[Bug 1864127] Re: apparmor denies ~/snap/chromium/ writes

2020-02-25 Thread Jamie Strandboge
$ aa-decode 2F686F6D652F7361726E6F6C642F736E61702F6368726F6D69756D2F313032362F2E636F6E6669672F6368726F6D69756D2F44656661756C742F53796E6320446174612F53796E63446174612E73716C697465332D6A6F75726E616C Decoded: /home/sarnold/snap/chromium/1026/.config/chromium/Default/Sync Data/SyncData.sqlite3-journa

[Bug 1862714] Re: package libdleyna-core-1.0-5 (not installed) failed to install/upgrade: trying to overwrite '/usr/lib/x86_64-linux-gnu/libdleyna-core-1.0.so.5.0.0', which is also in package libdleyn

2020-02-17 Thread Jamie Strandboge
Fyi, I worked around it with: $ sudo dpkg --purge --force-depends libdleyna-core-1.0-3 $ sudo apt-get -f install -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862714 Title: package libdleyna-core-

[Bug 1285444] Re: Login Successful, Desktop Never Loads

2020-02-16 Thread Jamie
Running into this issue on 19.10, so none of the unity-specific solutions work. If I switch TTY with ctrl+alt+F1, after I try to log back in and just see the desktop background, I'm brought to login screen again, but this time log in is successful. Disabling all gnome extensions doesn't seem to hel

[Bug 1863390] Re: GPU lockup ring 0 stalled for more than X msec

2020-02-14 Thread Jamie Bainbridge
** Attachment added: "dmesg-2020-02-15.txt" https://bugs.launchpad.net/ubuntu/+source/xserver-xorg-video-ati/+bug/1863390/+attachment/5328274/+files/dmesg-2020-02-15.txt -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.

[Bug 1863390] [NEW] GPU lockup ring 0 stalled for more than X msec

2020-02-14 Thread Jamie Bainbridge
Public bug reported: Since the update: xserver-xorg-video-ati-hwe-18.04 (1:19.0.1-1ubuntu1~18.04.1) bionic; which resulted from: https://bugs.launchpad.net/fedora/+source/xserver-xorg-video- ati/+bug/1841718 I've experienced GPU freezes where all video becomes unresponsive, both Xorg and Ctr

[Bug 1863390] Re: GPU lockup ring 0 stalled for more than X msec

2020-02-14 Thread Jamie Bainbridge
** Attachment added: "dmesg-2020-02-14.txt" https://bugs.launchpad.net/ubuntu/+source/xserver-xorg-video-ati/+bug/1863390/+attachment/5328273/+files/dmesg-2020-02-14.txt -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.

[Bug 1863119] [NEW] submittodebian: TypeError: write() argument must be str, not bytes

2020-02-13 Thread Jamie Strandboge
Public bug reported: On focal, I tried to use submittodebian and encountered this: $ submittodebian Traceback (most recent call last): File "/usr/bin/submittodebian", line 264, in main() File "/usr/bin/submittodebian", line 243, in main f.write(bug_body.encode('utf-8')) TypeError: w

[Bug 1862832] Re: snapd and Ubuntu 20.04 nvidia triggers apparmor denials on 'sendmsg' name=/run/nvidia-xdriver-xxxx and @var/run/nvidia-xdriver-*

2020-02-12 Thread Jamie Strandboge
Thanks! (re 'similar to'> yes, I had a typo :) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862832 Title: snapd and Ubuntu 20.04 nvidia triggers apparmor denials on 'sendmsg' name=/run/nvidia-xd

[Bug 1859643] Re: [snap] cannot use shared NSS db

2020-02-11 Thread Jamie Strandboge
OTOH, I think it makes sense to allow for the ability to share ~/.pki/nssdb (and yes, a personal-files addition along with a snap change (perhaps just a symlink from $SNAP_USER_DATA/.pki/nssdb to ~/.pki/nssdb would be enough rather than patching?). For read access, I have no problem with using per

[Bug 1862832] Re: Latest snapd triggers apparmor denials on 'sendmsg' name=/run/nvidia-xdriver-xxxx

2020-02-11 Thread Jamie Strandboge
Note, I found the unix path with: $ aa-decode @7661722F72756E2F6E76696469612D786472697665722D6638313737643966 String should only contain hex characters (0-9, a-f, A-F) $ aa-decode 7661722F72756E2F6E76696469612D786472697665722D66383

[Bug 1862832] Re: Latest snapd triggers apparmor denials on 'sendmsg' name=/run/nvidia-xdriver-xxxx

2020-02-11 Thread Jamie Strandboge
It looks like we need to adjust the policy to allow: /run/nvidia-xdriver-* rw, unix (send, receive) type=dgram peer=(addr="@var/run/nvidia-xdriver-*), I'm not sure if more is needed for the updated drivers. -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1861359] Re: swap storms kills interactive use

2020-01-31 Thread Jamie Strandboge
I forgot to mention, I also have nvme. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1861359 Title: swap storms kills interactive use To manage notifications about this bug go to: https://bugs.laun

[Bug 1861359] Re: swap storms kills interactive use

2020-01-31 Thread Jamie Strandboge
FYI, I decided to do this: $ sudo swapoff -a && sudo swapon -a $ free -h totalusedfree shared buff/cache available Mem: 15Gi 5.9Gi 4.8Gi 2.0Gi 4.8Gi 7.2Gi Swap: 15Gi 348Mi15Gi Even though I am no

[Bug 1861359] Re: swap storms kills interactive use

2020-01-31 Thread Jamie Strandboge
Seth and I talked about this and I marked this as affects me. If it helps, I saw this on eoan and focal doesn't make a difference (which might suggest the change is between disco and eoan). -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubunt

[Bug 1861177] Re: seccomp_rule_add is very slow

2020-01-28 Thread Jamie Strandboge
@mvo and @ijohnson, fyi, the fix for this may help with slow snap- seccomp (unconfirmed; not actively working on it at this time). ** Also affects: snapd Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed

[Bug 1860282] Re: corrupted desktop tooltips

2020-01-26 Thread Jamie
*** This bug is a duplicate of bug 1841718 *** https://bugs.launchpad.net/bugs/1841718 After a little more investigation, this is resolved on https://bugs.launchpad.net/fedora/+source/xserver-xorg-video- ati/+bug/1841718 and the fix is currently in ppa:canonical-x/x-staging ** This bug has be

[Bug 1860282] Re: corrupted desktop tooltips

2020-01-26 Thread Jamie
I am also seeing the same thing as the screencast. It can be reproduced with tooltips and the Alt+Tab window. Graphics card: Advanced Micro Devices, Inc. [AMD/ATI] Barts XT [Radeon HD 6870] Driver package: xserver-xorg-video-ati-hwe-18.04/bionic-updates,now 1:19.0.1-0ubuntu1~18.04.1 -- You rec

[Bug 1743200] Re: No support for interface labels

2020-01-22 Thread Jamie Murphy
+1. Its insane that a configuration option thats been around for years was skipped. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1743200 Title: No support for interface labels To manage notificati

[Bug 1849554] Re: Please move cache files to a different location

2020-01-20 Thread Jamie Strandboge
"Upstream apparmor has moved to defaulting the location to /var/cache/apparmor. But Ubuntu has yet to make this move." As mentioned in comment #1: "2.13.2-9ubuntu1 moved the cache dir to /var/cache/apparmor". Ubuntu 19.04+ is using /var/cache/apparmor. -- You received this bug notification becau

[Bug 1859972] Re: UFW doesn't support SCTP

2020-01-20 Thread Jamie Strandboge
I'll take a look at this when preparing the next release, which should be in the coming weeks. ** Changed in: ufw (Ubuntu) Importance: Undecided => Wishlist ** Changed in: ufw (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bu

[Bug 1858464] Re: iptable rules are still present after disabling ufw

2020-01-06 Thread Jamie Strandboge
Thank you for using Ubuntu and reporting a bug. Please note that 'sudo ufw disable' will flush the ufw chains and make them all 'pass through' (ie, think of them as NOPs) until reboot. On reboot, ufw won't run and even the pass through chains won't be added. Furthermore, unless MANAGE_BUILTINS is

[Bug 1849947] Re: Dell XPS 13 (7390) Display Flickering - 19.10

2019-12-29 Thread Jamie Bradley
Okay I've been silly. Just realised I hadn't installed the _all.deb first! I did notice during reboot that I got this error Couldn’t get size: 0x800e, however it disappears and I can carry on as normal. Not sure if you saw this too @Loik? -- You received this bug notification becaus

[Bug 1849947] Re: Dell XPS 13 (7390) Display Flickering - 19.10

2019-12-29 Thread Jamie Bradley
Hey @Loik thanks for the heads up. I've been able to install modules and image but for some reason the headers file won't install. When running via the OS Installer it never gives me the option to remove the file which suggests it hasn't installed. I then tried to install via terminal... ``` sud

[Bug 1849680] Re: audit spam in dmesg (libreoffice)

2019-12-17 Thread Jamie Strandboge
libreoffice ships this profile, so the bug should be tracked there. ** Package changed: apparmor (Ubuntu) => libreoffice (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1849680 Title: audit

