[Touch-packages] [Bug 1734038] Re: utils don't understand «include "/where/ever"» (was: Potential regression found with apparmor test on Xenial/Zesty)

2017-11-27 Thread Jamie Strandboge
@mvo - this is probably obvious, but if you used '#include' instead of 'include', it would side-step the issue. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1734038

[Touch-packages] [Bug 1667512] Re: update-initramfs hangs on upgrade, dpkg unusable, unbootable system

2017-11-25 Thread Jamie
Commenting out the sync command in the generate_initramfs function of /usr/sbin/update-initramfs worked for me. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to initramfs-tools in Ubuntu.

[Touch-packages] [Bug 1730908] Re: [ 1549.847151] audit: type=1400 audit(1510129355.497:61): apparmor="DENIED" operation="file_mmap" profile="/usr/bin/evince" name="/usr/lib/x86_64-linux-gnu/libproxy/

2017-11-08 Thread Jamie Strandboge
G.M. the first denial is because evince doesn't have the necessary rule for using libproxy (a GNOME 2 technology), but the ntpd denial is something different. Can you file a separate bug for ntpd? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages,

[Touch-packages] [Bug 1713710] Re: RM: obsolete product

2017-11-01 Thread Jamie Strandboge
Again, +1 to remove. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to click-apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1713710 Title: RM: obsolete product Status in click-apparmor package in Ubuntu: Triaged Bug

[Touch-packages] [Bug 1042771] Re: sanitized_helper prevents proper transition to other profiles

2017-10-27 Thread Jamie Strandboge
This would indeed be perfect for this situation. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1042771 Title: sanitized_helper prevents proper transition to other

[Touch-packages] [Bug 1042771] Re: sanitized_helper prevents proper transition to other profiles

2017-10-27 Thread Jamie Strandboge
Note that this is rather tricky. If the user disabled the evince profile, using Px means that the exec will fail with 'profile not found'. There is no way to specify 'use P if it exists, otherwise C'. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages,

[Touch-packages] [Bug 1681910] Re: gnome-terminal constantly logs "Unable to load blank_cursor from the cursor theme" under gnome/wayland

2017-10-26 Thread Jamie Strandboge
Here is the upstream patch as a debdiff that I compiled locally. Preliminary testing shows that it fixes the gnome-terminal issue. I won't be chasing this all the way through the SRU process, but hope that you consider it in a future 17.10 SRU. ** Patch added:

[Touch-packages] [Bug 1681910] Re: gnome-terminal constantly logs "Unable to load blank_cursor from the cursor theme" under gnome/wayland

2017-10-26 Thread Jamie Strandboge
https://git.gnome.org/browse/gtk%2B/commit/?id=db49d12 has the fix for this. ** Project changed: gnome-terminal => gtk ** Package changed: gnome-terminal (Ubuntu) => gtk+3.0 (Ubuntu) ** Changed in: gtk+3.0 (Ubuntu) Status: Confirmed => Triaged -- You received this bug notification

[Touch-packages] [Bug 1721278] Re: apparmor="DENIED" operation="create" profile="/usr/sbin/cups-browsed" w/ 4.14-rc2 and later

2017-10-18 Thread Jamie Strandboge
John, It sounds like we should backport r3700 to all Ubuntu releases? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1721278 Title: apparmor="DENIED" operation="create"

[Touch-packages] [Bug 1721278] Re: apparmor="DENIED" operation="create" profile="/usr/sbin/cups-browsed" w/ 4.14-rc2 and later

2017-10-13 Thread Jamie Strandboge
This isn't really an *Ubuntu* issue per se as we've never claimed to support apparmor profiles with non-Ubuntu kernels. I do think it is interesting that there are 'unix' denials on a kernel that isn't supposed to support unix rules. John, can you comment on this? -- You received this bug

[Touch-packages] [Bug 1722125] [NEW] HP Envy late 2017, Ubuntu 17.04 - laptop lid close doesn't suspend

2017-10-08 Thread Jamie
Public bug reported: In the power settings, the option to suspend when the lid is closed is selected. However, when the lid closes the laptop stays awake and the battery is then drained. Laptop details: Intel® Core™ i7-7500U CPU @ 2.70GHz × 4, Intel® HD Graphics 620 (Kabylake GT2) (actually, I

[Touch-packages] [Bug 1719211] Re: Bad interface name

2017-09-28 Thread Jamie Strandboge
** Changed in: ufw (Ubuntu) Status: Triaged => In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ufw in Ubuntu. https://bugs.launchpad.net/bugs/1719211 Title: Bad interface name Status in ufw package in

