[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#911897: AppArmor "complain" for oosplash & soffice



tag 911897 + moreinfo
tag 911897 + unreproducible
thanks

On Thu, Oct 25, 2018 at 05:49:27PM -0400, Anthony DeRobertis wrote:
> Presumably the xauth one will effect a lot of people (as that's the
> value of $XAUTHORITY here, set by KDE/sddm). Then there is a lot of

Really?

$ echo $XAUTHORITY
/home/rene/.Xauthority

(set by sddm logging into GNOME)

Shouldn't - if KDE set it - it not have been found when Vincas did
https://cgit.freedesktop.org/libreoffice/core/commit/?id=c86e4ad53391d17d1eb54845b5999889f7e65061
?

$ echo $XAUTHORITY
/home/rene/.Xauthority

(set by sddm logging into Plasma)

> Oct 25 16:52:11 Zia kernel: audit: type=1400 audit(1540500731.877:200): apparmor="ALLOWED" operation="open" profile="libreoffice-oopslash" name="/tmp/xauth-1000-_0" pid=25385 comm="oosplash" requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000
                                                           ^^^^^^^^^^^^^^^^^^

root@frodo:~# aa-enforce /etc/apparmor.d/usr.lib.libreoffice.program.oosplash 
Setting /etc/apparmor.d/usr.lib.libreoffice.program.oosplash to enforce
mode.
root@frodo:~# aa-enforce /etc/apparmor.d/usr.lib.libreoffice.program.soffice.bin
Setting /etc/apparmor.d/usr.lib.libreoffice.program.soffice.bin to
enforce mode.

Starts fine and does NOT print above (or deny) it.

Regards,

Rene


Reply to: