Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #189427 > unrolled thread

Thunderbird no longer opens links

Started bysolitone <solitone@mail.com>
First post2017-11-30 06:50 +0100
Last post2017-11-30 22:40 +0100
Articles 19 — 9 participants

Back to article view | Back to linux.debian.user


Contents

  Thunderbird no longer opens links solitone <solitone@mail.com> - 2017-11-30 06:50 +0100
    Re: Thunderbird no longer opens links Cindy-Sue Causey <butterflybytes@gmail.com> - 2017-11-30 07:10 +0100
    Re: Thunderbird no longer opens links "Alexander V. Makartsev" <avbetev@gmail.com> - 2017-11-30 08:50 +0100
      Re: Thunderbird no longer opens links solitone <solitone@mail.com> - 2017-11-30 12:00 +0100
        Re: Thunderbird no longer opens links Brian <ad44@cityscape.co.uk> - 2017-11-30 15:20 +0100
        Re: Thunderbird no longer opens links Jonathan Dowland <jmtd@debian.org> - 2017-12-01 15:30 +0100
          Re: Thunderbird no longer opens links solitone <solitone@mail.com> - 2017-12-01 15:40 +0100
            Re: Thunderbird no longer opens links <tomas@tuxteam.de> - 2017-12-01 15:50 +0100
              Re: Thunderbird no longer opens links Michael Biebl <biebl@debian.org> - 2017-12-01 18:30 +0100
                Re: Thunderbird no longer opens links "Alexander V. Makartsev" <avbetev@gmail.com> - 2017-12-01 23:10 +0100
                  Re: Thunderbird no longer opens links solitone <solitone@mail.com> - 2017-12-02 10:20 +0100
                    Re: Thunderbird no longer opens links "Alexander V. Makartsev" <avbetev@gmail.com> - 2017-12-02 11:50 +0100
                      Re: Thunderbird no longer opens links Ben Caradoc-Davies <ben@transient.nz> - 2017-12-02 23:00 +0100
                        Re: Thunderbird no longer opens links "Alexander V. Makartsev" <avbetev@gmail.com> - 2017-12-03 00:10 +0100
                          Re: Re: Thunderbird no longer opens links Vincas Dargis <vindrg@gmail.com> - 2017-12-03 10:10 +0100
                            Re: Thunderbird no longer opens links "Alexander V. Makartsev" <avbetev@gmail.com> - 2017-12-04 19:50 +0100
                              Re: Re: Thunderbird no longer opens links Vincas Dargis <vindrg@gmail.com> - 2017-12-05 17:50 +0100
            Re: Thunderbird no longer opens links Jonathan Dowland <jmtd@debian.org> - 2017-12-04 12:50 +0100
    Re: Thunderbird no longer opens links Ben Caradoc-Davies <ben@transient.nz> - 2017-11-30 22:40 +0100

#189427 — Thunderbird no longer opens links

Fromsolitone <solitone@mail.com>
Date2017-11-30 06:50 +0100
SubjectThunderbird no longer opens links
Message-ID<uRpTs-3aS-3@gated-at.bofh.it>
Hi, since a few days, hyperlink no longer works in my Thunderbird. When 
I click a hyperlink in a message, Chromium (my system's default web 
browser) should open and display the link. This has been working fine 
for long, but now it no longer happens.

I checked everything that's pointed out in a Mozilla Support web page 
[1], but didn't find what's causing the issue:

- I checked that the operating system's default browser is specified. 
 From KDE Plasma System Settings -> Applications -> Web Browser, I see 
that chromium is specified.

- I checked that no application is specified for the HTTP / HTTPS 
content type. In Thunderbird -> Edit -> Preferences -> Attachments -> 
Incoming I had two actions, one for HTTP the other for HTTPS, both 
pointing chromium. I tried and deleted both. When I clicked on a 
hyperlink in a message, a popup asked for an applications to open it, I 
chose chromium flagging the remember checkbox, and the action for HTTP 
content type was recreated, but the link did not open.

- I checked for an incorrect preference like 
network.protocol-handler.external-default or any other preference 
beginning with network.protocol-handler.warn-external, but I have no 
such preference.

- I checked for interference from an extension, running Thunderbird in 
Thunderbird Safe Mode, but the problem persisted.

The only other suspect I have is apparmor, which was installed in a 
recent security update. But can this be the reason?

Thanks & Regards!

[1] https://support.mozilla.org/en-US/kb/Hyperlinks-in-Messages-Not-Working

[toc] | [next] | [standalone]


#189428

FromCindy-Sue Causey <butterflybytes@gmail.com>
Date2017-11-30 07:10 +0100
Message-ID<uRqcN-3xm-5@gated-at.bofh.it>
In reply to#189427
On 11/30/17, solitone <solitone@mail.com> wrote:
> Hi, since a few days, hyperlink no longer works in my Thunderbird. When
> I click a hyperlink in a message, Chromium (my system's default web
> browser) should open and display the link. This has been working fine
> for long, but now it no longer happens.
>
> I checked everything that's pointed out in a Mozilla Support web page
> [1], but didn't find what's causing the issue:
>
> - I checked that the operating system's default browser is specified.
>  From KDE Plasma System Settings -> Applications -> Web Browser, I see
> that chromium is specified.
>
> - I checked that no application is specified for the HTTP / HTTPS
> content type. In Thunderbird -> Edit -> Preferences -> Attachments ->
> Incoming I had two actions, one for HTTP the other for HTTPS, both
> pointing chromium. I tried and deleted both. When I clicked on a
> hyperlink in a message, a popup asked for an applications to open it, I
> chose chromium flagging the remember checkbox, and the action for HTTP
> content type was recreated, but the link did not open.
>
> - I checked for an incorrect preference like
> network.protocol-handler.external-default or any other preference
> beginning with network.protocol-handler.warn-external, but I have no
> such preference.
>
> - I checked for interference from an extension, running Thunderbird in
> Thunderbird Safe Mode, but the problem persisted.
>
> The only other suspect I have is apparmor, which was installed in a
> recent security update. But can this be the reason?
>
> Thanks & Regards!
>
> [1] https://support.mozilla.org/en-US/kb/Hyperlinks-in-Messages-Not-Working


Have you ever tried running something like this from within a
terminal? It's been my favorite thing to try when something's not
running properly.

If you go that route, hopefully it might spew out one or more warning
or error messages that might give you an idea of what's going on..

Cindy :)
-- 
Cindy-Sue Causey
Talking Rock, Pickens County, Georgia, USA

* runs with duct tape *

[toc] | [prev] | [next] | [standalone]


#189429

From"Alexander V. Makartsev" <avbetev@gmail.com>
Date2017-11-30 08:50 +0100
Message-ID<uRrLA-4lz-3@gated-at.bofh.it>
In reply to#189427

[Multipart message — attachments visible in raw view] — view raw

On 30.11.2017 10:45, solitone wrote:
> Hi, since a few days, hyperlink no longer works in my Thunderbird.
> When I click a hyperlink in a message, Chromium (my system's default
> web browser) should open and display the link. This has been working
> fine for long, but now it no longer happens.
>
I had this problem too, and yes AppArmor is the reason.

You can disable AppArmor for thunderbird by typing:
    $ sudo aa-disable /usr/bin/thunderbird

Or create an AppArmor profile for it.


-- 
With kindest regards, Alexander.

⢀⣴⠾⠻⢶⣦⠀ 
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
⠈⠳⣄⠀⠀⠀⠀ 

[toc] | [prev] | [next] | [standalone]


#189431

Fromsolitone <solitone@mail.com>
Date2017-11-30 12:00 +0100
Message-ID<uRuJs-69h-5@gated-at.bofh.it>
In reply to#189429
On 30/11/17 08:48, Alexander V. Makartsev wrote:
> I had this problem too, and yes AppArmor is the reason.

Yes, I had a look at logs and I can confirm that apparmor is indeed the 
culprit:

-----------------------------------------------------------------------
~$ sudo journalctl -kaf --no-hostname | grep thunderbird
Nov 30 11:15:03 kernel: audit: type=1400 audit(1512036903.046:65): 
apparmor="DENIED" operation="file_mmap" 
profile="thunderbird//lsb_release" name="/usr/bin/python3.5" pid=27432 
comm="lsb_release" requested_mask="m" denied_mask="m" fsuid=1000 ouid=0
Nov 30 11:15:15 kernel: audit: type=1400 audit(1512036915.636:66): 
apparmor="DENIED" operation="exec" profile="thunderbird" 
name="/usr/bin/chromium" pid=27508 comm="thunderbird" requested_mask="x" 
denied_mask="x" fsuid=1000 ouid=0
-----------------------------------------------------------------------

It's a known bug, which is marked as solved since it has been solved in 
the latest version of thunderbird (1:52.4.0-2~exp1):
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=855346#135