[Touch-packages] [Bug 1719211] Re: Bad interface name

2017-09-28 Thread Jamie Strandboge
(Ubuntu) Importance: Undecided => Medium ** Changed in: ufw (Ubuntu) Status: New => Triaged ** Changed in: ufw (Ubuntu) Assignee: (unassigned) => Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Touch seeded packag

[Touch-packages] [Bug 1710637] Re: Input falls through to gdm3 and terminates the session on Ctrl+C after udevadm trigger is executed under wayland

2017-09-19 Thread Jamie Strandboge
The forum thread is enough IMO for this improvement (as opposed to bug fix) and it is in trello. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to systemd in Ubuntu. https://bugs.launchpad.net/bugs/1710637 Title: Input falls

[Touch-packages] [Bug 1710637] Re: Input falls through to gdm3 and terminates the session on Ctrl+C after udevadm trigger is executed under wayland

2017-09-19 Thread Jamie Strandboge
@Mathieu, while I understand the wayland gnome-shell desktop session is not supported on zesty or xenial, I wonder if this should be SRU'd to those releases? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to systemd in Ubuntu.

[Touch-packages] [Bug 1710637] Re: Input falls through to gdm3 and terminates the session on Ctrl+C after udevadm trigger is executed under wayland

2017-09-19 Thread Jamie Strandboge
Closing the snappy task-- while we might want to adjust its use of udevadm trigger, it is clear that running this command should not break the wayland desktop, just like it doesn't under X. ** Changed in: snappy Status: New => Opinion ** Changed in: snappy Status: Opinion => Won't

[Touch-packages] [Bug 1710637] Re: Input falls through to gdm3 and terminates the session on Ctrl+C after udevadm trigger is executed under wayland

2017-09-19 Thread Jamie Strandboge
I just now upgraded to 1.166ubuntu5 and no longer see the issue. To ogra's point, I use encrypted lvm and was able to enter a password and have everything work like normal. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

[Touch-packages] [Bug 1710637] Re: Input falls through to gdm3 and terminates the session on Ctrl+C after udevadm trigger is executed under wayland

2017-09-19 Thread Jamie Strandboge
I still have console-setup 1.166ubuntu4 so decided to poke at this more. I can confirm that 'sudo udevadm trigger' causes the ctrl+c to logout of Wayland. It does not cause a logout of gnome-shell under X. I then found that 'udevadm trigger --subsystem-nomatch=tty' does not cause the issue under

[Touch-packages] [Bug 1713710] Re: RM: obsolete product

2017-09-18 Thread Jamie Strandboge
Big +1. I tried to have this removed before but it was too soon. I had to settle (at the time) for demoting to universe and updating the LP project to state it was abandoned. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

[Touch-packages] [Bug 1710637] Re: Input falls through to gdm3 and terminates the session on Ctrl+C

2017-09-18 Thread Jamie Strandboge
Note I was seeing this in zesty for a while (then didn't): https://bugzilla.gnome.org/show_bug.cgi?id=772476 ** Bug watch added: GNOME Bug Tracker #772476 https://bugzilla.gnome.org/show_bug.cgi?id=772476 -- You received this bug notification because you are a member of Ubuntu Touch seeded

[Touch-packages] [Bug 1716324] Re: package ufw 0.35-4 failed to install/upgrade: subprocess installed post-installation script returned error exit status 10

2017-09-15 Thread Jamie Strandboge
Thank you for using Ubuntu and filing a bug. There are a number of issues in the dpkg log. Eg: сен 11 11:42:18 hostname classicmenu-indicator.desktop[12623]: dpkg: warning: files list file for package 'iptables' missing; assuming package has no files currently installed It seems this is

[Touch-packages] [Bug 1716848] Re: package bluez 5.37-0ubuntu5.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2017-09-13 Thread Jamie Strandboge
Marking as "Won't Fix" for the bluez deb -- the postinst is doing the right thing, there just happens to be something installed outside of dpkg/apt that is getting in the way. ** Changed in: bluez (Ubuntu) Status: Confirmed => Won't Fix -- You received this bug notification because you

[Touch-packages] [Bug 1716848] Re: package bluez 5.37-0ubuntu5.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2017-09-13 Thread Jamie Strandboge
Looking at the logs I see: Sep 13 07:51:08 agda-HP-Pavilion-dv6500-Notebook-PC audit[1221]: AVC apparmor="STATUS" operation="profile_replace" profile="unconfined" name="snap.bluez.bluetoothctl" pid=1221 comm="apparmor_parser" This indicates you have the bluez snap installed. This bug is about

[Touch-packages] [Bug 1710487] Re: evince silently crashes with apparmor error on artful

2017-08-14 Thread Jamie Strandboge
Uploaded apparmor and evince to artful. ** Changed in: apparmor (Ubuntu) Status: Triaged => Fix Committed ** Changed in: evince (Ubuntu) Status: Triaged => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is

[Touch-packages] [Bug 1710487] Re: evince silently crashes with apparmor error on artful

2017-08-14 Thread Jamie Strandboge
(Ubuntu) Status: New => Triaged ** Changed in: evince (Ubuntu) Importance: Undecided => High ** Changed in: evince (Ubuntu) Assignee: (unassigned) => Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Touch seeded packag

[Touch-packages] [Bug 1710487] Re: evince silently crashes with apparmor error on artful

2017-08-14 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: Confirmed => Triaged ** Changed in: apparmor (Ubuntu) Assignee: (unassigned) => Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ap

[Touch-packages] [Bug 1598759] Re: AppArmor nameservice abstraction doesn't allow communication with systemd-resolved

2017-08-07 Thread Jamie Strandboge
@intrigeri - you're right. I'll fix this in the citrain branch and in 2.11.0-2ubuntu14. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1598759 Title: AppArmor

[Touch-packages] [Bug 1588917] Re: Upgrade ping to latest version that doesn't require SUID or NET_RAW capability

2017-08-04 Thread Jamie Strandboge
** Changed in: iputils (Ubuntu) Status: New => Triaged ** Changed in: iputils (Ubuntu) Importance: Undecided => Wishlist -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to iputils in Ubuntu.

[Touch-packages] [Bug 1583057] Re: Deny audio recording for all snap applications

2017-08-03 Thread Jamie Strandboge
** Changed in: pulseaudio (Ubuntu Xenial) Status: In Progress => Won't Fix -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to pulseaudio in Ubuntu. https://bugs.launchpad.net/bugs/1583057 Title: Deny audio recording

[Touch-packages] [Bug 1707891] [NEW] Disabling a wifi network adapter disables all wifi adapters

2017-08-01 Thread Jamie Bennett
t seem to be the case. jamie@ubik:~$ uname -a Linux ubik 4.11.0-10-generic #15-Ubuntu SMP Thu Jun 29 15:03:41 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux jamie@ubik:~$ lsb_release -a No LSB modules are available. Distributor ID: Ubuntu Description:Ubuntu Artful Aardvark (development branch) R

[Touch-packages] [Bug 1707645] Re: system with high numbered uids has huge sparse /var/log/lastlog

2017-07-31 Thread Jamie Strandboge
FYI, people using rsync for backups might be interested in the --sparse (-S) option. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to util-linux in Ubuntu. https://bugs.launchpad.net/bugs/1707645 Title: system with high

[Touch-packages] [Bug 1707645] [NEW] system with high numbered uids has huge sparse /var/log/lastlog

2017-07-31 Thread Jamie Strandboge
Public bug reported: I was investigating the use of a single high UID user (ie, 20) and discovered that /var/log/lastlog grew to an enormously large sparse file: $ ls -lh /var/log/lastlog -rw-rw-r-- 1 root utmp 544G Jul 27 12:35 /var/log/lastlog The file is actually quite small though:

[Touch-packages] [Bug 1707522] [NEW] Unable to login after locking screen, unable to lock screen via gui menu

2017-07-30 Thread Jamie S.
Public bug reported: Using AMDGPU-Pro dpkg -l amdgpu-pro Desired=Unknown/Install/Remove/Purge/Hold | Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend |/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad) ||/ Name Version Architecture Description

[Touch-packages] [Bug 1703763] Re: How to correctly transition from packaged to dh_apparmor generated local includes

2017-07-12 Thread Jamie Strandboge
I suggest a variation on A where before rm_conffile you checksum /etc/apparmor.d/local/usr.sbin.libvirtd, if different safely save that off, call rm_conffile, then move the saved off file into place. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages,

[Touch-packages] [Bug 1408106] Re: attach_disconnected not sufficient for overlayfs