[Bug 1849680] Re: audit spam in dmesg (libreoffice)

2019-12-17 Thread Jamie Strandboge
For the next libreoffice upload, the non-/home read-only accesses all look fine to add to the libreoffice profile. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1849680 Title: audit spam in dmesg (l

[Bug 1798961] Re: Random unrecoverable freezes on Ubuntu 18.10

2019-12-17 Thread Jamie Redmond
Happening to me too. Full details available on this issue: https://github.com/brave/brave-browser/issues/7439 ** Bug watch added: github.com/brave/brave-browser/issues #7439 https://github.com/brave/brave-browser/issues/7439 -- You received this bug notification because you are a member of Ub

[Bug 1848919] Re: [snap] Permission denied on Private encrypted folder

2019-12-17 Thread Jamie Strandboge
** Changed in: apparmor Status: Triaged => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1848919 Title: [snap] Permission denied on Private encrypted folder To manage notificatio

[Bug 1824812] Re: apparmor does not start in Disco LXD containers

2019-12-17 Thread Jamie Strandboge
This was fixed upstream in 61c27d8808f0589beb6a319cc04073e8bb32d860 ** Changed in: apparmor Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1824812 Title: appar

[Bug 1682055] Re: dh_apparmor does not remove profiles(s) when purging package

2019-12-17 Thread Jamie Strandboge
Keeping the profiles in the running kernel is by design since there might be processes that are still running under the profile on package removal. dpkg doesn't do anything to guarantee that executables that the package ships aren't running, so we can't reasonably unload the profiles. Marking Won't

[Bug 1667751] Re: Confined binaries running in namespaces unable to read their executable

2019-12-17 Thread Jamie Strandboge
John, what do you think about Seth's question in https://bugs.launchpad.net/apparmor/+bug/1667751/comments/5? ** Also affects: apparmor Importance: Undecided Status: New ** Changed in: apparmor Status: New => Incomplete -- You received this bug notification because you are a me

[Bug 1830502] Re: apparmor uses excessive memory leading to oom kill

2019-12-17 Thread Jamie Strandboge
** Also affects: apparmor Importance: Undecided Status: New ** Changed in: apparmor Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1830502 Title: apparmor u

[Bug 1834192] Re: apparmor mult_mount regression test fails in eoan

2019-12-17 Thread Jamie Strandboge
This was fixed in 2.13.3-5ubuntu1 which added upstream-tests-mult-mount- bump-size-of-created-disk.patch ** Changed in: apparmor (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https:/

[Bug 1518663] Re: Disconnected path errors

2019-12-17 Thread Jamie Strandboge
Ultimately this is a kernel issue and the limitations it puts on apparmor for tracking files with disconnected paths. There isn't anything that the apparmor package or abstractions can do to help with this, but people can update their profiles to use flags=(attach_disconnected), as mentioned. For p

[Bug 1518663] Re: Disconnected path errors

2019-12-17 Thread Jamie Strandboge
Today, people experiencing this error need to use flags=(attach_disconnected) in the profile. Eg: /path/to/thing flags=(attach_disconnected) { ... } -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/151

[Bug 1764715] Re: /dev/pts/0 access detected as /0

2019-12-17 Thread Jamie Strandboge
This is the result of a disconnected path with how the container is being setup. This isn't something that should be added to the apparmor abstractions. Ultimately this is a kernel issue and the limitations it puts on apparmor for tracking files with disconnected paths. There isn't anything that th

[Bug 1703821] Re: Dovecot and Apparmor complains at operation file_inherit

2019-12-17 Thread Jamie Strandboge
Marking the dovecot task as Invalid since it doesn't ship the profiles. ** Changed in: dovecot (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1703821 Title: Do

[Bug 1703821] Re: Dovecot and Apparmor complains at operation file_inherit

2019-12-17 Thread Jamie Strandboge
@Matyáš, this configuration seems like something you added: /etc/dovecot/conf.d/10-master.conf service auth { unix_listener auth-userdb { mode = 0666 user = vmail group = mail } unix_listener /var/spool/postfix/private/auth { mode = 0666 user =

[Bug 1792027] Re: evince denied access to mimeapps.list

2019-12-17 Thread Jamie Strandboge
** Changed in: apparmor (Ubuntu) Status: New => In Progress ** Changed in: apparmor (Ubuntu) Assignee: (unassigned) => Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchp

[Bug 1797242] Re: apparmor package has inappropriate Breaks/Replaces

2019-12-17 Thread Jamie Strandboge
These were only needed for bionic and we can drop in focal. ** Changed in: apparmor (Ubuntu) Status: New => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1797242 Title: apparmor

[Bug 1831490] Re: kernel is out of memory and killed during a kernel sys_write operation