My question is--when will be this version come to stable? At the moment 
we have 1:52.4.0-1~deb9u1:

-----------------------------------------------------------------------
~$ apt-cache policy thunderbird
thunderbird:
   Installed: 1:52.4.0-1~deb9u1
   Candidate: 1:52.4.0-1~deb9u1
-----------------------------------------------------------------------

[toc] | [prev] | [next] | [standalone]


#189432

FromBrian <ad44@cityscape.co.uk>
Date2017-11-30 15:20 +0100
Message-ID<uRxR0-8ei-7@gated-at.bofh.it>
In reply to#189431
On Thu 30 Nov 2017 at 11:57:41 +0100, solitone wrote:

> On 30/11/17 08:48, Alexander V. Makartsev wrote:
> > I had this problem too, and yes AppArmor is the reason.
> 
> Yes, I had a look at logs and I can confirm that apparmor is indeed the
> culprit:
> 
> -----------------------------------------------------------------------
> ~$ sudo journalctl -kaf --no-hostname | grep thunderbird
> Nov 30 11:15:03 kernel: audit: type=1400 audit(1512036903.046:65):
> apparmor="DENIED" operation="file_mmap" profile="thunderbird//lsb_release"
> name="/usr/bin/python3.5" pid=27432 comm="lsb_release" requested_mask="m"
> denied_mask="m" fsuid=1000 ouid=0
> Nov 30 11:15:15 kernel: audit: type=1400 audit(1512036915.636:66):
> apparmor="DENIED" operation="exec" profile="thunderbird"
> name="/usr/bin/chromium" pid=27508 comm="thunderbird" requested_mask="x"
> denied_mask="x" fsuid=1000 ouid=0
> -----------------------------------------------------------------------
> 
> It's a known bug, which is marked as solved since it has been solved in the
> latest version of thunderbird (1:52.4.0-2~exp1):
> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=855346#135
> 
> My question is--when will be this version come to stable? At the moment we
> have 1:52.4.0-1~deb9u1:

https://lists.debian.org/debian-devel/2017/08/msg00090.html

 > tl;dr: I hereby propose we enable AppArmor by default in testing/sid,
 > and decide one year later if we want to keep it this way in the
 > Buster release.

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#189442

FromJonathan Dowland <jmtd@debian.org>
Date2017-12-01 15:30 +0100
Message-ID<uRUue-5vN-11@gated-at.bofh.it>
In reply to#189431
On Thu, Nov 30, 2017 at 11:57:41AM +0100, solitone wrote:
>It's a known bug, which is marked as solved since it has been solved 
>in the latest version of thunderbird (1:52.4.0-2~exp1):
>https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=855346#135
>
>My question is--when will be this version come to stable?

That version will never be in current-stable. It will be in a stable
release once the current testing release (buster) becomes stable, which
might not be for a while. However, AppArmor is not enabled in current
stable, so you should only hit this bug if you are using stable's
thunderbird on a testing/sid system, or manually enabling AppArmor
yourself on stable.

-- 

⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Jonathan Dowland
⢿⡄⠘⠷⠚⠋⠀ https://jmtd.net
⠈⠳⣄⠀⠀⠀⠀ Please do not CC me, I am subscribed to the list.

[toc] | [prev] | [next] | [standalone]


#189444

Fromsolitone <solitone@mail.com>
Date2017-12-01 15:40 +0100
Message-ID<uRUDU-5yP-7@gated-at.bofh.it>
In reply to#189442
On 01/12/17 15:22, Jonathan Dowland wrote:
> AppArmor is not enabled in current
> stable, so you should only hit this bug if you are using stable's
> thunderbird on a testing/sid system, or manually enabling AppArmor
> yourself on stable.

I have stretch, and didn't requested it manually, but was installed with 
the latest kernel update from stretch backports. I think it was 
installed because of that backported kernel version:

Start-Date: 2017-11-26  06:57:11
Commandline: apt upgrade
Requested-By: solitone (1000)
Install: libapparmor-perl:amd64 (2.11.0-3, automatic), apparmor:amd64 (2
.11.0-3, automatic)
Upgrade: linux-image-4.13.0-0.bpo.1-amd64:amd64 (4.13.4-2~bpo9+1, 4.13.1
3-1~bpo9+1)
End-Date: 2017-11-26  06:57:30

Cheers!

