Merge lp:~sdeziel/apparmor-profiles/thunderbird-enigmail-1.9 into lp:apparmor-profiles
Proposed by
Simon Déziel
Status: | Merged |
---|---|
Merged at revision: | 164 |
Proposed branch: | lp:~sdeziel/apparmor-profiles/thunderbird-enigmail-1.9 |
Merge into: | lp:apparmor-profiles |
Diff against target: |
42 lines (+13/-0) 1 file modified
ubuntu/16.04/usr.bin.thunderbird (+13/-0) |
To merge this branch: | bzr merge lp:~sdeziel/apparmor-profiles/thunderbird-enigmail-1.9 |
Related bugs: |
Reviewer | Review Type | Date Requested | Status |
---|---|---|---|
AppArmor Developers | Pending | ||
Review via email:
|
Description of the change
This updates the thunderbird//gpg2 profile to support the enigmail version 1.9 that landed in Xenial recently.
While at it, give thunderbird access to /usr/bin/locale that is sometimes needed.
To post a comment you must log in.
Heh, I was going to complain about the /usr/bin/locale Uxr, rule but there's at least those three other Uxr rules right next to it.
I'm surprised about the silenced denials -- those seem wide-ranging and potentially problematic. I might have even thought that thunderbird should have ~/.thunderbird/** rwlk, access.
The static names in /tmp/ are interesting. Those may need more research to see if those need a CVE. (It's possible to use static names in /tmp safely, but the [0-9]* regex there gives me a bad feeling.)
Thanks