home bbs files messages ]

Forums before death by AOL, social media and spammers... "We can't have nice things"

   linux.debian.bugs.dist      Ohh some weird Debian bug report thing      28,835 messages   

[   << oldest   |   < older   |   list   |   newer >   |   newest >>   ]

   Message 28,682 of 28,835   
   intrigeri to All   
   Bug#1127710: thunderbird: apparmor profi   
   23 Feb 26 18:50:01   
   
   From: intrigeri@debian.org   
      
   Hi Simon,   
      
   Simon McVittie (2026-02-22):   
   > On Mon, 16 Feb 2026 at 12:09:18 +0100, intrigeri wrote:   
   >>my next step, as announced on that MR a while ago, is to remove   
   >>the AppArmor profile from the Debian package in sid: without   
   >>a collaborative effort upstream, there's no good way for me to keep   
   >>maintaining it for Debian, with an amount of effort that I can   
   >>justify.   
   >   
   > I think that would be wise: this profile seems to be causing more    
   > problems than it solves. I think the following bugs could be closed by    
   > its removal: […]   
      
   Thank you, I've passed on this info via the MR:   
   https://salsa.debian.org/mozilla-team/thunderbird/-/merge_requests/11   
      
   >>Given the profile is so widely open   
   >   
   > In particular, it has   
   >   
   >    #include    
   >   
   > which is a complete sandbox escape: lots of session services can be    
   > asked to execute arbitrary code via D-Bus. It also has   
   >   
   >    owner @{HOME}/.{cache,config}/dconf/user rw,   
   >   
   > which is a complete sandbox escape via any dconf/GSettings option that    
   > can be configured to run arbitrary commands, for example GNOME's    
   > desktop-wide custom keyboard shortcuts.   
      
   Thanks for this input!   
      
   Cheers,   
   --    
   intrigeri   
      
   --- SoupGate-Win32 v1.05   
    * Origin: you cannot sedate... all the things you hate (1:229/2)   

[   << oldest   |   < older   |   list   |   newer >   |   newest >>   ]


(c) 1994,  bbs@darkrealms.ca