2019-12-17 Thread Jamie Strandboge
*** This bug is a duplicate of bug 1848567 *** https://bugs.launchpad.net/bugs/1848567 I'm going to mark the linux task as Invalid and then mark as a dupe of bug 1848567 ** Changed in: linux (Ubuntu) Status: Confirmed => Won't Fix ** Changed in: apparmor (Ubuntu) Status: New =>

[Bug 1808360] Re: AppArmor fails after MySQL installation using 18.04.1 LTS

2019-12-17 Thread Jamie Strandboge
The apparmor package provides this file: $ dpkg -S /etc/apparmor.d/abstractions/mysql apparmor: /etc/apparmor.d/abstractions/mysql It seems the file was accidentally deleted. Recreating it in the manner you did is the proper way to resolve the issue. ** Changed in: apparmor (Ubuntu) Stat

[Bug 1813339] Re: Apparmor is denying evince from running vivaldi

2019-12-17 Thread Jamie Strandboge
The path to vivaldi indicates that the application you are trying to launch is not in the Ubuntu repositories. To accommodate this sort of thing, apparmor profiles in Ubuntu ship files in /etc/apparmor.d/local for admins to modify. I suggest adding this to /etc/apparmor.d/local/usr.bin.evince: /

[Bug 1849554] Re: Please move cache files to a different location

2019-12-17 Thread Jamie Strandboge
2.13.2-9ubuntu1 moved the cache dir to /var/cache/apparmor. ** Changed in: apparmor (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1849554 Title: Please m

[Bug 1482852] Re: apparmor profile usr.bin.firefox missing abstractions/ubuntu-helpers

2019-12-17 Thread Jamie Strandboge
** Package changed: apparmor (Ubuntu) => firefox (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1482852 Title: apparmor profile usr.bin.firefox missing abstractions/ubuntu-helpers To manage

[Bug 1580463] Re: Snap blocks access to system input methods (ibus, fcitx, ...)

2019-12-17 Thread Jamie Strandboge
@Gunnar - I am preparing the focal upload now, though there is a parser bug (bug 1856738) which means I cannot use @{HOME} in the rule and instead hardcode /home/*/. This will cover all typical situations (ie, not the atypical /root/.cache/ibus...) except when the user updates /etc/apparmor.d/tunab

[Bug 1856738] Re: access always denied when using @{HOME} tunable in peer_addr for abstract socket

2019-12-17 Thread Jamie Strandboge
** Also affects: apparmor (Ubuntu) Importance: Undecided Status: New ** Changed in: apparmor Status: New => Triaged ** Changed in: apparmor (Ubuntu) Status: New => Triaged ** Changed in: apparmor Importance: Undecided => Medium ** Changed in: apparmor (Ubuntu) Impo

[Bug 1849753] Re: AppArmor profile prohibits classic snap from inheriting file descriptors

2019-12-13 Thread Jamie Strandboge
>> An alternative without modifying snap-confine would be to have two >> snap-confine profiles, one for >> strict and one for classic, and adjust the classic template to transition to >> the classic >> snap-confine template which has rules allowing 'rw' access to files and >> 'unix' for sockets.

[Bug 1781428] Re: please enable snap mediation support

2019-12-12 Thread Jamie Strandboge
Note, there is a spread test in snapd that checks for if the mediation patches are dropped (or added). While it is fine for https://launchpad.net/bugs/1856054 to be fast tracked, this pulseaudio bug should not be marked as Fix Released before the end of year break unless you coordinate with the sna

[Bug 1851211] Re: [snap] SoloKeys not supported by u2f-devices interface

2019-12-10 Thread Jamie Strandboge
** Changed in: snapd Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1851211 Title: [snap] SoloKeys not supported by u2f-devices interface To manage notific

[Bug 1855477] Re: gnome-control-center will not let me paste in a password from my password manger

2019-12-09 Thread Jamie Strandboge
Thank you for using Ubuntu and reporting a bug. Are you using wayland or Xorg for your desktop session? What password manager are you using? ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which

[Bug 1739468] Re: Repeated [AppIndicatorSupport-WARN] Item :1.51/org/ayatana/NotificationItem/multiload is already registered

2019-12-07 Thread Jamie Browning
Why is this low importance when anyone who has this issue should be quiting the application rendering it useless, seems pretty high to me. What else could possibly trump this? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bug

[Bug 1816548] Re: [MIR] usbguard

2019-12-04 Thread Jamie Strandboge
0.7.5 does not fix bug #1855189 (and code inspection suggests 0.7.6 is also affected). IMO, bug #1855189 needs to be fixed as part of main inclusion. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/18165

