Denial when running binaries in terminal app
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| | apparmor-easyprof-ubuntu (Ubuntu) |
Undecided
|
Jamie Strandboge | ||
| | dbus-property-service (Ubuntu) |
Undecided
|
Jamie Strandboge | ||
Bug Description
Open terminal on device
Make a typical bash shell script in your home directory
Try and run it
Get this:-
bash: foo.sh: Permission denied.
Apparmor denial in dmesg:-
[26531.600286] type=1400 audit(143404039
| Jamie Strandboge (jdstrand) wrote : | #1 |
| Changed in apparmor-easyprof-ubuntu (Ubuntu): | |
| status: | New → Triaged |
| assignee: | nobody → Jamie Strandboge (jdstrand) |
| Changed in dbus-property-service (Ubuntu): | |
| status: | New → Triaged |
| assignee: | nobody → Jamie Strandboge (jdstrand) |
| Nicholas Skaggs (nskaggs) wrote : | #2 |
The apparmor click rules have moved from under autopilot-touch to dbus-property-
| Jamie Strandboge (jdstrand) wrote : | #3 |
dbus-property-
# Allow writes to various (application-
owner @{HOME}
owner @{HOME}
owner @{HOME}
owner @{HOME}
owner @{HOME}
owner @{HOMEDIRS}
owner @{HOME}
owner @{HOME}
balloons is verifying if this is safe to do at this time.
| Nicholas Skaggs (nskaggs) wrote : | #4 |
None of the coreapps are using this; tests work fine without it. We should be safe to remove.
| Changed in apparmor-easyprof-ubuntu (Ubuntu): | |
| status: | Triaged → In Progress |
| Changed in dbus-property-service (Ubuntu): | |
| status: | Triaged → In Progress |
| Launchpad Janitor (janitor) wrote : | #5 |
This bug was fixed in the package dbus-property-
---------------
dbus-property-
* click.rules: remove no longer used and overly complicated fakeenv rules
(LP: #1464341)
-- Jamie Strandboge <email address hidden> Fri, 12 Jun 2015 09:54:36 -0500
| Changed in dbus-property-service (Ubuntu): | |
| status: | In Progress → Fix Released |
| Launchpad Janitor (janitor) wrote : | #6 |
This bug was fixed in the package apparmor-
---------------
apparmor-
* ubuntu/unconfined: remove autopilot specific rules and use simpler
'/** pix,' rule. This is possible because dbus-property-
ships 'fakeenv' rules. This is only backportable on earlier releases if
dbus-
(LP: #1464341)
-- Jamie Strandboge <email address hidden> Fri, 12 Jun 2015 09:59:18 -0500
| Changed in apparmor-easyprof-ubuntu (Ubuntu): | |
| status: | In Progress → Fix Released |


There are autopilot rules in the unconfined template that will make the fix more complicated than I would like. I've talked to balloons and he is looking into the possibility of removing these.