Ok, I've tried it with only this change to /etc/apparmor.d/fusermount3
and Flatpak is working:

root@cube:/etc/apparmor.d# diff fusermount3 ~/fusermount3 
11d10
<   /run/mount/utab.lock rwk,


The Logs are:

Sep 27 07:45:38 cube kernel: audit: type=1400 audit(1758923138.690:299): 
apparmor="DENIED" operation="capable" class="cap" profile="fusermount3" 
pid=110534 comm="fusermount3" capability=1  capname="dac_override"
Sep 27 07:45:38 cube kernel: audit: type=1400 audit(1758923138.690:300): 
apparmor="DENIED" operation="capable" class="cap" profile="fusermount3" 
pid=110534 comm="fusermount3" capability=7  capname="setuid"
Sep 27 07:45:38 cube kernel: audit: type=1400 audit(1758923138.690:301): 
apparmor="DENIED" operation="capable" class="cap" profile="fusermount3" 
pid=110535 comm="fusermount3" capability=7  capname="setuid"
Sep 27 07:45:38 cube kernel: audit: type=1400 audit(1758923138.813:302): 
apparmor="DENIED" operation="capable" class="cap" profile="fusermount3" 
pid=110546 comm="fusermount3" capability=1  capname="dac_override"
Sep 27 07:45:38 cube kernel: audit: type=1400 audit(1758923138.813:303): 
apparmor="DENIED" operation="capable" class="cap" profile="fusermount3" 
pid=110546 comm="fusermount3" capability=7  capname="setuid"
Sep 27 07:45:38 cube kernel: audit: type=1400 audit(1758923138.813:304): 
apparmor="DENIED" operation="capable" class="cap" profile="fusermount3" 
pid=110547 comm="fusermount3" capability=7  capname="setuid"
Sep 27 07:45:38 cube kernel: audit: type=1400 audit(1758923138.814:305): 
apparmor="DENIED" operation="mknod" class="file" profile="fusermount3" 
name="/run/mount/utab.act" pid=110547 comm="umount" requested_mask="c" 
denied_mask="c" fsuid=0 ouid=0
Sep 27 07:45:38 cube kernel: audit: type=1400 audit(1758923138.814:306): 
apparmor="DENIED" operation="open" class="file" profile="fusermount3" 
name="/run/mount/utab" pid=110547 comm="umount" requested_mask="r" 
denied_mask="r" fsuid=0 ouid=0
Sep 27 07:45:38 cube kernel: audit: type=1400 audit(1758923138.814:307): 
apparmor="DENIED" operation="open" class="file" profile="fusermount3" 
name="/run/mount/utab.event" pid=110547 comm="umount" requested_mask="wc" 
denied_mask="wc" fsuid=0 ouid=0
Sep 27 07:45:38 cube kernel: audit: type=1400 audit(1758923138.936:308): 
apparmor="DENIED" operation="capable" class="cap" profile="fusermount3" 
pid=110557 comm="fusermount3" capability=1  capname="dac_override"

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2122161

Title:
  error: Failed to install org.gnome.Platform: Could not unmount
  revokefs-fuse filesystem at /var/tmp/flatpak-
  cache-4EB3B3/org.gnome.Platform-EM6KC3: Child process exited with code
  1

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2122161/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to