2017-07-06 Thread Jamie Strandboge
@Frode, I can yes, when I file them. I need to do a bit of work for simple reproducers/etc/etc to file them. I've added an item to add a comment to this bug when I do. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor

[Touch-packages] [Bug 1576066] Re: 32bit glibc calls old socketcall() syscall, causing seccomp problems

2017-06-30 Thread Jamie Strandboge
Bug watch added: Debian Bug tracker #809556 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=809556 ** Changed in: libseccomp (Ubuntu) Assignee: Jamie Strandboge (jdstrand) => (unassigned) ** Changed in: libseccomp (Ubuntu) Status: Confirmed => Fix Released ** Changed in: lib

[Touch-packages] [Bug 1700231] Re: 16.04 , apparmor denies dbus communications even with flags=(complain)

2017-06-27 Thread Jamie Strandboge
@sles, yes, this is expected behavior. The child profile 'inside' is still a separate profile and therefore needs to have its own flags. Marking this bug as Invalid based on reporter's feedback. If you feel this is in error, please reopen. Thanks for filing a bug and please feel free to file bugs

[Touch-packages] [Bug 1670408] Re: Missing apparmor rules cause tor to fail to start

2017-06-20 Thread Jamie Strandboge
This is what someone needs to backport: http://bazaar.launchpad.net /~apparmor-dev/apparmor/master/revision/3658. If you want the security team to do it, please use the stakeholder process to get this prioritized. -- You received this bug notification because you are a member of Ubuntu Touch

[Touch-packages] [Bug 1647586] Re: apparmor errors with current ntp

2017-06-20 Thread Jamie Strandboge
** Changed in: ntp (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ntp in Ubuntu. https://bugs.launchpad.net/bugs/1647586 Title: apparmor errors with current ntp Status in ntp

[Touch-packages] [Bug 1670408] Re: Missing apparmor rules cause tor to fail to start

2017-06-20 Thread Jamie Strandboge
As mentioned in other comments, this is fixed in 17.04, so marking the tor task as Invalid (it is an issue in the apparmor abstractions, not tor) and marking the apparmor task as Fix Released. If someone wants to perform the SRU or supply debdiffs, please open tasks against the particular releases

[Touch-packages] [Bug 1698751] Re: interface related rules appear active after deletion

2017-06-20 Thread Jamie Strandboge
Thanks for getting back to me. I'll mark this as Invalid based on your feedback. Please feel free to report other bugs you may find. ** Changed in: ufw (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of Ubuntu Touch seeded packages,

[Touch-packages] [Bug 1698751] Re: interface related rules appear active after deletion

2017-06-19 Thread Jamie Strandboge
Thank you for using ufw and reporting a bug. I cannot reproduce this: $ sudo ufw allow OpenSSH $ sudo ufw enable $ sudo ufw show added Added user rules (see 'ufw status' for running firewall): ufw allow OpenSSH $ sudo ufw allow in on eth0 to any port 8080 proto tcp Rule added Rule added (v6) $

[Touch-packages] [Bug 1589401] Re: cannot view wifi networks after re-enabling wifi

2017-06-08 Thread Jamie Strandboge
Is this still an issue with 1.2.6-0ubuntu0.16.04.3 in 16.04? I see that Ken applied the patch I identified in https://bugzilla.gnome.org/show_bug.cgi?id=767317 to fix https://bugs.launchpad.net/ubuntu/+source/network-manager- applet/+bug/1641889, which references a different upstream bug. -- You

[Touch-packages] [Bug 1204579] Re: ufw doesn't support concurrent updates

2017-06-06 Thread Jamie Strandboge
@Luke, you could modify backend_iptables.py as mentioned in comment #5 or you could perhaps use 'man 1 flock' or implement a lock wrapper around your invocation of ufw. That said, since didn't hear back from Christopher, I'll take a look at implementing this for 0.36. ** Changed in: ufw

[Touch-packages] [Bug 1633698] Re: ufw before6.rules adds echo-request and echo-response rules to wrong chain

2017-06-06 Thread Jamie Strandboge
** Changed in: ufw Milestone: None => 0.36 ** Changed in: ufw Assignee: (unassigned) => Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ufw in Ubuntu. https://bugs.launchpad.ne

[Touch-packages] [Bug 1520551] Re: Profiling from Ubuntu SDK IDE is working only if "networking", policy group is enabled in apparmor

2017-05-31 Thread Jamie Strandboge
** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor-easyprof-ubuntu in Ubuntu. https://bugs.launchpad.net/bugs/1520551 Title: Profiling

[Touch-packages] [Bug 1562183] Re: No way to associate .mp4 file with video player

2017-05-31 Thread Jamie Strandboge
** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to unity-scope-mediascanner in Ubuntu. https://bugs.launchpad.net/bugs/1562183 Title: No way to

[Touch-packages] [Bug 1319546] Re: Remove sync-monitor policy rules

2017-05-31 Thread Jamie Strandboge
** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor-easyprof-ubuntu in Ubuntu. https://bugs.launchpad.net/bugs/1319546 Title: Remove

[Touch-packages] [Bug 1606595] Re: Default profile should allow communication with maliit-server

2017-05-31 Thread Jamie Strandboge
** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor-easyprof-ubuntu in Ubuntu. https://bugs.launchpad.net/bugs/1606595 Title: Default

[Touch-packages] [Bug 1609616] Re: Alarm/AlarmModel should be confined per app

2017-05-31 Thread Jamie Strandboge
** Changed in: apparmor-easyprof-ubuntu (Ubuntu) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor-easyprof-ubuntu in Ubuntu. https://bugs.launchpad.net/bugs/1609616 Title:

[Touch-packages] [Bug 1688730] Re: click-apparmor ubuntu-app-launch url-dispatcher

2017-05-25 Thread Jamie Strandboge
This appears to be a transient error: May 06 18:49:31 hostname update-notifier.desktop[2677]: Traceback (most recent call last): May 06 18:49:31 hostname update-notifier.desktop[2677]: File "/usr/lib/python3/dist-packages/defer/__init__.py", line 483, in _inline_callbacks May 06 18:49:31

[Touch-packages] [Bug 1660316] Re: apparmor denial of CUPS

2017-05-25 Thread Jamie Strandboge
In the meantime, users can workaround this by adjusting /etc/apparmor.d/local/usr.sbin.cupsd to have: capability net_admin, and then reloading the profile with: $ sudo apparmor_parser -r /etc/apparmor.d/usr.sbin.cupsd -- You received this bug notification because you are a member of Ubuntu

[Touch-packages] [Bug 1660316] Re: apparmor denial of CUPS

2017-05-25 Thread Jamie Strandboge
@Till, see 'man 7 capabilities' for what net_admin grants. We need to understand why the access is needed before granting it. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu.

[Touch-packages] [Bug 1408106] Re: attach_disconnected not sufficient for overlayfs

2017-05-16 Thread Jamie Strandboge
Actually, I marked the MAAS task as incomplete in case people want to give feedback. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1408106 Title: attach_disconnected

[Touch-packages] [Bug 1408106] Re: attach_disconnected not sufficient for overlayfs

2017-05-16 Thread Jamie Strandboge
Closing the MAAS task as it the referenced bug is marked Fix Release. If there are issues there still, please see my previous comment and look at the code in that snap-- there are viable ways to use overlayfs with chroot and an apparmor alias rule, or overlayfs with private mount, chroot and

[Touch-packages] [Bug 1408106] Re: attach_disconnected not sufficient for overlayfs

2017-05-16 Thread Jamie Strandboge
Ok, I spent quite a bit of time evaluating this and believe this bug can be closed, but other bugs open. In looking at this I created https://code.launchpad.net/~jdstrand/+git /test-overlay (to build simply git clone, run 'snapcraft', install the snap and then run 'test-overlay' for instructions

[Touch-packages] [Bug 1689585] Re: ntp doesn't unload its apparmor profile on purge

2017-05-15 Thread Jamie Strandboge
"Asking someone to know about that: echo -n "" > /sys/kernel/security/apparmor/.remove Is asking too much IMHO and increases the friction between sysadmins and Apparmor in general." Of course. I listed this as something that could be considered for the openntpd/ntpd case, not for a sysadmin.

