[pkg-apparmor] Bug#920833: apparmor: AppArmor denies access to mime-specifc files for various GUI applications

Vincas Dargis vindrg at gmail.com
Mon Feb 11 18:47:07 GMT 2019


Something strange is going on. Check this output:

```
$ /usr/sbin/apparmor_parser -Q -p /etc/apparmor.d/usr.bin.thunderbird  | fgrep user_share
@{user_share_dirs} = @{HOME}/.local/{,share/@{flatpak_exports_root}}/share
   owner @{user_share_dirs}/applications/{**,} r,
   owner @{user_share_dirs}/icons/{**,}        r,
   {**,}         r,
   owner @{user_share_dirs}/applications/{**,} r,
   owner @{user_share_dirs}/icons/{**,}        r,
   owner @{user_share_dirs}/mime/{**,}         r,
   owner @{user_share_dirs}/applications/{**,} r,
   owner @{user_share_dirs}/icons/{**,}        r,
   owner @{user_share_dirs}/mime/{**,}         r,
   owner @{user_share_dirs}/applications/{**,} r,
   owner @{user_share_dirs}/icons/{**,}        r,
   owner @{user_share_dirs}/mime/{**,}         r,
   owner @{user_share_dirs}/applications/{**,} r,
   owner @{user_share_dirs}/icons/{**,}        r,
   owner @{user_share_dirs}/mime/{**,}         r,
```

So, Thunderbird should have access to mime-stuff in home via (indirectly) included 
`abstractions/freedesktop.org`.

Could it be that's something is wrong with "@{user_share_dirs} = 
@{HOME}/.local/{,share/@{flatpak_exports_root}}/share" rule?



More information about the pkg-apparmor-team mailing list