Unprivileged user namespace restrictions break various third-party applications

Bug #2036698 reported by Alex Murray
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
apparmor (Ubuntu)
Fix Released
High
Alex Murray

Bug Description

Similar to https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2035315 the proposed unprivileged user namespace restrictions feature of apparmor in mantic breaks various third-party applications that use unprivileged userns for sandboxing themselves.

These include:

- Brave
- Microsoft Edge
- Opera
- Visual Studio Code
- Vivaldi

apparmor in mantic should ship skeleton profiles for each of these to ensure they work as expected if a user has them installed.

Alex Murray (alexmurray)
Changed in apparmor (Ubuntu):
assignee: nobody → Alex Murray (alexmurray)
importance: Undecided → High
status: New → Confirmed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package apparmor - 4.0.0~alpha2-0ubuntu5

---------------
apparmor (4.0.0~alpha2-0ubuntu5) mantic; urgency=medium

  * Add additional AppArmor profiles to support third-party applications
    that use unprivileged user namespace restrictions (LP: #2036698)
    - Refreshed d/p/u/userns-unconfined-profiles.patch to add additional
      profiles and added to debian/apparmor.install
       - usr.share.code.bin.code
       - opt.microsoft.msedge.msedge
       - usr.lib.multiarch.opera.opera
       - opt.brave.com.brave.brave
       - opt.vivaldi.vivaldi-bin
  * Clarify comment in sysctl.d conf file that this feature is not
    enabled by default but can be overridden by the user if desired.

 -- Alex Murray <email address hidden> Fri, 22 Sep 2023 16:50:22 +0930

Changed in apparmor (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.