[Touch-packages] [Bug 1689585] Re: ntp doesn't unload its apparmor profile on purge

2017-05-12 Thread Jamie Strandboge
Christian is right and this is precisely why dh_apparmor intentionally does not unload the profile. Marking the apparmor task as Won't Fix since this has been discussed several times in the past (if apparmor upstream wants to revisit, we can open the bug). The ntp package is still in a position

[Touch-packages] [Bug 1688395] Re: Remove Oxide, webbrowser-app and the Unity webapps

2017-05-04 Thread Jamie Strandboge
Are all of these unsupported? I know that the signage effort was initially using webapp-container (part of webbrowser-app) with mir. Even if webbrowser-app were removed, oxide-qt might still be interesting for signage/etc since it can be used with upstream Qt. I've not heard an official statement

[Touch-packages] [Bug 1655982] Re: cups-browsed fails to start in containers after apparmor stacking backport to xenial

2017-05-04 Thread Jamie Strandboge
Host: $ uname -a Linux sec-xenial-amd64 4.4.0-77-generic #98-Ubuntu SMP Wed Apr 26 08:34:02 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux $ apparmor_parser -V AppArmor parser version 2.10.95 Copyright (C) 1999-2008 Novell Inc. Copyright 2009-2012 Canonical Ltd. Container: root@xen:~# uname -a Linux

[Touch-packages] [Bug 1655982] Re: cups-browsed fails to start in containers after apparmor stacking backport to xenial

2017-05-04 Thread Jamie Strandboge
FYI, http://bazaar.launchpad.net/~apparmor- dev/apparmor/master/revision/3658 fixes the /run/systemd/journal/stdout denials. It seems like the real cause of this bug is this denial: [95224.610046] audit: type=1400 audit(1484230178.466:1014): apparmor="DENIED" operation="file_mmap"

[Touch-packages] [Bug 1649310] Re: RM Upstart, obsolete, superseded by systemd / Products discontinued

2017-05-04 Thread Jamie Strandboge
"Once I have a list of things, I was planning to file individual bugs with a tag repeal-act-2019 (or similar)" Can you add click-apparmor and apparmor-easyprof-ubuntu to your list if they aren't there already? -- You received this bug notification because you are a member of Ubuntu Touch seeded

[Touch-packages] [Bug 1681908] [NEW] aa-notify difficult to use with gnome-shell

2017-04-11 Thread Jamie Strandboge
urgency. In other popular DEs critical urgency notifications time out. We should adjust the urgency to 'normal' to obtain intended behavior across DEs. ** Affects: apparmor (Ubuntu) Importance: Medium Assignee: Jamie Strandboge (jdstrand) Status: In Progress ** Changed

[Touch-packages] [Bug 1680496] Re: black screen when using 'GNOME Wayland' with lightdm on zesty

2017-04-06 Thread Jamie Strandboge
** Description changed: In an up to date Ubuntu 17.04 amd64 vm, if I: 1. install ubuntu-gnome-desktop 2. select lightdm as the default 3. sudo service lightdm stop ; sudo service lightdm start 4. login choosing 'GNOME Wayland' the screen goes black with a flashing cursor in the

[Touch-packages] [Bug 1677244] [NEW] "UnicodeEncodeError: 'utf-8' codec can't encode character '\udcc4' in position 69: surrogates not allowed" with mime.file() on path from os.walk

2017-03-29 Thread Jamie Strandboge
Public bug reported: The following script works fine on 16.04 LTS: #!/usr/bin/python3 import magic import os dir = "/usr/share/ca-certificates/mozilla" mime = magic.open(magic.MAGIC_MIME) mime.load() for root, dirnames, filenames in os.walk(dir): for f in filenames: fn =

[Touch-packages] [Bug 1675503] Re: cups and cups-pdf denials in snapd autopkgtests on zesty

2017-03-23 Thread Jamie Strandboge
FYI, I noticed Ubuntu was in sync with Debian so I filed https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=858571. ** Bug watch added: Debian Bug tracker #858571 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=858571 -- You received this bug notification because you are a member of Ubuntu

[Touch-packages] [Bug 1675503] Re: cups and cups-pdf denials in snapd autopkgtests on zesty

2017-03-23 Thread Jamie Strandboge
** Changed in: cups (Ubuntu) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1675503 Title: cups and cups-pdf denials in snapd

[Touch-packages] [Bug 1536201] Re: cupsctl can corrupt cupsd.conf if invoked by member of lpadmin group

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1536201 Title: cupsctl can corrupt cupsd.conf if invoked by member of lpadmin group Status in cups

[Touch-packages] [Bug 1572489] Re: Canon MF4330d needs usb-no-reattach-default=true

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1572489 Title: Canon MF4330d needs usb-no-reattach-default=true Status in cups package in Ubuntu:

[Touch-packages] [Bug 1671420] Re: package cups-daemon 2.0.2-1ubuntu3 failed to install/upgrade: le sous-processus script post-installation installé a retourné une erreur de sortie d'état 1

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1671420 Title: package cups-daemon 2.0.2-1ubuntu3 failed to install/upgrade: le sous- processus

