Untrusted Helpers using Trusted Prompt Sessions should be socket activated

Bug #1462492 reported by Ted Gould
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
apparmor-easyprof-ubuntu (Ubuntu)
Confirmed
Undecided
Unassigned
ubuntu-app-launch (Ubuntu)
Confirmed
Wishlist
Unassigned

Bug Description

Passing the Mir FD over DBus isn't ideal because it's a generic bus that is readable by more than the app itself. Instead there should be a direct socket connection made to pass the Mir Trusted Prompt Session FD that is unique to the untrusted helper that is being started.

Revision history for this message
Ted Gould (ted) wrote :

Schedule for fixing when migrating to systemd.

Changed in ubuntu-app-launch (Ubuntu):
importance: Undecided → Wishlist
status: New → Confirmed
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

When this bug is fixed we should adjust the apparmor rules that were added in bug #1462494 accordingly.

tags: added: application-confinement
Changed in apparmor-easyprof-ubuntu (Ubuntu):
status: New → Confirmed
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.