
openat(AT_FDCWD, "/usr/share/fonts/woff/mononoki/.uuid.TMP-S9ygla", 
O_RDWR|O_CREAT|O_EXCL|O_LARGEFILE|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)
openat(AT_FDCWD, "/usr/share/fonts/X11/encodings/large/.uuid.TMP-VcWBhq", 
O_RDWR|O_CREAT|O_EXCL|O_LARGEFILE|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)
openat(AT_FDCWD, "/usr/lib/firefox-esr/fonts/.uuid.TMP-uG7neG", 
O_RDWR|O_CREAT|O_EXCL|O_LARGEFILE|O_CLOEXEC, 0600) = -1 EACCES (Permission denied)
...

--
Jakub Wilk



Processed: Re: Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2018-11-09 Thread Debian Bug Tracking System
Processing control commands:

> found -1 2.13.1-2
Bug #909750 {Done: Vincas Dargis } [libfontconfig1] 
applications tries to write to /usr/* directories via libfontconfig1
Marked as found in versions fontconfig/2.13.1-2; no longer marked as fixed in 
versions fontconfig/2.13.1-2 and reopened.

-- 
909750: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=909750
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: Re: Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2018-11-08 Thread Debian Bug Tracking System
Processing control commands:

> fixed -1 2.13.1-2
Bug #909750 [libfontconfig1] applications tries to write to /usr/* directories 
via libfontconfig1
Marked as fixed in versions fontconfig/2.13.1-2.

-- 
909750: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=909750
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2018-11-08 Thread Vincas Dargis

Control: fixed -1 2.13.1-2

I cannot reproduce this any more, thanks!



Processed: Re: Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2018-10-31 Thread Debian Bug Tracking System
Processing control commands:

> severity -1 serious
Bug #909750 [libfontconfig1] applications tries to write to /usr/* directories 
via libfontconfig1
Severity set to 'serious' from 'normal'

-- 
909750: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=909750
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems