[Touch-packages] [Bug 2058866] Re: proposed-migration for cups-browsed 2.0.0-0ubuntu8

2024-03-26 Thread Georgia Garcia
The fix is similar for privoxy. I attached the debdiff that fixes it. ** Patch added: "privoxy_3.0.34-3ubuntu2.debdiff" https://bugs.launchpad.net/ubuntu/+source/cups-browsed/+bug/2058866/+attachment/5759689/+files/privoxy_3.0.34-3ubuntu2.debdiff -- You received this bug notification

[Touch-packages] [Bug 2058866] Re: proposed-migration for cups-browsed 2.0.0-0ubuntu8

2024-03-26 Thread Georgia Garcia
Ah, sorry, Łukasz. I didn't see you were working on it. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/2058866 Title: proposed-migration for cups-browsed 2.0.0-0ubuntu8

[Touch-packages] [Bug 2046844] Re: AppArmor user namespace creation restrictions cause many applications to crash with SIGTRAP

2024-03-15 Thread Georgia Garcia
Erich Eickmeyer, I don't have a Tuxedo Computer to test, so could you please check if the following profile works for you? $ echo "# This profile allows everything and only exists to give the # application a name instead of having the label "unconfined" abi , include profile

[Touch-packages] [Bug 2033282] Re: package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: yeni apparmor paketi pre-installation betiği alt süreci 1 hatalı çıkış kodu ile sona erdi

2024-03-08 Thread Georgia Garcia
*** This bug is a duplicate of bug 2032851 *** https://bugs.launchpad.net/bugs/2032851 ** This bug has been marked a duplicate of bug 2032851 package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: new apparmor package pre-installation script subprocess returned error exit status 1

[Touch-packages] [Bug 2038443] Re: mantic:linux: ubuntu_qrt_apparmor: ApparmorTestsuites.test_regression_testsuiteattach_disconnected.

2024-03-08 Thread Georgia Garcia
*** This bug is a duplicate of bug 2051932 *** https://bugs.launchpad.net/bugs/2051932 ** This bug has been marked a duplicate of bug 2051932 attach_disconnected test from test_regression_testsuite of ubuntu_qrt_apparmor failed with "Unable to run test sub-executable" on Mantic -- You

[Touch-packages] [Bug 2046844] Re: AppArmor user namespace creation restrictions cause many applications to crash with SIGTRAP

2024-02-16 Thread Georgia Garcia
** Changed in: devhelp (Ubuntu) Status: Confirmed => Fix Released ** Changed in: devhelp (Ubuntu) Assignee: (unassigned) => Georgia Garcia (georgiag) ** Changed in: epiphany-browser (Ubuntu) Status: Confirmed => Fix Released ** Changed in: epiphany-browse

[Touch-packages] [Bug 2052489] Re: Mate Daily Graphic Layer does not come up - apparmor denied snap desktop integration

2024-02-06 Thread Georgia Garcia
** Also affects: apparmor Importance: Undecided Status: New ** No longer affects: apparmor ** Also affects: lightdm (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed

[Touch-packages] [Bug 2051506] Re: apparmor blocks libnss-resolve socket

2024-02-06 Thread Georgia Garcia
Hi Gunnar, could you share which AppArmor version you are running? and which kernel version? Thanks -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/2051506 Title:

[Touch-packages] [Bug 2052297] Re: Please add opt.keybase.keybase profile

2024-02-05 Thread Georgia Garcia
** Changed in: apparmor (Ubuntu) Status: New => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/2052297 Title: Please add opt.keybase.keybase profile

[Touch-packages] [Bug 2018439] Re: Apparmor crashes GPU acceleration

2024-02-01 Thread Georgia Garcia
Hi Daniel! Thanks for testing and making sure. As you were able to figure out, the AppArmor parser accepts both include and #includes, although we are deprecating the latter. Since the AppArmor policy is distributed by the Mozilla Team's firefox, they need to add this permission to their

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2024-01-02 Thread Georgia Garcia
Hi Gerard Brave does not work currently because we only added support to Chromium, Firefox and Opera as you can see in the current snap_browsers abstraction [1]. I'm adding Brave support as well [2]. While that change is not applied to the apparmor package, as a workaround, you could apply the

[Touch-packages] [Bug 2046477] [NEW] Enable unprivileged user namespace restrictions by default

2023-12-14 Thread Georgia Garcia
Public bug reported: As per https://discourse.ubuntu.com/t/spec-unprivileged-user-namespace- restrictions-via-apparmor-in-ubuntu-23-10/37626, unprivileged user namespace restrictions for Ubuntu 23.10 are to be enabled by default via a sysctl.d conf file in apparmor, and for that to happen, the

[Touch-packages] [Bug 2044604] Re: package apparmor 2.12-4ubuntu5.3+esm1 installed the 20.04 release, with words, "mer/upgrade: new apparmor package pre-installation script subprocess returned error e

2023-11-29 Thread Georgia Garcia
*** This bug is a duplicate of bug 2032851 *** https://bugs.launchpad.net/bugs/2032851 Hi Herb! The fix is already on the way and should be available to you soon. Meanwhile, as a workaround, you can remove the /etc/apparmor.d/cache/e10c1cf9.0 directory with rm -r

[Touch-packages] [Bug 2044604] Re: package apparmor 2.12-4ubuntu5.3+esm1 installed the 20.04 release, with words, "mer/upgrade: new apparmor package pre-installation script subprocess returned error e

2023-11-28 Thread Georgia Garcia
*** This bug is a duplicate of bug 2032851 *** https://bugs.launchpad.net/bugs/2032851 ** This bug has been marked a duplicate of bug 2032851 package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: new apparmor package pre-installation script subprocess returned error exit status 1

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2023-11-21 Thread Georgia Garcia
The autopkgtests for apparmor failed for the evince update because the test requires the apparmor update which is also in proposed https://launchpad.net/ubuntu/+source/apparmor/3.0.4-2ubuntu2.3 but it is not a regression. -- You received this bug notification because you are a member of Ubuntu

[Touch-packages] [Bug 2043869] Re: package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: new apparmor package pre-installation script subprocess returned error exit status 1

2023-11-20 Thread Georgia Garcia
*** This bug is a duplicate of bug 2032851 *** https://bugs.launchpad.net/bugs/2032851 ** This bug has been marked a duplicate of bug 2032851 package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: new apparmor package pre-installation script subprocess returned error exit status 1

[Touch-packages] [Bug 2032851] Re: package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: new apparmor package pre-installation script subprocess returned error exit status 1

2023-11-17 Thread Georgia Garcia
Verification from proposed was successful: georgia@sec-bionic-amd64:~$ sudo bash -c "cat deb http://archive.ubuntu.com/ubuntu/ focal-proposed restricted main > multiverse universe > EOF" georgia@sec-bionic-amd64:~$ sudo bash -c "cat

[Touch-packages] [Bug 2043326] Re: package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: »neues apparmor-Skript des Paketes pre-installation«-Unterprozess gab den Fehlerwert 1 zurück

2023-11-16 Thread Georgia Garcia
*** This bug is a duplicate of bug 2032851 *** https://bugs.launchpad.net/bugs/2032851 Hello! Thanks for the report. I noticed that it is a duplicate of Bug 2032851 which already has a fix on its way. Meanwhile, as a workaround, you could fix the upgrade issue by running rm -r

[Touch-packages] [Bug 2043326] Re: package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: »neues apparmor-Skript des Paketes pre-installation«-Unterprozess gab den Fehlerwert 1 zurück

2023-11-16 Thread Georgia Garcia
*** This bug is a duplicate of bug 2032851 *** https://bugs.launchpad.net/bugs/2032851 ** This bug has been marked a duplicate of bug 2032851 package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: new apparmor package pre-installation script subprocess returned error exit status 1

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2023-10-20 Thread Georgia Garcia
Reuploading because I had a conflicting version with what was rejected in -proposed ** Patch added: "evince_42.3-0ubuntu3.2.debdiff" https://bugs.launchpad.net/ubuntu/+source/evince/+bug/1794064/+attachment/5711859/+files/evince_42.3-0ubuntu3.2.debdiff -- You received this bug notification

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2023-10-20 Thread Georgia Garcia
** Patch removed: "evince_42.3-0ubuntu3.1.debdiff" https://bugs.launchpad.net/ubuntu/+source/evince/+bug/1794064/+attachment/5711419/+files/evince_42.3-0ubuntu3.1.debdiff -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2023-10-19 Thread Georgia Garcia
Hi! You're right, I forgot to request a sponsorship. I uploaded the patch for evince/jammy, could you take a look and sponsor if possible? Thanks ** Patch added: "evince_42.3-0ubuntu3.1.debdiff"

[Touch-packages] [Bug 2039242] Re: package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: new apparmor package pre-installation script subprocess returned error exit status 1

2023-10-16 Thread Georgia Garcia
*** This bug is a duplicate of bug 2032851 *** https://bugs.launchpad.net/bugs/2032851 ** This bug has been marked a duplicate of bug 2032851 package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: new apparmor package pre-installation script subprocess returned error exit status 1

[Touch-packages] [Bug 2032851] Re: package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: new apparmor package pre-installation script subprocess returned error exit status 1

2023-10-10 Thread Georgia Garcia
** Changed in: apparmor (Ubuntu) Importance: Undecided => Critical -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/2032851 Title: package apparmor 2.12-4ubuntu5.3

[Touch-packages] [Bug 2032851] Re: package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: new apparmor package pre-installation script subprocess returned error exit status 1

2023-10-10 Thread Georgia Garcia
us: No upgrade log present (probably fresh install) ** Patch added: "apparmor_2.13.3-7ubuntu5.3.debdiff" https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2032851/+attachment/5708296/+files/apparmor_2.13.3-7ubuntu5.3.debdiff ** Changed in: apparmor (Ubuntu) Assi

[Touch-packages] [Bug 2038740] Re: package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: o subprocesso do pacote apparmor, novo script pre-installation retornou erro do status de saída 1

2023-10-10 Thread Georgia Garcia
*** This bug is a duplicate of bug 2032851 *** https://bugs.launchpad.net/bugs/2032851 ** This bug has been marked a duplicate of bug 2032851 package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: new apparmor package pre-installation script subprocess returned error exit status 1

[Touch-packages] [Bug 2038443] Re: mantic:linux: ubuntu_qrt_apparmor: ApparmorTestsuites.test_regression_testsuiteattach_disconnected.

2023-10-06 Thread Georgia Garcia
Hi! Could you share the kernel and apparmor version? I tested on mantic with the configuration below and I wasn't able to reproduce the failure for this specific test. I did see an unrelated dbus issue with the test suite and proposed a fixed on

[Touch-packages] [Bug 2034100] Re: package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: new apparmor package pre-installation script subprocess returned error exit status 1

2023-09-05 Thread Georgia Garcia
*** This bug is a duplicate of bug 2032851 *** https://bugs.launchpad.net/bugs/2032851 ** Information type changed from Private Security to Public ** This bug has been marked a duplicate of bug 2032851 package apparmor 2.12-4ubuntu5.3 failed to install/upgrade: new apparmor package

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2023-07-06 Thread Georgia Garcia
Andreas, Jeremy, you are correct. The worst that could happen is the same behavior we have currently: when we click a URL the browser does not open, we get a denied log and evince prints "Permission denied". My previous statement that profile loading could fail if apparmor did not find

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2023-06-28 Thread Georgia Garcia
I have verified on lunar with both apparmor and evince packages updated from the proposed pocket, it works as expected. ** Tags removed: verification-needed-lunar ** Tags added: verification-done-lunar -- You received this bug notification because you are a member of Ubuntu Touch seeded

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2023-06-20 Thread Georgia Garcia
Steve, the snap_browsers abstractions needed an update because the abstraction had not been updated in an year and the snap browsers now required read and lock permissions to the file /var/lib/snapd/inhibit/{browser-name}.lock, but this was also submitted, approved and merged upstream:

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2023-06-09 Thread Georgia Garcia
Hi Steve. I updated the patches containing the requested changes and uploaded them to https://launchpad.net/~georgiag/+archive/ubuntu/lp1794064/+packages Please let me know if you prefer I attached the debdiffs here. I'm resubscribing ~ubuntu-sponsors. Thanks ** Patch removed:

[Touch-packages] [Bug 2018439] Re: Apparmor crashes GPU acceleration

2023-05-04 Thread Georgia Garcia
Hi Daniel. Thanks for the report! Could you try the following commands and let me know if they fix the issue? sudo sh -c "echo 'include ' >> /etc/apparmor.d/local/usr.bin.firefox" sudo apparmor_parser -r /etc/apparmor.d/usr.bin.firefox -- You received this bug notification because you are a

[Touch-packages] [Bug 2009230] Re: AppArmor denials for rsyslog

2023-03-24 Thread Georgia Garcia
I added the consoles abstraction to the rsyslog AppArmor profile and I also had to add syslog to the tty group, otherwise rsyslog would not have been able to write to /dev/console due to file permissions (bug 1890177). I added the proposed changes to this PPA

[Touch-packages] [Bug 2009317] Re: All Snaps Broken After Release Upgrade

2023-03-21 Thread Georgia Garcia
I think /var/log/syslog and /var/log/kern.log will be sufficient. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/2009317 Title: All Snaps Broken After Release Upgrade

[Touch-packages] [Bug 2009317] Re: All Snaps Broken After Release Upgrade

2023-03-16 Thread Georgia Garcia
Hi! Could you upload some system logs of when this happens? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/2009317 Title: All Snaps Broken After Release Upgrade Status

[Touch-packages] [Bug 2009230] Re: AppArmor denials for rsyslog

2023-03-07 Thread Georgia Garcia
Hi Chlo! I was just testing a fix that I did myself: https://launchpad.net/~georgiag/+archive/ubuntu/lp2009230/+packages and it seemed to work as expected. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to rsyslog in Ubuntu.

[Touch-packages] [Bug 2009230] Re: AppArmor denials for rsyslog

2023-03-03 Thread Georgia Garcia
** Also affects: gce-compute-image-packages (Ubuntu) Importance: Undecided Status: New ** Description changed: The AppArmor profile for rsyslog, which had been disabled on previous Ubuntu versions, was enabled in lunar. The package google-compute-engine added a config file to

[Touch-packages] [Bug 2009230] [NEW] AppArmor denials for rsyslog

2023-03-03 Thread Georgia Garcia
Public bug reported: The AppArmor profile for rsyslog, which had been disabled on previous Ubuntu versions, was enabled in lunar. The package google-compute-engine added a config file to rsyslog which requires rw access to /dev/console google:ubuntu-23.04-64 /root# cat

[Touch-packages] [Bug 2003383] Re: LXC ignores lxc.rootfs.options on container reboot

2023-02-16 Thread Georgia Garcia
** Also affects: lxc Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/2003383 Title: LXC ignores lxc.rootfs.options on

[Touch-packages] [Bug 2006528] Re: LXD processes are not enforced in Ubuntu 20.04 HWE kernel

2023-02-16 Thread Georgia Garcia
/proc is not usually shared between the host and the container, but I can see how that can happen if you run the mount with hidepid=2 on the host. When it comes to processes, aa-status works by going through /proc and reading attr/apparmor/current. So if you remount /proc with hidepid=2, then

[Touch-packages] [Bug 2006528] Re: LXD processes are not enforced in Ubuntu 20.04 HWE kernel

2023-02-16 Thread Georgia Garcia
Could you also provide some kernel logs? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/2006528 Title: LXD processes are not enforced in Ubuntu 20.04 HWE kernel Status

[Touch-packages] [Bug 1641236] Re: Confined processes inside container cannot fully access host pty device passed in by lxc exec

2023-02-10 Thread Georgia Garcia
Thanks, Simon, I must have missed it. When I use --mode=non-interactive on lxc and -l on tcpdump, I don't see the issue at all. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu.

[Touch-packages] [Bug 1667016] Re: tcpdump in lxd container: apparmor blocks writing to stdout/stderr

2023-02-10 Thread Georgia Garcia
** Description changed: + [ Impact ] + + Users that run tcpdump from an SSH session inside a container cannot + see the output because tcpdump tries to write to /dev/pts/, which is + not allowed by the AppArmor policy. + + This upload fixes the bug by allowing read/write access to the devices +

[Touch-packages] [Bug 1641236] Re: Confined processes inside container cannot fully access host pty device passed in by lxc exec

2023-02-10 Thread Georgia Garcia
I tried reproducing the issue on a 22.04 VM with a 22.04 container and I got some weird behavior, not consistent to what was reported in the comments, so I appreciate if anyone can also take a look. What I found is that I can only reproduce the issue when running tcpdump in

[Touch-packages] [Bug 1667016] Re: tcpdump in lxd container: apparmor blocks writing to stdout/stderr

2023-02-09 Thread Georgia Garcia
I agree that this issue is not a duplicate of Bug 1641236 and it can be fixed by adding rw access to /dev/pts/*, which is not the case for the other bug. ** This bug is no longer a duplicate of bug 1641236 Confined processes inside container cannot fully access host pty device passed in by

[Touch-packages] [Bug 2003383] Re: LXC ignores lxc.rootfs.options on container reboot

2023-02-09 Thread Georgia Garcia
Hello, Looking at the lxc logs exclusively I couldn't figure out what's going on, or if it's related to AppArmor. Could you also provide the kernel logs from the host and from the container? Thank you -- You received this bug notification because you are a member of Ubuntu Touch seeded

[Touch-packages] [Bug 2006528] Re: LXD processes are not enforced in Ubuntu 20.04 HWE kernel

2023-02-09 Thread Georgia Garcia
Hello, I wasn't able to reproduce the error https://pastebin.canonical.com/p/VDkkkCx2HF/ Does the issue persist if you restart the container? Also, can you please check if restarting the apparmor service fixes it? -- You received this bug notification because you are a member of Ubuntu Touch

[Touch-packages] [Bug 1994146] Re: [SRU] apparmor - Focal, Jammy

2023-02-08 Thread Georgia Garcia
Tests for jammy worked as expected. The systemd autopkgtest on s390x passed after the test was retriggered. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1994146 Title:

[Touch-packages] [Bug 1993353] Re: Add posix message queue IPC mediation

2023-02-08 Thread Georgia Garcia
Tests for jammy worked as expected. The systemd autopkgtest on s390x passed after the test was retriggered. ** Tags removed: verification-needed verification-needed-jammy ** Tags added: verification-done verification-done-jammy -- You received this bug notification because you are a member of

[Touch-packages] [Bug 1994146] Re: [SRU] apparmor - Focal, Jammy

2023-02-08 Thread Georgia Garcia
** Tags removed: verification-needed verification-needed-jammy ** Tags added: verification-done verification-done-jammy -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu.

[Touch-packages] [Bug 1728130] Re: Policy needs improved feature versioning to ensure it is correctly being applied

2023-01-31 Thread Georgia Garcia
Thank you for validating the test, Heather. In addition to the ABI validation, I also ran the AppArmor tests using the QA Regression Test suite (https://git.launchpad.net/qa-regression- testing/tree/scripts/test-apparmor.py). It includes tests for LibAppArmor, the parser, and all regression

[Touch-packages] [Bug 2000359] Re: posix_ipc in test_regression_testsuite from ubuntu_qrt_apparmor failed on K-5.19 arm64 (Unable to run test sub-executable)

2023-01-03 Thread Georgia Garcia
Thanks for reporting this issue. I created a MR upstream to fix it https://gitlab.com/apparmor/apparmor/-/merge_requests/962 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu.

[Touch-packages] [Bug 1728130] Re: Policy needs improved feature versioning to ensure it is correctly being applied

2022-12-12 Thread Georgia Garcia
Verification done. The autopkgtest failure for libreoffice was a temporary issue with the test infrastructure that passed when it was retriggered. ** Tags removed: verification-needed verification-needed-focal ** Tags added: verification-done verification-done-focal -- You received this bug

[Touch-packages] [Bug 1993353] Re: Add posix message queue IPC mediation

2022-12-12 Thread Georgia Garcia
** Tags removed: verification-needed-focal ** Tags added: verification-done-focal -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1993353 Title: Add posix message queue

[Touch-packages] [Bug 1964636] Re: Incorrect handling of apparmor `bpf` capability

2022-12-12 Thread Georgia Garcia
Verification done. The autopkgtest failure for libreoffice was a temporary issue with the test infrastructure that passed when it was retriggered. ** Tags removed: verification-needed verification-needed-focal ** Tags added: verification-done verification-done-focal -- You received this bug

[Touch-packages] [Bug 1994146] Re: [SRU] apparmor - Focal, Jammy

2022-12-12 Thread Georgia Garcia
** Tags removed: verification-needed-focal ** Tags added: verification-done-focal -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1994146 Title: [SRU] apparmor - Focal,

[Touch-packages] [Bug 1994146] Re: [SRU] apparmor - Focal, Jammy

2022-12-05 Thread Georgia Garcia
Łukasz, the commits that are "missing" from the upstream merge request had already been merged. They are: mqueue8-libapparmor-add-support-for-requested-and-denied-on-.patch mqueue9-libapparmor-add-support-for-class-in-logparsing.patch Corresponding commits upstream:

[Touch-packages] [Bug 1994146] Re: [SRU] apparmor - Focal, Jammy

2022-11-23 Thread Georgia Garcia
Chris, I added the missing SRU information on the bugs that were missing. > The packaging itself looks sane, but my understanding is that this adds > new classes of apparmor denials, and *particularly* it appears that this > might cause existing apparmor profiles to deny application behaviour >

[Touch-packages] [Bug 1728130] Re: Policy needs improved feature versioning to ensure it is correctly being applied

2022-11-23 Thread Georgia Garcia
** Merge proposal linked: https://code.launchpad.net/~georgiag/qa-regression-testing/+git/qa-regression-testing/+merge/433546 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu.

[Touch-packages] [Bug 1964636] Re: Incorrect handling of apparmor `bpf` capability

2022-11-23 Thread Georgia Garcia
Description updated with the SRU template information. ** Description changed: - We've recently noticed a lot of the LXD CI jobs failing because of - apparmor related snapd issues. + [ Impact ] - The way this usually manifests is: - - lxc launch images:ubuntu/20.04 c1 - - lxc exec c1 -- apt

[Touch-packages] [Bug 1728130] Re: Policy needs improved feature versioning to ensure it is correctly being applied

2022-11-23 Thread Georgia Garcia
Chris, I updated the description with the SRU template information. The test plan shows this does what we need: 1. feature is in kernel, abi set in policy is kernel, and policy does not have permission: execution fails with permission denied. 2. abi set in policy does not contain feature, and

[Touch-packages] [Bug 1728130] Re: Policy needs improved feature versioning to ensure it is correctly being applied

2022-11-23 Thread Georgia Garcia
** Description changed: + [ Impact ] + Currently allows pinning a single feature abi or running in a developer mode where the full abi available of the current kernel is enforced. However this can result in breaking applications in undesirable ways. If an application is shipped

[Touch-packages] [Bug 1994146] Re: [SRU] apparmor - Focal, Jammy

2022-11-21 Thread Georgia Garcia
Hi Steve Langasek, thanks for taking a look at the SRU. > Is that not what this means, or is mqueue access actually denied by > default and this refers only to how an unqualified 'mqueue' rule is > interpreted? Correct, this only refers to how an unqualified 'mqueue' rule is interpreted. > In

[Touch-packages] [Bug 1994146] [NEW] [SRU] apparmor - Focal, Jammy

2022-10-25 Thread Georgia Garcia
Public bug reported: [ Impact ] This is a SRU proposal for apparmor in Focal and Jammy. For focal, we want to SRU fixes for Bug 1964636 which introduces the capability upstream patches. We are also fixing Bug 1728130 and Bug 1993353 which are introducing full backport of abi from apparmor-3.0

[Touch-packages] [Bug 1728130] Re: Policy needs improved feature versioning to ensure it is correctly being applied

2022-10-20 Thread Georgia Garcia
This feature is required by Bug 1993353. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1728130 Title: Policy needs improved feature versioning to ensure it is correctly

[Touch-packages] [Bug 1993353] Re: Add posix message queue IPC mediation

2022-10-20 Thread Georgia Garcia
** Description changed: [ Impact ] We need to add IPC mediation support in the userspace tools, starting with posix message queue. This would improve security and lower the attack surface for applications - There is already a proposal upstream: + There is already a proposal upstream:

[Touch-packages] [Bug 1993353] [NEW] Add posix message queue IPC mediation

2022-10-18 Thread Georgia Garcia
Public bug reported: [ Impact ] We need to add IPC mediation support in the userspace tools, starting with posix message queue. This would improve security and lower the attack surface for applications There is already a proposal upstream:

[Touch-packages] [Bug 1989309] Re: [FFe] new apparmor features for 3.0.7

2022-10-13 Thread Georgia Garcia
** Changed in: apparmor (Ubuntu) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1989309 Title: [FFe] new apparmor features for

[Touch-packages] [Bug 1989309] Re: [FFe] new apparmor features for 3.0.7

2022-10-03 Thread Georgia Garcia
I updated the description and PPAs to reflect what we are hoping to land: patches on top of 3.0.7 instead of a new 3.1.1 release. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu.

[Touch-packages] [Bug 1989309] Re: [FFe] new apparmor features for 3.0.7

2022-10-03 Thread Georgia Garcia
** Attachment added: "apparmor-3.0.7-1ubuntu2-apt-upgrade.log" https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1989309/+attachment/5620824/+files/apparmor-3.0.7-1ubuntu2-apt-upgrade.log ** Description changed: - AppArmor 3.1.1 is the latest upstream version of the apparmor userspace

[Touch-packages] [Bug 1989309] Re: [FFe] new apparmor features for 3.0.7

2022-10-03 Thread Georgia Garcia
** Summary changed: - [FFe] apparmor 3.1.1 upstream release + [FFe] new apparmor features for 3.0.7 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1989309 Title: [FFe]

[Touch-packages] [Bug 1703821] Re: Dovecot and Apparmor complains at operation file_inherit

2022-08-04 Thread Georgia Garcia
Robie, thank you for taking a look at it. In this case, the user is impacted by noisy logs, since the dovecot profile is in complain mode. That means that AppArmor does not block actions, it only logs them, so that's probably the reason we are not getting more users reporting this. I believe

[Touch-packages] [Bug 1703821] Re: Dovecot and Apparmor complains at operation file_inherit

2022-08-02 Thread Georgia Garcia
** Description changed: [Impact] Users report that while running dovecot there are some issues reported by AppArmor, specifically regarding "file_inherit" operations: Jul 12 13:31:19 myserver kernel: [ 3905.672577] audit: type=1400 audit(1499859079.016:363): apparmor="ALLOWED"

[Touch-packages] [Bug 1703821] Re: Dovecot and Apparmor complains at operation file_inherit

2022-08-01 Thread Georgia Garcia
I have attached a debdiff for AppArmor containing the upstream fix. ** Description changed: - My server is running Ubuntu 17.04 and Dovecot 2.2.27 (c0f36b0). Apparmor - is still complaining about problems with file_inherit. I have put the - profiles in complain-only mode, so I can continue, but

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2022-05-10 Thread Georgia Garcia
@Sebastien, yes, I asked people from the security team to sponsor it but we are still reviewing the snap_browsers abstraction. We are denying access to /run/user/[0-9]*/gdm/Xauthority in the policy but if that was the case, then the browser should not have been able to open, but it does open so we

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2022-04-20 Thread Georgia Garcia
** Patch added: "apparmor_2.12-4ubuntu5.2.debdiff" https://bugs.launchpad.net/ubuntu/+source/evince/+bug/1794064/+attachment/5581885/+files/apparmor_2.12-4ubuntu5.2.debdiff -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2022-04-20 Thread Georgia Garcia
@Sebastien, yes, just did. Thank you! I also attached the debdiffs for evince and apparmor for bionic, focal, impish and jammy. They were also uploaded into the Security Proposed PPA: https://launchpad.net/~ubuntu-security-proposed/+archive/ubuntu/ppa/+packages?field.name_filter=apparmor

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2022-04-20 Thread Georgia Garcia
** Patch added: "apparmor_2.13.3-7ubuntu5.2.debdiff" https://bugs.launchpad.net/ubuntu/+source/evince/+bug/1794064/+attachment/5581884/+files/apparmor_2.13.3-7ubuntu5.2.debdiff ** Patch removed: "apparmor_3.0.3-0ubuntu1.1.debdiff"

