Re: [apparmor] [profile] Evince: the lack of "private-files-strict" and a lenient, dangerous rules related to @{HOME} folder.

2017-12-04 Thread Seth Arnold
On Sat, Dec 02, 2017 at 03:40:52PM +, daniel curtis wrote: > Thank You for an answer and sorry for my naive, stupid questions and other > things. Hello Daniel, please don't think your questions are naive or stupid! You just have the luxury of not seeing evince bugs over many years. :) > [1]

[apparmor] [profile] Evince: the lack of "private-files-strict" and a lenient, dangerous rules related to @{HOME} folder.

2017-12-02 Thread daniel curtis
Hello Seth Thank You for an answer and sorry for my naive, stupid questions and other things. >> Strictly speaking, even if you remove the ~/** rw, kinds of >> rules from firefox's profile, you'll still be able to download to >> any writable location in the profile. Doing any different would >>

Re: [apparmor] [profile] Evince: the lack of "private-files-strict" and a lenient, dangerous rules related to @{HOME} folder.

2017-11-29 Thread Seth Arnold
Hello Daniel, On Wed, Nov 29, 2017 at 05:02:25PM +, daniel curtis wrote: > I'm asking, because Evince is a document viewer (PostScript, PDF). > Of course it allows e.g. printing PS files, EPS etc., text searching, > hypertext > navigation and bookmarks with index when it is available in the

[apparmor] [profile] Evince: the lack of "private-files-strict" and a lenient, dangerous rules related to @{HOME} folder.

2017-11-29 Thread daniel curtis
​ ​Hello Jamie​ Remember that these evince profiles include abstractions/evince. This > has: > ​ ​ > > ​Geez, I totally forgot about checking another abstractions​! Sorry. I was just amazed. That's all. Thank you for bringing my attention to it. By the way; are these abstractions rules really

Re: [apparmor] [profile] Evince: the lack of "private-files-strict" and a lenient, dangerous rules related to @{HOME} folder.

2017-11-29 Thread Jamie Strandboge
On Wed, 2017-11-29 at 12:30 +, daniel curtis wrote: > Hello > > Yesterday, I noticed a strange lack of an abstraction rule in a > default > Evince profile (provided with 16.04 LTS install) and I would like to > ask if > it's just an oversight and there should be added one rule: >