Bug#908471: atril: include AppArmor profile in the package
Package: atril
Version: 1.20.2-1
Severity: normal
Hi,
would it be possible to include an AppArmor profile in the atril
package? PDF readers are quite exposed to bad stuff coming from the
Internet, and now that AppArmor is enabled by defaultin Debian, it would make
sense to include one.
I guess reusing Evince profiles could be a start, they're located at
https://sources.debian.org/src/evince/3.30.0-2/debian/apparmor-profile.abstraction/
and
https://sources.debian.org/src/evince/3.30.0-2/debian/apparmor-profile/
I'm currently trying to craft a profile for Tumbler thumbnailers, and
since we switched to Atril for Xfce in Debian, it would really help me.
Regards,
--
Yves-Alexis
-- System Information:
Debian Release: buster/sid
APT prefers unstable-debug
APT policy: (500, 'unstable-debug'), (500, 'unstable'), (450, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386
Kernel: Linux 4.18.0-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=fr_FR.utf8, LC_CTYPE=fr_FR.utf8 (charmap=UTF-8), LANGUAGE=fr_FR.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages atril depends on:
ii atril-common 1.20.2-1
ii dconf-gsettings-backend [gsettings-backend] 0.30.0-1
ii libatk1.0-0 2.30.0-1
ii libatrildocument3 1.20.2-1
ii libatrilview3 1.20.2-1
ii libc6 2.27-6
ii libcairo-gobject2 1.15.12-1
ii libcairo2 1.15.12-1
ii libcaja-extension1 1.20.2-5
ii libgail-3-0 3.24.0-1
ii libgdk-pixbuf2.0-0 2.38.0+dfsg-4
ii libglib2.0-0 2.58.0-3
ii libgtk-3-0 3.24.0-1
ii libice6 2:1.0.9-2
ii libjavascriptcoregtk-4.0-18 2.20.5-1
ii libpango-1.0-0 1.42.4-3
ii libpangocairo-1.0-0 1.42.4-3
ii libsecret-1-0 0.18.6-2
ii libsm6 2:1.2.2-1+b3
ii libsoup2.4-1 2.64.0-2
ii libwebkit2gtk-4.0-37 2.20.5-1
ii libx11-6 2:1.6.6-1
ii libxml2 2.9.4+dfsg1-7+b1
ii shared-mime-info 1.9-2
ii zlib1g 1:1.2.11.dfsg-1
Versions of packages atril recommends:
ii dbus-user-session [default-dbus-session-bus] 1.12.10-1
ii dbus-x11 [dbus-session-bus] 1.12.10-1
ii gvfs 1.36.2-1
Versions of packages atril suggests:
pn caja <none>
ii poppler-data 0.4.9-2
ii unrar 1:5.5.8-1
-- no debconf information
Reply to: