browser-support needs to be an implicit interface, not implicit classic

Bug #1667480 reported by Pat McGowan
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
snapd (Ubuntu)
Fix Released
Medium
Jamie Strandboge

Bug Description

While running any browser/webapp on the arm64 dragonboard, they would not run under strict confinement.

Per jdstrand we need browser-support as an implicit interface, not just implicit classic.

Other denials to udev and attr/current

Feb 23 21:07:47 patsdragon audit[4036]: AVC apparmor="DENIED" operation="open" profile="snap.testdemo.testdemo" name="/run/udev/data/+platform:1a00000.qcom,mdss_mdp" pid=4036 comm="webapp-containe" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
Feb 23 21:07:47 patsdragon kernel: audit: type=1400 audit(1487884067.942:3248): apparmor="DENIED" operation="open" profile="snap.testdemo.testdemo" name="/run/udev/data/+platform:1a00000.qcom,mdss_mdp" pid=4036 comm="webapp-containe" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0

Feb 23 21:07:48 patsdragon audit[4036]: AVC apparmor="DENIED" operation="open" profile="snap.testdemo.testdemo" name="/proc/4036/attr/current" pid=4036 comm="webapp-containe" requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000
Feb 23 21:07:48 patsdragon kernel: audit: type=1400 audit(1487884068.074:3251): apparmor="DENIED" operation="open" profile="snap.testdemo.testdemo" name="/proc/4036/attr/current" pid=4036 comm="webapp-containe" requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000

description: updated
description: updated
description: updated
tags: added: snapd-interface
Changed in snapd (Ubuntu):
status: New → Triaged
importance: Undecided → Medium
assignee: nobody → Jamie Strandboge (jdstrand)
Changed in snapd (Ubuntu):
status: Triaged → In Progress
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

This is committed to master and will be fixed in snapd 2.23.

Changed in snapd (Ubuntu):
status: In Progress → Fix Committed
Changed in snapd (Ubuntu):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.