gnome thumbnailers should have an apparmor profile
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| | gnome-desktop3 (Ubuntu) |
Wishlist
|
Unassigned | ||
| | gnome-utils (Ubuntu) |
Wishlist
|
Unassigned | ||
| | totem (Ubuntu) |
Wishlist
|
Unassigned | ||
Bug Description
Binary package hint: gnome-control-
Nautilus normally uses gnome-thumbnail
$ gconftool-2 -g /desktop/
true
$ gconftool-2 -g /desktop/
gnome-thumbnail
If a flaw is discovered in a font library or Gnome and a user navigates to a directory that has a malicious font file, gnome-thumbnail
The same can be said for other thumbnailers. Nautilus also uses totem-video-
| Jamie Strandboge (jdstrand) wrote : | #1 |
| Changed in gnome-control-center (Ubuntu): | |
| assignee: | nobody → Jamie Strandboge (jdstrand) |
| importance: | Undecided → Wishlist |
| status: | New → In Progress |
| tags: | added: apparmor |
| summary: |
- should have apparmor profile for gnome-thumbnail-font + gnome thumbnailers should have an apparmor profile |
| Changed in totem (Ubuntu): | |
| importance: | Undecided → Wishlist |
| status: | New → Triaged |
| description: | updated |
| Changed in gnome-desktop (Ubuntu): | |
| importance: | Undecided → Wishlist |
| status: | New → Triaged |
| description: | updated |
| Jamie Strandboge (jdstrand) wrote : | #2 |
Attached is a preliminary totem abstraction and totem-previewers profile for totem-video-
$ sudo apparmor_parser -r /etc/apparmor.
It requires more testing before inclusion in Ubuntu, but was tested with ogg audio and flash video thumbnails via nautilus.
| Changed in totem (Ubuntu): | |
| assignee: | nobody → Jamie Strandboge (jdstrand) |
| status: | Triaged → In Progress |
| Jamie Strandboge (jdstrand) wrote : | #3 |
| Jamie Strandboge (jdstrand) wrote : | #4 |
| Jamie Strandboge (jdstrand) wrote : | #5 |
| Changed in gnome-desktop (Ubuntu): | |
| assignee: | nobody → Jamie Strandboge (jdstrand) |
| dino99 (9d9) wrote : | #6 |
hi Jamie,
i'm ready to test but cant see the attached file into post #1
| Jamie Strandboge (jdstrand) wrote : | #7 |
@dino99: I updated the usr.bin.
| affects: | gnome-control-center (Ubuntu) → gnome-utils (Ubuntu) |
| affects: | gnome-desktop (Ubuntu) → gnome-desktop3 (Ubuntu) |
| Changed in gnome-utils (Ubuntu): | |
| status: | In Progress → Triaged |
| Changed in totem (Ubuntu): | |
| status: | In Progress → Triaged |
| Changed in gnome-desktop3 (Ubuntu): | |
| assignee: | Jamie Strandboge (jdstrand) → nobody |
| Changed in gnome-utils (Ubuntu): | |
| assignee: | Jamie Strandboge (jdstrand) → nobody |
| Changed in totem (Ubuntu): | |
| assignee: | Jamie Strandboge (jdstrand) → nobody |
| tags: | added: raring saucy |
| Simon Déziel (sdeziel) wrote : | #8 |
@Jamie, I've been running with your profile (from comment #5) on Precise since a long time and it works really well. It would be nice to have it shipped enabled by default in future releases. Thanks


Attached is a preliminary profile to achieve this. It was tested with various font files based on http:// gfontview. sourceforge. net/features. html as well as with nautilus. It requires more testing before inclusion in Ubuntu. To try it out, copy it to /etc/apparmor. d/usr.bin. gnome-thumbnail -font and then perform: d/usr.bin. gnome-thumbnail -font
$ sudo apparmor_parser -r /etc/apparmor.
Feedback is welcome.