[maverick] apparmor blocks mmap of files in /tmp (needed for playing multimedia)

Bug #662918 reported by Jamie Strandboge
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
firefox (Ubuntu)
Fix Released
Medium
Jamie Strandboge
Maverick
Fix Released
Medium
Jamie Strandboge
Natty
Fix Released
Medium
Jamie Strandboge

Bug Description

Binary package hint: firefox

Navigating to 'file:///tmp/qrt-test-browser/data/rfbproxy-jaunty.avi' results in the following AppArmor denial, when the profile is enabled:

[ 4053.034987] type=1400 audit(1287432637.563:53): apparmor="DENIED" operation="file_mmap" parent=1 profile="/usr/lib/firefox-3.6.11/firefox-*bin" name="/tmp/orcexec.orc_merge_linear_u8.ZSm7pR" pid=6072 comm="vqueue:src" requested_mask="m" denied_mask="m" fsuid=1000 ouid=1000

This can be fixed with the following:
  owner /tmp/** m,
  owner /var/tmp/** m,

Tags: apparmor
description: updated
summary: - apparmor blocks mmap of files in /tmp (needed for playing multimedia)
+ [maverick] apparmor blocks mmap of files in /tmp (needed for playing
+ multimedia)
Changed in firefox (Ubuntu):
assignee: nobody → Jamie Strandboge (jdstrand)
importance: Undecided → Medium
status: New → Fix Committed
Changed in firefox (Ubuntu Maverick):
assignee: nobody → Jamie Strandboge (jdstrand)
importance: Undecided → Medium
status: New → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package firefox - 3.6.12+build1+nobinonly-0ubuntu0.10.10.1

---------------
firefox (3.6.12+build1+nobinonly-0ubuntu0.10.10.1) maverick-security; urgency=low

  * New upstream release v3.6.12 (FIREFOX_3_6_12_BUILD1)
    - see USN-1011-1

  [ Jamie Strandboge ]
  * AppArmor:
    - allow mmap for temporary files that we own (LP: #662918)
    - add owner read to environ and auxv in @{PROC} as well as
      /etc/lsb-release read and expr ix for the crash reporter
    - update path for Xubuntu default settings (LP: #664093)
 -- Chris Coulson <email address hidden> Wed, 27 Oct 2010 08:31:06 -0400

Changed in firefox (Ubuntu Maverick):
status: Fix Committed → Fix Released
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

This is already fixed in natty. The bug didn't get autoclosed.

Changed in firefox (Ubuntu Natty):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.