Comment 4 for bug 1504049

Revision history for this message
Chad Miller (cmiller) wrote : Re: apparmor rules too tight for chromium

apparmor="ALLOWED" operation="capable" profile="/usr/lib/chromium-browser/chromium-browser" comm="chromium-browse" capability=21 capname="sys_admin"
apparmor="ALLOWED" operation="open" profile="/usr/lib/chromium-browser/chromium-browser" name="/proc/32564/setgroups" comm="chromium-browse" requested_mask="w" denied_mask="w" fsuid=1000 ouid=1000
apparmor="ALLOWED" operation="capable" profile="/usr/lib/chromium-browser/chromium-browser" comm="chromium-browse" capability=21 capname="sys_admin"
apparmor="ALLOWED" operation="open" profile="/usr/lib/chromium-browser/chromium-browser" name="/proc/32564/uid_map" comm="chromium-browse" requested_mask="w" denied_mask="w" fsuid=1000 ouid=1000
apparmor="ALLOWED" operation="open" profile="/usr/lib/chromium-browser/chromium-browser" name="/proc/32564/gid_map" comm="chromium-browse" requested_mask="w" denied_mask="w" fsuid=1000 ouid=1000
apparmor="ALLOWED" operation="open" profile="/usr/lib/chromium-browser/chromium-browser" name="/proc/32564/setgroups" comm="chromium-browse" requested_mask="w" denied_mask="w" fsuid=1000 ouid=1000
apparmor="ALLOWED" operation="capable" profile="/usr/lib/chromium-browser/chromium-browser" comm="chromium-browse" capability=21 capname="sys_admin"
apparmor="ALLOWED" operation="open" profile="/usr/lib/chromium-browser/chromium-browser" name="/proc/32564/gid_map" comm="chromium-browse" requested_mask="w" denied_mask="w" fsuid=1000 ouid=1000
apparmor="ALLOWED" operation="open" profile="/usr/lib/chromium-browser/chromium-browser" name="/proc/32564/uid_map" comm="chromium-browse" requested_mask="w" denied_mask="w" fsuid=1000 ouid=1000
apparmor="ALLOWED" operation="open" profile="/usr/lib/chromium-browser/chromium-browser//xdgsettings" name="/etc/xdg/xdg-xubuntu/xfce4/helpers.rc" comm="grep" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
apparmor="ALLOWED" operation="open" profile="/usr/lib/chromium-browser/chromium-browser//xdgsettings" name="/etc/xdg/xdg-xubuntu/xfce4/helpers.rc" comm="grep" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
apparmor="ALLOWED" operation="open" profile="/usr/lib/chromium-browser/chromium-browser" name="/proc/32748/stat" comm="Chrome_FileThre" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
apparmor="ALLOWED" operation="capable" profile="/usr/lib/chromium-browser/chromium-browser" comm="chromium-browse" capability=19 capname="sys_ptrace"
apparmor="ALLOWED" operation="open" profile="/usr/lib/chromium-browser/chromium-browser//xdgsettings" name="/etc/xdg/xdg-xubuntu/xfce4/helpers.rc" comm="grep" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
apparmor="ALLOWED" operation="open" profile="/usr/lib/chromium-browser/chromium-browser//xdgsettings" name="/etc/xdg/xdg-xubuntu/xfce4/helpers.rc" comm="grep" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
apparmor="ALLOWED" operation="open" profile="/usr/lib/chromium-browser/chromium-browser" name="/proc/32766/stat" comm="BrowserBlocking" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
apparmor="ALLOWED" operation="capable" profile="/usr/lib/chromium-browser/chromium-browser" comm="chromium-browse" capability=19 capname="sys_ptrace"
apparmor="ALLOWED" operation="capable" profile="/usr/lib/chromium-browser/chromium-browser" comm="chromium-browse" capability=19 capname="sys_ptrace"
apparmor="ALLOWED" operation="capable" profile="/usr/lib/chromium-browser/chromium-browser" comm="Chrome_IOThread" capability=19 capname="sys_ptrace"