Chromium not working in guest session (need more AppArmor rules)
Bug #1504049 reported by
Hadmut Danisch
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Light Display Manager |
Fix Released
|
Medium
|
Unassigned | ||
1.10 |
Fix Committed
|
Medium
|
Unassigned | ||
1.14 |
Fix Released
|
Medium
|
Unassigned | ||
1.16 |
Fix Released
|
Medium
|
Unassigned | ||
lightdm (Ubuntu) |
Fix Released
|
Medium
|
Robert Ancell | ||
Trusty |
Fix Released
|
Medium
|
Robert Ancell | ||
Vivid |
Fix Released
|
Medium
|
Robert Ancell | ||
Wily |
Fix Released
|
Medium
|
Robert Ancell |
Bug Description
[Impact]
Unable to run Chromium from guest session.
[Test Case]
1. Start Ubuntu
2. From greeter select guest session
3. Load Chromium
Expected result:
Chromium runs.
Observed result:
Chromium does not run.
[Regression Potential]
Low. The change is a few additional apparmor rules. There is a low risk that the new rules might allow a guest program to access a flaw.
Related branches
lp://qastaging/~cmiller/lightdm/guest-session-chromium-sandbox-cgroups
- Robert Ancell: Approve
-
Diff: 26 lines (+6/-0)2 files modifieddata/apparmor/abstractions/lightdm_chromium-browser (+4/-0)
debian/changelog (+2/-0)
Changed in chromium-browser (Ubuntu): | |
status: | Incomplete → Confirmed |
no longer affects: | lightdm/trunk |
Changed in lightdm: | |
importance: | Undecided → Medium |
status: | New → Fix Committed |
milestone: | none → 1.17.0 |
Changed in lightdm (Ubuntu Trusty): | |
importance: | Undecided → Medium |
status: | New → Triaged |
Changed in lightdm (Ubuntu Vivid): | |
importance: | Undecided → Medium |
status: | New → Triaged |
Changed in lightdm (Ubuntu Wily): | |
importance: | Undecided → Medium |
status: | New → Triaged |
description: | updated |
summary: |
- apparmor rules too tight for chromium + Chromium not working in guest session (need more AppArmor rules) |
Changed in lightdm: | |
status: | Fix Committed → Fix Released |
Changed in lightdm (Ubuntu Vivid): | |
assignee: | nobody → Robert Ancell (robert-ancell) |
status: | Triaged → In Progress |
Changed in chromium-browser (Ubuntu): | |
status: | Confirmed → Invalid |
Changed in chromium-browser (Ubuntu Wily): | |
status: | Confirmed → Invalid |
no longer affects: | chromium-browser (Ubuntu) |
no longer affects: | chromium-browser (Ubuntu Trusty) |
no longer affects: | chromium-browser (Ubuntu Vivid) |
no longer affects: | chromium-browser (Ubuntu Wily) |
To post a comment you must log in.
BTW: the logs say "ALLOWED", but still are annoying.