~u-d/apparmor-profiles:thunderbird/launcher

Last commit made on 2017-03-19
Get this branch:
git clone -b thunderbird/launcher https://git.launchpad.net/~u-d/apparmor-profiles
Only Ulrike Uhlig can upload to this branch. If you are Ulrike Uhlig please log in for upload directions.

Branch merges

Branch information

Name:
thunderbird/launcher
Repository:
lp:~u-d/apparmor-profiles

Recent commits

a8b1ce6... by Ulrike Uhlig

After some discussion with intrigeri and cboltz, here is a better proposal.

We want people to open attachments.
This should work for most users, not only GNOME users.
Thunderbird should use *-open but it does not, so we need to allow launching programs from /usr/bin.
Programs that have a profile though should be called using Px, the others using sanitized_helper at least.

05c0f96... by Ulrike Uhlig

Correct permissions. We want these apps to run only if they have a profile.

058cbba... by Ulrike Uhlig

Correct permissions. We want these apps to run using their own profile.

677d1b1... by Ulrike Uhlig

Be a little bit permissive when users try to view attachments.

We can't really forbid users to view attachments, but launching external
applications is not allowed by the AA profile for Thunderbird.
For common applications, this should be allowed though.

All uncommon applications should probably be added through a local
profile.

b0d658f... by Steve Beattie

Merge pulseaudio profile update from intrigeri

Update to handle pulseaudio 10.0 and another location of autospawn
files.

Acked-by: Steve Beattie <email address hidden>

a21cd43... by intrigeri

pulseaudio: support one more path where autospawn.lock can live.

6019980... by intrigeri

pulseaudio: support 10.x (currently in Debian sid) and newer.

392d8ab... by intrigeri

Make more policy compatible with merged-/usr.

Signed-off-by: intrigeri <email address hidden>
Acked-by: John Johansen <email address hidden>

f2105d4... by intrigeri

Make policy compatible with merged-/usr.

017285a... by Seth Arnold

Merge remote-tracking branch 'intrigeri/gst-plugin-scanner_fix'

Fixes "initial startup of Pidgin fails on Tails/Stretch"
Acked-by: Seth Arnold <email address hidden>