[Bug 1816548] Re: [MIR] usbguard

2019-12-04 Thread Jamie Strandboge
I found the cause of usbguard becoming unresponsive and filed https://bugs.launchpad.net/usbguard/+bug/1855189 (with https://github.com/USBGuard/usbguard/issues/349). ** Bug watch added: github.com/USBGuard/usbguard/issues #349 https://github.com/USBGuard/usbguard/issues/349 -- You received t

[Bug 1855189] Re: usbguard stops responding when recvmsg receives ENOBUFS

2019-12-04 Thread Jamie Strandboge
FYI, IMHO, this bug needs to be fixed as part of the MIR process in bug #1816548. ** Bug watch added: github.com/USBGuard/usbguard/issues #349 https://github.com/USBGuard/usbguard/issues/349 ** Also affects: usbguard via https://github.com/USBGuard/usbguard/issues/349 Importance: Unknown

[Bug 1855189] [NEW] usbguard stops responding when recvmsg receives ENOBUFS

2019-12-04 Thread Jamie Strandboge
Public bug reported: With 0.7.4+ds-1 from 19.10, usbguard may stop responding to events when recvmsg fails with ENOBUFS. To reproduce:   while /bin/true ; do sudo udevadm control --reload-rules sudo udevadm trigger sudo udevadm settle --timeout=3   done Eventually, this pops out in t

[Bug 1851211] Re: [snap] SoloKeys not supported by u2f-devices interface

2019-11-26 Thread Jamie Strandboge
https://github.com/snapcore/snapd/pull/7779 ** Also affects: snapd Importance: Undecided Status: New ** Changed in: snapd Status: New => In Progress ** Changed in: snapd Importance: Undecided => Medium ** Changed in: snapd Assignee: (unassigned) => Jamie S

[Bug 1848919] Re: [snap] Permission denied on Private encrypted folder

2019-11-26 Thread Jamie Strandboge
https://github.com/snapcore/snapd/pull/7779 ** Also affects: snapd Importance: Undecided Status: New ** Changed in: snapd (Ubuntu) Assignee: Jamie Strandboge (jdstrand) => (unassigned) ** Changed in: snapd Importance: Undecided => Low ** Changed in: snapd As

[Bug 1781428] Re: please enable snap mediation support

2019-11-25 Thread Jamie Strandboge
Installing 1:8.0-0ubuntu3.11 from xenial-proposed, the test plan and James' addition for mediation is preserved across snapd restart all works as expected. Marking as verification done. ** Description changed: [Impact] Ubuntu 16.10 added rudimentary snap support to disable audio recording if

[Bug 1781428] Re: please enable snap mediation support

2019-11-25 Thread Jamie Strandboge
Installing 1:11.1-1ubuntu7.5 from bionic-proposed, the test plan and James' addition for mediation is preserved across snapd restart all works as expected. Marking as verification done. ** Tags removed: verification-needed-bionic ** Tags added: verification-done-bionic -- You received this bug n

[Bug 1781428] Re: please enable snap mediation support

2019-11-25 Thread Jamie Strandboge
** Description changed: [Impact] Ubuntu 16.10 added rudimentary snap support to disable audio recording if the connecting process was a snap. By Ubuntu 18.04, something changed in the build resulting in 'Enable Snappy support: no' with audio recording no longer being mediated by pulseaudio

[Bug 1851211] Re: [snap] SoloKeys not supported by u2f-devices interface

2019-11-22 Thread Jamie Strandboge
** Changed in: snapd (Ubuntu) Status: Triaged => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1851211 Title: [snap] SoloKeys not supported by u2f-devices interface To manage not

[Bug 1778332] Re: Apparmor Permission Denied (apparmor="DENIED")

2019-11-22 Thread Jamie Strandboge
Clement, your issue is different than Charles'. More information is required from you to triage your issue. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1778332 Title: Apparmor Permission Denied (a

[Bug 1778332] Re: Apparmor Permission Denied (apparmor="DENIED")

2019-11-22 Thread Jamie Strandboge
Nov 11 09:47:56 kernel: audit: type=1400 audit(1573487276.018:797080): apparmor="DENIED" operation="open" profile="snap.gnome-system-monitor.gnome-system-monitor" name="/run/systemd/sessions/c1" pi d=8733 comm="gnome-system-mo" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0 I'm able to repr

[Bug 1848919] Re: [snap] Permission denied on Private encrypted folder

2019-11-22 Thread Jamie Strandboge
Assignee: (unassigned) => Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1848919 Title: [snap] Permission denied on Private encrypted folder To manage notifications about th

[Bug 1791454] Re: system-monitor produces many apparmor permission denied warnings

