[Pkg-kde-extras] Bug#946931: quassel-core: apparmor denials

Thomas Schneider qsx at chaotikum.eu
Sat Jan 11 13:49:07 GMT 2020


Hello,

I stumbled upon the same issue and fixed it locally before searching the
BTS.

I agree on the change '/var/lib/quassel/** rwkl' (although AA convention
seems to be 'rwkl', but that’s just cosmetic), but I would suggest
adding '#include <abstractions/dbus-session-strict>' instead of
specifying the IDs manually.

Said 'abstractions/dbus-session-strict' does not allow access to
'@{PROC}/sys/kernel/random/boot_id', but I didn’t get any audit messages
about that after including the abstraction.  I haven’t looked any
further into it, but maybe it isn’t needed?

Thanks,
qsx



More information about the pkg-kde-extras mailing list