[toc] | [prev] | [next] | [standalone]


#189445

From<tomas@tuxteam.de>
Date2017-12-01 15:50 +0100
Message-ID<uRUNA-5C6-5@gated-at.bofh.it>
In reply to#189444
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Fri, Dec 01, 2017 at 03:30:50PM +0100, solitone wrote:
> On 01/12/17 15:22, Jonathan Dowland wrote:
> >AppArmor is not enabled in current
> >stable [...]

> I have stretch, and didn't requested it manually, but was installed
> with the latest kernel update from stretch backports. I think it was
> installed because of that backported kernel version:

[...]

> Install: libapparmor-perl:amd64 (2.11.0-3, automatic), apparmor:amd64 (2
> .11.0-3, automatic)
> Upgrade: linux-image-4.13.0-0.bpo.1-amd64:amd64 (4.13.4-2~bpo9+1, 4.13.1
> 3-1~bpo9+1)

Woah.

Thanks for the heads-up!

Cheers
- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlohacMACgkQBcgs9XrR2kbYiQCcD0KpM9bCQ8kn0EThdYAqDo1O
1sMAoIHZhlLejdC88beABSWhoP+WgqUN
=a87T
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#189447

FromMichael Biebl <biebl@debian.org>
Date2017-12-01 18:30 +0100
Message-ID<uRXiq-7dS-11@gated-at.bofh.it>
In reply to#189445

[Multipart message — attachments visible in raw view] — view raw

Am 01.12.2017 um 15:40 schrieb tomas@tuxteam.de:
> On Fri, Dec 01, 2017 at 03:30:50PM +0100, solitone wrote:
>> On 01/12/17 15:22, Jonathan Dowland wrote:
>>> AppArmor is not enabled in current
>>> stable [...]
> 
>> I have stretch, and didn't requested it manually, but was installed
>> with the latest kernel update from stretch backports. I think it was
>> installed because of that backported kernel version:
> 
> [...]
> 
>> Install: libapparmor-perl:amd64 (2.11.0-3, automatic), apparmor:amd64 (2
>> .11.0-3, automatic)
>> Upgrade: linux-image-4.13.0-0.bpo.1-amd64:amd64 (4.13.4-2~bpo9+1, 4.13.1
>> 3-1~bpo9+1)
> 
> Woah.
> 
> Thanks for the heads-up!

I think it might be useful to open a (wishlist) bug report against the
linux package to not add the recommends when building for stretch-backports

-- 
Why is it that all of the instruments seeking intelligent life in the
universe are pointed away from Earth?

-- 
Why is it that all of the instruments seeking intelligent life in the
universe are pointed away from Earth?

[toc] | [prev] | [next] | [standalone]


#189457

From"Alexander V. Makartsev" <avbetev@gmail.com>
Date2017-12-01 23:10 +0100
Message-ID<uS1Fn-1ym-1@gated-at.bofh.it>
In reply to#189447

[Multipart message — attachments visible in raw view] — view raw

On 01.12.2017 22:19, Michael Biebl wrote:
>
> I think it might be useful to open a (wishlist) bug report against the
> linux package to not add the recommends when building for stretch-backports
>
Isn't AppArmor required in buster and also required in stretch-backports
linux-image? Of course AppArmor can be disabled completely or partially
if profile for some application is broken, but it is not just
recommended package now.

-- 
With kindest regards, Alexander.

⢀⣴⠾⠻⢶⣦⠀ 
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
⠈⠳⣄⠀⠀⠀⠀ 

[toc] | [prev] | [next] | [standalone]


#189461

Fromsolitone <solitone@mail.com>
Date2017-12-02 10:20 +0100
Message-ID<uSc7L-84f-5@gated-at.bofh.it>
In reply to#189457
On 01/12/17 22:59, Alexander V. Makartsev wrote:
> On 01.12.2017 22:19, Michael Biebl wrote:
>>
>> I think it might be useful to open a (wishlist) bug report against the
>> linux package to not add the recommends when building for stretch-backports
>>
> Isn't AppArmor required in buster and also required in stretch-backports 
> linux-image? Of course AppArmor can be disabled completely or partially 
> if profile for some application is broken, but it is not just 
> recommended package now.

Yes, if I'm pretty sure it wasn't just recommended, but it was 
required--if I remember right I had no choice.

