Comment 5 for bug 1819734

Revision history for this message
Zygmunt Krynicki (zyga) wrote :

We've discussed this issue and determined the following:

 - the issue affects Debian and systems like it but not Ubuntu
 - the issue is caused by mysql reading the host's /etc/mysql configuration
 - on Debian this is not denied by apparmor
 - on Ubuntu this is denied by apparmor and the additional configuration set up by the snap is effective

The issue, as described by the bug title is not real but I acknowledge there is another issue with confinement. We've decided not to enable partial apparmor on existing Debian releases. We plan to enable it on the next stable release, where people need to explicitly upgrade and accept the consequences of the new behaviour. While it affects nextcloud negatively, we don't want to break existing installations where snaps worked because confinement was lax in Debian, but gets stronger to the point of breaking without those people upgrading their Debian installations explicitly.