apparmor messages when opening pdfs attached to mail

Bug #1308488 reported by Heiko Adams
12
This bug affects 2 people
Affects Status Importance Assigned to Milestone
evince (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

When opening a pdf file which is attached to a mail with evolution the following errors are raised

Apr 16 12:09:04 nb-heiko kernel: [14156.403031] type=1400 audit(1397642944.077:117): apparmor="DENIED" operation="mkdir" profile="/usr/bin/evince" name="/run/user/1000/at-spi2-Z05FEX/" pid=23527 comm="evince" requested_mask="c" denied_mask="c" fsuid=1000 ouid=1000
Apr 16 12:22:25 nb-heiko kernel: [14958.101986] type=1400 audit(1397643745.129:118): apparmor="DENIED" operation="mkdir" profile="/usr/bin/evince" name="/run/user/1000/at-spi2-YJUBEX/" pid=23828 comm="evince" requested_mask="c" denied_mask="c" fsuid=1000 ouid=1000
Apr 16 12:26:33 nb-heiko kernel: [15206.548457] type=1400 audit(1397643993.373:119): apparmor="DENIED" operation="mkdir" profile="/usr/bin/evince" name="/run/user/1000/at-spi2-HKSAEX/" pid=24771 comm="evince" requested_mask="c" denied_mask="c" fsuid=1000 ouid=1000
Apr 16 12:26:57 nb-heiko kernel: [15230.855886] type=1400 audit(1397644017.661:120): apparmor="DENIED" operation="open" profile="/usr/bin/evince" name="/dev/tty" pid=24771 comm="evince" requested_mask="rw" denied_mask="rw" fsuid=1000 ouid=0
Apr 16 12:27:06 nb-heiko kernel: [15240.062832] type=1400 audit(1397644026.861:121): apparmor="DENIED" operation="mkdir" profile="/usr/bin/evince" name="/run/user/1000/at-spi2-40AZDX/" pid=24834 comm="evince" requested_mask="c" denied_mask="c" fsuid=1000 ouid=1000
Apr 16 12:37:16 nb-heiko kernel: [15850.176969] type=1400 audit(1397644636.485:122): apparmor="DENIED" operation="mkdir" profile="/usr/bin/evince" name="/run/user/1000/at-spi2-99C7DX/" pid=3982 comm="evince" requested_mask="c" denied_mask="c" fsuid=1000 ouid=1000

I'm using Ubuntu 14.04 with Gnom3 ppas enabled.

ProblemType: Bug
DistroRelease: Ubuntu 14.04
Package: evince-common 3.11.92-0ubuntu1~trusty1 [origin: LP-PPA-gnome3-team-gnome3-staging]
ProcVersionSignature: Ubuntu 3.13.0-24.46-generic 3.13.9
Uname: Linux 3.13.0-24-generic x86_64
ApportVersion: 2.14.1-0ubuntu3
Architecture: amd64
CurrentDesktop: GNOME
Date: Wed Apr 16 13:22:40 2014
EcryptfsInUse: Yes
PackageArchitecture: all
SourcePackage: evince
UpgradeStatus: Upgraded to trusty on 2014-03-21 (25 days ago)

Revision history for this message
Heiko Adams (ha-4) wrote :
affects: ubuntu-gnome → evince (Ubuntu)
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in evince (Ubuntu):
status: New → Confirmed
Changed in evince (Ubuntu):
status: Confirmed → In Progress
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package evince - 3.10.3-0ubuntu15

---------------
evince (3.10.3-0ubuntu15) utopic; urgency=medium

  * debian/apparmor-profile:
    - allow site-wide dconf. Thanks to Lars Masden. (LP: #1355804)
    - allow read/write to files we own in /media (LP: #1096837)
    - allow read/write to files we own in /run/user/1000/at-spi2-*
      (LP: #1308488)
    - allow 'l' to /run/user/*/gvfs-metadata/** (LP: #1344810)
    - allow read/write of @{HOME}/.cache/dconf/user (LP: #1024605)
  * debian/apparmor-profile.abstraction:
    - allow read of /etc/xdg/lubuntu/applications/defaults.list (LP: #1290157,
      LP: #1299239)
    - allow read of /**.[eE][pP][sS][fFiI23] (LP: #1330430)
 -- Jamie Strandboge <email address hidden> Tue, 12 Aug 2014 14:30:43 -0500

Changed in evince (Ubuntu):
status: In Progress → Fix Released
Revision history for this message
Iain Lane (laney) wrote :

Jamie, was it intentional to specify 1000 explicitly here?

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

No it wasn't, sorry. Uploading the proper policy now. Thanks!

Changed in evince (Ubuntu):
status: Fix Released → In Progress
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package evince - 3.10.3-0ubuntu16

---------------
evince (3.10.3-0ubuntu16) utopic; urgency=medium

  * debian/apparmor-profile: fix at-spi2 rules added in last update to use a
    glob rather than hardcoded UID (LP: #1308488)
 -- Jamie Strandboge <email address hidden> Wed, 13 Aug 2014 07:06:29 -0500

Changed in evince (Ubuntu):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.