2019-11-21 Thread Jamie Strandboge
Note, these accesses were added in 22d37f834b6f4605faa3887bae3cf4d0e1673278 ** Changed in: gnome-system-monitor (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.n

[Bug 1851211] Re: [snap] SoloKeys not supported by u2f-devices interface

2019-11-06 Thread Jamie Strandboge
I've added it to my trello card for 2.43 policy updates. ** Changed in: snapd (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1851211 Title: [snap] SoloKeys not

[Bug 1794064] Re: Clicking a hyperlink in a PDF fails to open it if the default browser is a snap

2019-11-05 Thread Jamie Strandboge
** Changed in: evince (Ubuntu) Status: Confirmed => Triaged ** Changed in: evince (Ubuntu) Assignee: (unassigned) => Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchp

[Bug 1850863] Re: execstack --set-execstack Aborted (core dump)

2019-10-31 Thread Jamie Strandboge
*** This bug is a duplicate of bug 1850861 *** https://bugs.launchpad.net/bugs/1850861 ** This bug has been marked a duplicate of bug 1850861 execstack --set-execstack Aborted (core dump) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 1850861] Re: execstack --set-execstack Aborted (core dump)

2019-10-31 Thread Jamie Strandboge
$ hardening-check /tmp/ls /tmp/ls: Position Independent Executable: yes Stack protected: yes Fortify Source functions: yes (some protected functions found) Read-only relocations: yes Immediate binding: yes Stack clash protection: yes Control flow integrity: yes On older releases, we can use

[Bug 1850863] [NEW] execstack --set-execstack Aborted (core dump)

2019-10-31 Thread Jamie Strandboge
Public bug reported: Reproducer: $ cp /bin/ls /tmp $ execstack --set-execstack /tmp/ls execstack: dso.c:877: reopen_dso: Assertion `dso->shdr[j].sh_size == 0' failed. Aborted (core dumped) [134] ProblemType: Bug DistroRelease: Ubuntu 19.10 Package: execstack 0.0.20131005-1 ProcVersionSignature:

[Bug 1850861] [NEW] execstack --set-execstack Aborted (core dump)

2019-10-31 Thread Jamie Strandboge
Public bug reported: Reproducer: $ cp /bin/ls /tmp $ execstack --set-execstack /tmp/ls execstack: dso.c:877: reopen_dso: Assertion `dso->shdr[j].sh_size == 0' failed. Aborted (core dumped) [134] ProblemType: Bug DistroRelease: Ubuntu 19.10 Package: execstack 0.0.20131005-1 ProcVersionSignature:

[Bug 1849753] Re: AppArmor profile prohibits classic snap from inheriting file descriptors

2019-10-30 Thread Jamie Strandboge
Since the issue is that an fd is opened by the first app running in one profile while transitioning to the snap-confine profile, there is an option that would 'work'. As a POC, I installed the hello-world snap and also created a test- classic snap (just hello-world renamed with 'confinement: class

[Bug 1849753] Re: AppArmor profile prohibits classic snap from inheriting file descriptors

2019-10-30 Thread Jamie Strandboge
" 1. adjust the classic policy to use: /usr/lib/snapd/snap-confine ix, /snap/$SNAP_WITH_SNAPD/$SNAP_WITH_SNAPD_REVISION/usr/lib/snapd/snap-confine ix, " This should have been: 1. adjust the classic policy to use: /usr/lib/snapd/snap-confine px -> unconfined, /snap/$SNAP_WITH_SNAPD/$SNA

[Bug 1844743] Re: ufw missing .conf for syslog-ng

2019-10-30 Thread Jamie Strandboge
** Changed in: ufw (Ubuntu) Status: New => Triaged ** Changed in: ufw (Ubuntu) Importance: Undecided => Medium ** Also affects: ufw Importance: Undecided Status: New ** Changed in: ufw Status: New => Triaged ** Changed in: ufw Importance: Undecided => Medium -- Y

[Bug 1850629] Re: [eoan] title bar transparent for several seconds on start (making gnome-tweaks unusable during this time)

2019-10-30 Thread Jamie Strandboge
This may be related to https://bugs.launchpad.net/ubuntu/+source/gnome- tweaks/+bug/1847136 since the reporter in that bug also refers to issues with the title bar. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad

[Bug 1850629] [NEW] [eoan] title bar transparent for several seconds on start (making gnome-tweaks unusable during this time)

2019-10-30 Thread Jamie Strandboge
Public bug reported: With the upgrade to 19.10, when I launch gnome-tweaks, it renders the window, but the title bar is transparent for a number of seconds (and therefore the '<' icon is unavailable for navigating the tool). Eventually, the title bar is fully rendered and the tool works fine. Lau