[Touch-packages] [Bug 1526010] Re: Duplex not working

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1526010 Title: Duplex not working Status in cups package in Ubuntu: New Bug description: I

[Touch-packages] [Bug 1526415] Re: after upgrade printer properties not recognized (paper, duplex etc)

2017-03-23 Thread Jamie Strandboge
The apparmor denials have since been fixed. Removing the apparmor tag. ** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1526415 Title: after upgrade

[Touch-packages] [Bug 1523395] Re: package cups-daemon 2.0.2-1ubuntu3 failed to install/upgrade: 子程序 已安裝的 post-installation script 傳回了錯誤退出狀態 1

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1523395 Title: package cups-daemon 2.0.2-1ubuntu3 failed to install/upgrade: 子程序 已安裝的

[Touch-packages] [Bug 1526586] Re: package cups 1.7.2-0ubuntu1.6 failed to install/upgrade: subprocess installed post-installation script returned error exit status 255

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1526586 Title: package cups 1.7.2-0ubuntu1.6 failed to install/upgrade: subprocess installed

[Touch-packages] [Bug 1532551] Re: no response from printer

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1532551 Title: no response from printer Status in cups package in Ubuntu: New Bug description:

[Touch-packages] [Bug 1354596] Re: Internal Server Error accessing localhost:631/admin

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1354596 Title: Internal Server Error accessing localhost:631/admin Status in cups package in

[Touch-packages] [Bug 1351036] Re: Printer starts job from beginning after system suspend/resume

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1351036 Title: Printer starts job from beginning after system suspend/resume Status in cups package

[Touch-packages] [Bug 1357529] Re: Magenta Toner Icon is yellow and Yellow Toner Icon is magenta

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1357529 Title: Magenta Toner Icon is yellow and Yellow Toner Icon is magenta Status in cups package

[Touch-packages] [Bug 1477002] Re: Working printer not printing

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1477002 Title: Working printer not printing Status in cups package in Ubuntu: New Bug

[Touch-packages] [Bug 1418326] Re: "lpr -p -P PDF" (prettyprint) hangs print job with sample string

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1418326 Title: "lpr -p -P PDF" (prettyprint) hangs print job with sample string Status in cups

[Touch-packages] [Bug 1516352] Re: printer does not print

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1516352 Title: printer does not print Status in cups package in Ubuntu: New Bug description:

[Touch-packages] [Bug 1086303] Re: Cups server can't listen - accept connections to 127.0.1.1 ( Bad request )

2017-03-23 Thread Jamie Strandboge
The apparmor denials have since been fixed. Removing the apparmor tag. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1086303 Title: Cups server can't listen - accept

[Touch-packages] [Bug 1310192] Re: package cups 1.6.1-0ubuntu11.5 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1310192 Title: package cups 1.6.1-0ubuntu11.5 failed to install/upgrade: subprocess installed

[Touch-packages] [Bug 1089628] Re: Print first pdf file works, second pdf file results in garbage output

2017-03-23 Thread Jamie Strandboge
The apparmor denials have since been fixed, removing the apparmor tag. ** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1089628 Title: Print first

[Touch-packages] [Bug 1378438] Re: Printer dialog stuck on "Getting printer information..."

2017-03-23 Thread Jamie Strandboge
The apparmor denials were fixed in 1.7.1-1. ** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1378438 Title: Printer dialog stuck on "Getting printer

[Touch-packages] [Bug 1582251] Re: CUPS does not find network Samsung SCX-4729FD printer

2017-03-23 Thread Jamie Strandboge
The apparmor denials are unrelated to this issue. ** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1582251 Title: CUPS does not find network Samsung

[Touch-packages] [Bug 1076347] Re: two-sided printing not working on my pc, no problem on another one.

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1076347 Title: two-sided printing not working on my pc, no problem on another one. Status in cups

[Touch-packages] [Bug 1583997] Re: cannot print correctly on HP Deskjet 840C

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1583997 Title: cannot print correctly on HP Deskjet 840C Status in cups package in Ubuntu: New

[Touch-packages] [Bug 1636747] Re: Printer canon MF3010.