[toc] | [prev] | [next] | [standalone]


#189462

From"Alexander V. Makartsev" <avbetev@gmail.com>
Date2017-12-02 11:50 +0100
Message-ID<uSdwR-pc-3@gated-at.bofh.it>
In reply to#189461

[Multipart message — attachments visible in raw view] — view raw

On 02.12.2017 14:11, solitone wrote:
> On 01/12/17 22:59, Alexander V. Makartsev wrote:
>> On 01.12.2017 22:19, Michael Biebl wrote:
>>>
>>> I think it might be useful to open a (wishlist) bug report against the
>>> linux package to not add the recommends when building for
>>> stretch-backports
>>>
>> Isn't AppArmor required in buster and also required in
>> stretch-backports linux-image? Of course AppArmor can be disabled
>> completely or partially if profile for some application is broken,
>> but it is not just recommended package now.
>
> Yes, if I'm pretty sure it wasn't just recommended, but it was
> required--if I remember right I had no choice.
>
Now, when I hit this buggy profile problem, I'm thinking about how to
deal with these problems in the future for other applications.
After consulting AppArmor manual I have not found any reference about
how to override AppArmor profile.
All profiles are placed in "/etc/apparmor.d/" and that is it, so the
only options are either disable misbehaving AppArmor profile or modify
it which is bad option because this is package shipped profile.
For an example, systemd unit-files could be easily overridden without
resorting to modification of package shipped unit-files.
I this possible for AppArmor?

-- 
With kindest regards, Alexander.

⢀⣴⠾⠻⢶⣦⠀ 
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
⠈⠳⣄⠀⠀⠀⠀ 

[toc] | [prev] | [next] | [standalone]


#189486

FromBen Caradoc-Davies <ben@transient.nz>
Date2017-12-02 23:00 +0100
Message-ID<uSnZf-6MA-1@gated-at.bofh.it>
In reply to#189462
On 02/12/17 23:43, Alexander V. Makartsev wrote:
> Now, when I hit this buggy profile problem, I'm thinking about how to
> deal with these problems in the future for other applications.
> After consulting AppArmor manual I have not found any reference about
> how to override AppArmor profile.
> All profiles are placed in "/etc/apparmor.d/" and that is it, so the
> only options are either disable misbehaving AppArmor profile or modify
> it which is bad option because this is package shipped profile.
> For an example, systemd unit-files could be easily overridden without
> resorting to modification of package shipped unit-files.
> I this possible for AppArmor?

Yes, there is aa-complain in the apparmor-utils packages, but this was 
itself buggy when I used it for thunderbird:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=882047

Kind regards,

-- 
Ben Caradoc-Davies <ben@transient.nz>
Director
Transient Software Limited <http://transient.nz/>
New Zealand

[toc] | [prev] | [next] | [standalone]


#189488

From"Alexander V. Makartsev" <avbetev@gmail.com>
Date2017-12-03 00:10 +0100
Message-ID<uSp4Z-7Ff-7@gated-at.bofh.it>
In reply to#189486

[Multipart message — attachments visible in raw view] — view raw

On 03.12.2017 02:57, Ben Caradoc-Davies wrote:
> On 02/12/17 23:43, Alexander V. Makartsev wrote:
>> Now, when I hit this buggy profile problem, I'm thinking about how to
>> deal with these problems in the future for other applications.
>> After consulting AppArmor manual I have not found any reference about
>> how to override AppArmor profile.
>> All profiles are placed in "/etc/apparmor.d/" and that is it, so the
>> only options are either disable misbehaving AppArmor profile or modify
>> it which is bad option because this is package shipped profile.
>> For an example, systemd unit-files could be easily overridden without
>> resorting to modification of package shipped unit-files.
>> I this possible for AppArmor?
>
> Yes, there is aa-complain in the apparmor-utils packages, but this was
> itself buggy when I used it for thunderbird:
> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=882047
>
> Kind regards,
>
If I understood this correctly, aa-complain will only switch profile to
"complain mode"(log, but don't block). This is effectively the same as
disabling the profile, which is not a good solution.
"aa-complain" is useful for debugging and writing my own profiles, but
it won't be as useful when partially broken profile is coming from
package, because any user-modifications will be over-written after
package updates.

-- 
With kindest regards, Alexander.

⢀⣴⠾⠻⢶⣦⠀ 
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
⠈⠳⣄⠀⠀⠀⠀ 

[toc] | [prev] | [next] | [standalone]


#189496

FromVincas Dargis <vindrg@gmail.com>
Date2017-12-03 10:10 +0100
Message-ID<uSyrD-5r3-1@gated-at.bofh.it>
In reply to#189488
On 2017-12-03 01:07, Alexander V. Makartsev wrote:
> If I understood this correctly, aa-complain will only switch profile to "complain mode"(log, but don't block). This is 
> effectively the same as disabling the profile, which is not a good solution.