[Bug 1849753] Re: AppArmor profile prohibits classic snap from inheriting file descriptors

2019-10-30 Thread Jamie Strandboge
John, I know there are plans for FD delegation and properly mediating this but I wonder if there is any use for a 'file_inherit' rule that is perhaps just very coarse and would allow inheriting the fd. It does seem like this could provide a means of sandbox escape though since a(n unprivileged) pro

[Bug 1849753] Re: AppArmor profile prohibits classic snap from inheriting file descriptors

2019-10-30 Thread Jamie Strandboge
** Also affects: apparmor Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1849753 Title: AppArmor profile prohibits classic snap from inheriting file desc

[Bug 1850552] [NEW] logs spammed with file_inherit denials from classic snaps

2019-10-29 Thread Jamie Strandboge
e is already denying them. We could consider making these allowed rather than explicit deny, but people haven't been complaining about these classic chromium content api snaps not working, so I'd like to continue denying for now. ** Affects: snapd Importance: Medium Assi

[Bug 1849753] Re: AppArmor profile prohibits classic snap from inheriting file descriptors

2019-10-28 Thread Jamie Strandboge
> To be clear, I’m not using ‘snap run’, just the ‘node’ that snap has put in the PATH, which is /snap/bin/node (a symlink to /usr/bin/snap). Lots of applications expect to be able to run ‘node’ from the PATH, including the ‘node’ snap’s own ‘npm’, ‘npx’, ‘yarn’, and ‘yarnpkg’ scripts. Sure, node

[Bug 1849947] Re: Dell XPS 13 (7390) Display Flickering - 19.10

2019-10-27 Thread Jamie Bradley
Hi Timo, thanks for the response. I'm sorry but I'm not sure how to change the kernel - quite new to Ubuntu etc. Do you have a guide I could maybe take a look at to reference? Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. h

[Bug 1849947] [NEW] Dell XPS 13 (7390) Display Flickering - 19.10

2019-10-26 Thread Jamie Bradley
Public bug reported: Hi there, I recently purchased a Dell XPS 13 7390 (Developer Edition). I decided to replace 18.4 LTS with 19.10 and so far it has been pretty smooth. However, there is one issue which occurs frequently whereby the display flickers and becomes unusable. The best way to descr

[Bug 1849753] Re: AppArmor profile prohibits classic snap from inheriting file descriptors

2019-10-25 Thread Jamie Strandboge
As Zygmunt said, this is a current limitation with apparmor. The problem is because both node and snap-confine are differently confined by apparmor, there is a revalidation that happens when node calls itself since it invokes snap run, which invokes snap-confine which causes the revalidation (becau

[Bug 1830502] Re: apparmor uses excessive memory leading to oom kill

2019-10-24 Thread Jamie Strandboge
@Ivan, we are going to fix snapd for the excessive memory usage. AppArmor upstream already uses expr-simplify by default and newer release of Ubuntu use parser.conf to set -O no-expr-simplify so users can manage the setting like any other conffile. -- You received this bug notification because yo

[Bug 1848919] Re: [snap] Permission denied on Private encrypted folder

2019-10-23 Thread Jamie Strandboge
Ok, I'll fix this in the next batch of policy updates for snapd. ** Changed in: snapd (Ubuntu) Importance: Undecided => Low ** Changed in: snapd (Ubuntu) Status: New => Triaged ** Changed in: snapd (Ubuntu) Assignee: (unassigned) => Jamie Strandboge (jdstrand) --

[Bug 1848919] Re: [snap] Permission denied on Private encrypted folder

2019-10-23 Thread Jamie Strandboge
Ok, that is a read on /home/ubuntu/.Private/. Is the encrypted home mounted at the time of the denial? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1848919 Title: [snap] Permission denied on Privat

[Bug 1848919] Re: [snap] Permission denied on Private encrypted folder

2019-10-23 Thread Jamie Strandboge
Encrypted home is typically setup as ~/.Private, not ~/Private and the policy already allows: owner @{HOME}/.Private/** mrixwlk, owner @{HOMEDIRS}/.ecryptfs/*/.Private/** mrixwlk, The home interface should already allow ~/Private. What is the denial you see in the logs? -- You received this

[Bug 1849176] [NEW] installer crashes

2019-10-21 Thread Jamie Noonan
Public bug reported: crashes after 3 tries ProblemType: Bug DistroRelease: Ubuntu 19.04 Package: ubiquity 19.04.9 ProcVersionSignature: Ubuntu 5.0.0-13.14-generic 5.0.6 Uname: Linux 5.0.0-13-generic x86_64 ApportVersion: 2.20.10-0ubuntu27 Architecture: amd64 CasperVersion: 1.405 CurrentDesktop: u

