bwrap: setting up uid map: Permission denied (with Apparmor)

Bug #1901567 reported by Franck
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
evolution (Ubuntu)
New
Undecided
Unassigned

Bug Description

After upgrading from Ubuntu 20.04 to 20.10, evolution is unable to display my mails.

Launching from a shell, I get this error message: "bwrap: setting up uid map: Permission denied"

Also, double clicking on a mail shows: "Something has gone wrong when displaying the message
A WebKitWebProcess crashed when displaying the message. You can try again by moving to another message and back. If the issue persists, please file a bug report in GNOME Gitlab."

I found this Archlinux thread https://bbs.archlinux.org/viewtopic.php?id=259928 regarding the problem. A workaround is proposed, that consists in exporting WEBKIT_FORCE_SANDBOX=0 before running Evolution. This works.

Notice I have Apparmor enforced. Disableing Apparomor for usr.bin.evolution also works around the problem.

Both are not required, either one is sufficient. I guess a modification in apparmor profile is necessary, but I'm not sure I can figure out out to do that...

ProblemType: Bug
DistroRelease: Ubuntu 20.10
Package: evolution 3.38.1-1
ProcVersionSignature: Ubuntu 5.8.0-25.26-generic 5.8.14
Uname: Linux 5.8.0-25-generic x86_64
NonfreeKernelModules: zfs zunicode zavl icp zcommon znvpair
ApportVersion: 2.20.11-0ubuntu50
Architecture: amd64
CasperMD5CheckResult: skip
CurrentDesktop: GNOME
Date: Mon Oct 26 16:47:39 2020
EcryptfsInUse: Yes
ProcEnviron:
 TERM=xterm-256color
 PATH=(custom, no user)
 XDG_RUNTIME_DIR=<set>
 LANG=fr_FR.UTF-8
 SHELL=/bin/bash
SourcePackage: evolution
UpgradeStatus: Upgraded to groovy on 2020-10-26 (0 days ago)

Revision history for this message
Franck (alci) wrote :
Revision history for this message
Franck (alci) wrote :

Also notice that setting apparmor in complain mode for usr.bin.evolution is not enough to get it working. You have to disable the profile...

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.