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1636747 Title: Printer canon MF3010. Status in cups package in Ubuntu: New Bug description:

[Touch-packages] [Bug 1652148] Re: I am not able to print on my new canon laser shot LBP2900B printer

2017-03-23 Thread Jamie Strandboge
The kernel log contains many denials of the form: [ 1729.383907] audit: type=1400 audit(1482428730.641:24): apparmor="DENIED" operation="open" profile="/usr/sbin/cupsd" name="/home/.ecryptfs/megatron/.ecryptfs/Private.mnt" pid=1048 comm="cupsd" requested_mask="r" denied_mask="r" fsuid=1000

[Touch-packages] [Bug 1660316] Re: apparmor denial of CUPS

2017-03-23 Thread Jamie Strandboge
net_admin is a very powerful capability. What is lpd trying to do? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1660316 Title: apparmor denial of CUPS Status in cups

[Touch-packages] [Bug 1663647] Re: cannot add printer

2017-03-23 Thread Jamie Strandboge
** Tags removed: apparmor -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1663647 Title: cannot add printer Status in cups package in Ubuntu: Incomplete Bug description:

[Touch-packages] [Bug 1675503] Re: cups and cups-pdf denials in snapd autopkgtests on zesty

2017-03-23 Thread Jamie Strandboge
** Changed in: cups (Ubuntu) Importance: Undecided => Medium ** Changed in: cups (Ubuntu) Status: New => In Progress ** Changed in: cups (Ubuntu) Assignee: (unassigned) => Jamie Strandboge (jdstrand) ** Tags added: apparmor -- You received this bug notification be

[Touch-packages] [Bug 1675503] Re: cups and cups-pdf denials in snapd autopkgtests on zesty

2017-03-23 Thread Jamie Strandboge
>From the denials, it seems like adding this to the cups profile: unix peer=(label=/usr/lib/cups/backend/cups-pdf), and this to cups-pdf: /etc/cups/ppd/*.ppd r, /var/log/cups/cups-pdf-*_log rw, unix peer=(label=/usr/sbin/cupsd), should fix the issue (untested). -- You received this

[Touch-packages] [Bug 1675503] [NEW] cups and cups-pdf denials in snapd autopkgtests on zesty

2017-03-23 Thread Jamie Strandboge
Public bug reported: https://objectstorage.prodstack4-5.canonical.com/v1/AUTH_77e2ada1e7a84929a74ba3b87153c0ac /autopkgtest-zesty/zesty/amd64/s/snapd/20170323_131353_98370@/log.gz: [ 1146.168148] audit: type=1400 audit(1490272816.901:880): apparmor="DENIED" operation="file_inherit"

[Touch-packages] [Bug 1674532] Re: glibc update caused NSS ABI break

2017-03-23 Thread Jamie
I just want to chime in here and say this bug has cost our company thousands of dollars in lost revenue, and not to mention the unnecessary cost of debugging time, because it broke two of the most important API endpoints we use... Stripe for payments and the API for email delivery with SendGrid,

[Touch-packages] [Bug 1590561] Re: webbrowser-app crashes on startup on fresh zesty Unity8: No suitable EGL configs found

2017-02-22 Thread Jamie Strandboge
For the ibus denial you need: #include For nvidia, you need: #include @{PROC}/driver/nvidia/params r, /dev/nvidia* rw, unix (send, receive) type=dgram peer=(addr="@nvidia[0-9a-f]*"), (the apparmor abstraction needs to be updated for newer nvidia). What happens if you add the above

[Touch-packages] [Bug 1661743] Re: XmlListModel with xml string triggers AppArmor denials

2017-02-16 Thread Jamie Strandboge
FYI, IIRC this would happen on Touch but on Touch we would explicitly deny access to network manager in the networking policy group which suppressed the apparmor denial. Due to the way apparmor works and how snappy builds up interfaces, we use explicit denials extremely sparingly, which is why you

[Touch-packages] [Bug 1662501] Re: AppArmor profile for ubuntu-browsers allows too much read access

2017-02-07 Thread Jamie Strandboge
Thank you for using Ubuntu and filing a bug! While /etc/apparmor.d/abstractions/ubuntu-browsers.d/user-files is shipped by apparmor, it is actually /etc/apparmor.d/abstractions/ubuntu- browsers.d/firefox that #include's it, and this file is managed by the firefox package, so moving this bug

[Touch-packages] [Bug 1660040] Re: old-fashioned ufw structure reduces usability

2017-01-30 Thread Jamie Strandboge
** Changed in: ufw (Ubuntu) Importance: Undecided => Wishlist -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ufw in Ubuntu. https://bugs.launchpad.net/bugs/1660040 Title: old-fashioned ufw structure reduces usability

<    1   2   3   4   5   6   7   8   9   10   >