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2022-04-20 Thread Georgia Garcia
** Patch added: "apparmor_3.0.3-0ubuntu1.1.debdiff" https://bugs.launchpad.net/ubuntu/+source/evince/+bug/1794064/+attachment/5581883/+files/apparmor_3.0.3-0ubuntu1.1.debdiff -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2022-04-20 Thread Georgia Garcia
** Patch added: "apparmor_3.0.3-0ubuntu1.1.debdiff" https://bugs.launchpad.net/ubuntu/+source/evince/+bug/1794064/+attachment/5581882/+files/apparmor_3.0.3-0ubuntu1.1.debdiff -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2022-04-20 Thread Georgia Garcia
** Patch added: "evince_3.28.4-0ubuntu1.3.debdiff" https://bugs.launchpad.net/ubuntu/+source/evince/+bug/1794064/+attachment/5581880/+files/evince_3.28.4-0ubuntu1.3.debdiff -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2022-04-20 Thread Georgia Garcia
** Patch added: "apparmor_3.0.4-2ubuntu3.debdiff" https://bugs.launchpad.net/ubuntu/+source/evince/+bug/1794064/+attachment/5581881/+files/apparmor_3.0.4-2ubuntu3.debdiff -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2022-04-20 Thread Georgia Garcia
** Patch added: "evince_40.4-2ubuntu0.1.debdiff" https://bugs.launchpad.net/ubuntu/+source/evince/+bug/1794064/+attachment/5581878/+files/evince_40.4-2ubuntu0.1.debdiff -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2022-04-20 Thread Georgia Garcia
** Patch added: "evince_3.36.10-0ubuntu1.1.debdiff" https://bugs.launchpad.net/ubuntu/+source/evince/+bug/1794064/+attachment/5581879/+files/evince_3.36.10-0ubuntu1.1.debdiff -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2022-04-20 Thread Georgia Garcia
** Patch added: "evince_42.1-3ubuntu1.debdiff" https://bugs.launchpad.net/ubuntu/+source/evince/+bug/1794064/+attachment/5581877/+files/evince_42.1-3ubuntu1.debdiff -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2022-04-20 Thread Georgia Garcia
** Description changed: - This is related to bug #1792648. After fixing that one (see discussion - at https://salsa.debian.org/gnome-team/evince/merge_requests/1), - clicking a hyperlink in a PDF opens it correctly if the default browser - is a well-known application (such as /usr/bin/firefox),

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2022-04-20 Thread Georgia Garcia
** Changed in: apparmor (Ubuntu) Assignee: (unassigned) => Georgia Garcia (georgiag) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1794064 Title: Click

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2022-04-19 Thread Georgia Garcia
I'm working on a SRU for apparmor and evince to introduce the snap_browsers abstraction on apparmor as a workaround for this issue. It is based on these two merge requests from upstream: https://gitlab.com/apparmor/apparmor/-/merge_requests/806

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2021-10-08 Thread Georgia Garcia
I was able to reproduce this issue on focal and bionic but not on impish. I'm still investigating why, since I don't see any changes in policies that might affect this issue, but I could have missed something. -- You received this bug notification because you are a member of Ubuntu Touch seeded

[Touch-packages] [Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2021-10-07 Thread Georgia Garcia
** Changed in: evince (Ubuntu) Assignee: (unassigned) => Georgia Garcia (georgiag) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1794064 Title: Click

[Touch-packages] [Bug 1918410] Re: isc-dhcp-client denied by apparmor

2021-08-17 Thread Georgia Garcia
** Tags added: hirsute -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to isc-dhcp in Ubuntu. https://bugs.launchpad.net/bugs/1918410 Title: isc-dhcp-client denied by apparmor Status in isc-dhcp package in Ubuntu: Triaged

[Touch-packages] [Bug 1940305] Re: dhclient not starting on boot due to apparmor

2021-08-17 Thread Georgia Garcia
*** This bug is a duplicate of bug 1918410 *** https://bugs.launchpad.net/bugs/1918410 This is likely a duplicate of bug #1918410 ** This bug has been marked a duplicate of bug 1918410 isc-dhcp-client denied by apparmor -- You received this bug notification because you are a member of

[Touch-packages] [Bug 1932331] Re: ubuntu_qrt_apparmor: i18n test fails on arm64 Hirsute / Impish

2021-07-08 Thread Georgia Garcia
After downloading the apparmor source from hirsute-proposed and running the regression tests, I was able to confirm that the i18n test is now passing for arm64. ** Tags removed: verification-needed verification-needed-hirsute ** Tags added: verification-done verification-done-hirsute -- You