apparmor denies app-specific download directory

Bug #1384349 reported by Robert Schroll
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
apparmor-easyprof-ubuntu (Ubuntu)
Fix Released
Critical
Jamie Strandboge
apparmor-easyprof-ubuntu (Ubuntu RTM)
Fix Released
Critical
Jamie Strandboge

Bug Description

Oct 22 13:32:41 ubuntu-phablet kernel: [ 9393.918517] type=1400 audit(1413999161.373:361): apparmor="DENIED" operation="open" profile="com.ubuntu.developer.rschroll.beru_beru_0.9.8" name="/home/phablet/.local/share/ubuntu-download-manager/com.ubuntu.developer.rschroll.beru/Downloads/History%20of%20King%20Charles%20the%20Second%20of%20England%20-%20Abbot_%20Jacob.epub" pid=19786 comm="qmlscene" requested_mask="r" denied_mask="r" fsuid=32011 ouid=32011

On the one hand, this is not a super critical bug because the ubuntu-download-manager API is not widely used by apps. However, this API is part of the supported frameworks and adding to the policy now rather than as OTA means we can avoid a policy recompile in OTA. The change is simple and the risk is negligible (it would fail to build if there was an error). Plan would be to piggback this on the fix for bug #1383858 so policy recompile only happens once.

summary: - apparmor denies app-specific download dorectpry
+ apparmor denies app-specific download directory
Changed in apparmor-easyprof-ubuntu (Ubuntu):
assignee: nobody → Jamie Strandboge (jdstrand)
importance: Undecided → Critical
status: New → Triaged
tags: added: rtm
Changed in apparmor-easyprof-ubuntu (Ubuntu RTM):
status: New → Triaged
importance: Undecided → Critical
assignee: nobody → Jamie Strandboge (jdstrand)
description: updated
Changed in apparmor-easyprof-ubuntu (Ubuntu):
status: Triaged → In Progress
Changed in apparmor-easyprof-ubuntu (Ubuntu RTM):
status: Triaged → New
tags: added: application-confinement rtm14
removed: rtm
Revision history for this message
Jamie Strandboge (jdstrand) wrote :
description: updated
tags: added: patch
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package apparmor-easyprof-ubuntu - 1.2.38

---------------
apparmor-easyprof-ubuntu (1.2.38) utopic; urgency=medium

  * ubuntu/networking: add rules for app-specific ubuntu-download-manager
    file downloads (LP: #1384349)
 -- Jamie Strandboge <email address hidden> Wed, 22 Oct 2014 14:13:44 -0400

Changed in apparmor-easyprof-ubuntu (Ubuntu):
status: In Progress → Fix Released
Olli Ries (ories)
tags: added: touch-2014-10-30
Changed in apparmor-easyprof-ubuntu (Ubuntu RTM):
status: New → Triaged
status: Triaged → In Progress
Changed in apparmor-easyprof-ubuntu (Ubuntu RTM):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.