In addition to the above, we need to:
* add to apparmor's abstractions/private-files-strict
  # don't allow access to any gnome-keyring modules
  audit deny /{,var/}run/user/[0-9]*/keyring** mrwkl,

* add to apparmor's abstractions/p11-kit:
  # gnome-keyring pkcs11 module
  owner /{,var/}run/user/[0-9]*/keyring*/pkcs11 rw,


Adding this will allow telepathy and evince to work with the kernel change.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1208988

Title:
  AppArmor no longer mediates access to path-based AF_UNIX socket files

To manage notifications about this bug go to:
https://bugs.launchpad.net/apparmor/+bug/1208988/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to