[Bug 1781428] Re: please enable snap mediation support

2019-09-30 Thread Jamie Strandboge
** Changed in: pulseaudio (Ubuntu Xenial) Status: In Progress => Triaged ** Changed in: pulseaudio (Ubuntu Bionic) Status: In Progress => Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net

[Bug 1781428] Re: please enable snap mediation support

2019-09-29 Thread Jamie Strandboge
** Description changed: [Impact] Ubuntu 16.10 added rudimentary snap support to disable audio recording if the connecting process was a snap. By Ubuntu 18.04, something changed in the build resulting in 'Enable Snappy support: no' with audio recording no longer being mediated by pulseaudio

[Bug 1781428] Re: please enable snap mediation support

2019-09-29 Thread Jamie Strandboge
** Description changed: [Impact] Ubuntu 16.10 added rudimentary snap support to disable audio recording if the connecting process was a snap. By Ubuntu 18.04, something changed in the build resulting in 'Enable Snappy support: no' with audio recording no longer being mediated by pulseaudio

[Bug 1781428] Re: please enable snap mediation support

2019-09-29 Thread Jamie Strandboge
** Attachment added: "test-snapd-audio-record_1_amd64.snap" https://bugs.launchpad.net/ubuntu/+source/pulseaudio/+bug/1781428/+attachment/5292539/+files/test-snapd-audio-record_1_amd64.snap -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to U

[Bug 1781428] Re: please enable snap mediation support

2019-09-29 Thread Jamie Strandboge
Attaching test-snapd-pulseaudio and test-snapd-audio-record snaps. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1781428 Title: please enable snap mediation support To manage notifications about th

[Bug 1781428] Re: please enable snap mediation support

2019-09-29 Thread Jamie Strandboge
** Description changed: + [Impact] + Ubuntu 16.10 added rudimentary snap support to disable audio recording if the connecting process was a snap. By Ubuntu 18.04, something changed in the build resulting in 'Enable Snappy support: no' with audio recording no longer being mediated by pulseaudio

[Bug 1781428] Re: pulseaudio built with --enable-snappy but 'Enable Snappy support: no'

2019-09-29 Thread Jamie Strandboge
** Description changed: + + # Original summary: pulseaudio built with --enable-snappy but 'Enable + Snappy support: no' + + # Original description + From https://launchpadlibrarian.net/377100864/buildlog_ubuntu-cosmic- amd64.pulseaudio_1%3A12.0-1ubuntu1_BUILDING.txt.gz: ... dh_auto_c

[Bug 1767493] Re: 64bit integer division broken on 32bit armhf

2019-09-17 Thread Jamie Strandboge
I took a look at this and am unable to reproduce. The test program compiles and ran fine on an Ubuntu 16.04 system: $ ./test value1: -3 Running this under valgrind I see: $ valgrind --leak-check=yes ./test ==16237== Memcheck, a memory error detector ==16237== Copyright (C) 2002-2015, and GNU GPL

[Bug 1767493] Re: 64bit integer division broken on 32bit armhf

2019-09-17 Thread Jamie Strandboge
I do not have access to and Orange Pi or NanoPi Duo. I suggest trying again with an updated toolchain and see if you still have the issue, and if so, specify the gcc invocation and board information. Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is s

[Bug 301755] Re: Crackling noise after update to pulseaudio

2019-09-14 Thread Jamie
Sorry for bringing up an old post but I had problems similar to what was described here. I was able to "fix" the crackling audio issues using the following lines in daemon.pa: high-priority = yes nice-level = -11 realtime-scheduling = yes default-fragments = 8 default-fragment-size-msec = 10 Not

[Bug 1548057] Re: rfkill state is not restored on reboot

2019-09-12 Thread Jamie Strandboge
This still seems to be a problem on Ubuntu 19.04. Ie, if I do: $ sudo systemctl status systemd-rfkill ● systemd-rfkill.service - Load/Save RF Kill Switch Status Loaded: loaded (/lib/systemd/system/systemd-rfkill.service; static; vendor preset: ... $ rfkill block bluetooth $ rfkill ID TYPE

[Bug 1620635] Re: libapparmor's aa_query_label() always returns allowed = 0 for file rules containing the "owner" conditional

2019-09-11 Thread Jamie Strandboge
Retriaging these down to Medium. People worked around this in different ways and High was obviously inflated since it isn't fixed yet (I just verified with 5.0.0-25.26-generic and apparmor 2.13.2-9ubuntu6.1). ** Changed in: apparmor Importance: High => Medium ** Changed in: apparmor (Ubuntu)

<    1   2   3   4   5   6   7   8   9   10   >