I believe "deny" rules still apply even on complain mode. If profile has "private-files" abstraction included, your 
~/.bash* files will be still protected.

> "aa-complain" is useful for debugging and writing my own profiles, but it won't be as useful when partially broken 
> profile is coming from package, because any user-modifications will be over-written after package updates.

User modifications can be place into "local" includes, for Thunderbird it's `/etc/apparmor.d/local/usr.bin.thunderbird`, 
they will not be overwritten.

Do not forget to reload profile with `sudo apparmor_parser -r /etc/apparmor.d/usr.bin.thunderbird` afterwards.

If you believe that these local modifications could be useful for other use cases, please report a bug with usertag 
modify-profile or buggy-profile [0]

[0] https://wiki.debian.org/AppArmor/Reportbug#Usertags

[toc] | [prev] | [next] | [standalone]


#189560

From"Alexander V. Makartsev" <avbetev@gmail.com>
Date2017-12-04 19:50 +0100
Message-ID<uT3Yu-8pK-15@gated-at.bofh.it>
In reply to#189496

[Multipart message — attachments visible in raw view] — view raw

On 03.12.2017 13:49, Vincas Dargis wrote:
> On 2017-12-03 01:07, Alexander V. Makartsev wrote:
>> If I understood this correctly, aa-complain will only switch profile
>> to "complain mode"(log, but don't block). This is effectively the
>> same as disabling the profile, which is not a good solution.
>
> I believe "deny" rules still apply even on complain mode. If profile
> has "private-files" abstraction included, your ~/.bash* files will be
> still protected.
>
>> "aa-complain" is useful for debugging and writing my own profiles,
>> but it won't be as useful when partially broken profile is coming
>> from package, because any user-modifications will be over-written
>> after package updates.
>
> User modifications can be place into "local" includes, for Thunderbird
> it's `/etc/apparmor.d/local/usr.bin.thunderbird`, they will not be
> overwritten.
>
> Do not forget to reload profile with `sudo apparmor_parser -r
> /etc/apparmor.d/usr.bin.thunderbird` afterwards.
>
> If you believe that these local modifications could be useful for
> other use cases, please report a bug with usertag modify-profile or
> buggy-profile [0]
>
> [0] https://wiki.debian.org/AppArmor/Reportbug#Usertags

Thanks for the information. It felt like there should be some way to
gracefully override profiles. Definitely gonna test that.

Also will eventually go through whole AppArmor documentation as well at
http://wiki.apparmor.net/index.php/Documentation

-- 
With kindest regards, Alexander.

⢀⣴⠾⠻⢶⣦⠀ 
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
⠈⠳⣄⠀⠀⠀⠀ 

[toc] | [prev] | [next] | [standalone]


#189581

FromVincas Dargis <vindrg@gmail.com>
Date2017-12-05 17:50 +0100
Message-ID<uTozT-56E-9@gated-at.bofh.it>
In reply to#189560
On 2017-12-04 20:42, Alexander V. Makartsev wrote:
> Thanks for the information. It felt like there should be some way to gracefully override profiles. Definitely gonna test 
> that.

There is a current discussion [0] for using AppArmor profile variables for ever more customization points, as (again) 
advanced Thunderbird use cases shows us.

> Also will eventually go through whole AppArmor documentation as well at http://wiki.apparmor.net/index.php/Documentation

`man apparmor.d` looks like a good read too.

[0] https://lists.ubuntu.com/archives/apparmor/2017-December/011350.html

[toc] | [prev] | [next] | [standalone]


#189546

FromJonathan Dowland <jmtd@debian.org>
Date2017-12-04 12:50 +0100
Message-ID<uSXq2-4ll-21@gated-at.bofh.it>
In reply to#189444
On Fri, Dec 01, 2017 at 03:30:50PM +0100, solitone wrote:
>On 01/12/17 15:22, Jonathan Dowland wrote:
>>AppArmor is not enabled in current
>>stable, so you should only hit this bug if you are using stable's
>>thunderbird on a testing/sid system, or manually enabling AppArmor
>>yourself on stable.
>
>I have stretch, and didn't requested it manually, but was installed 
>with the latest kernel update from stretch backports. I think it was 
>installed because of that backported kernel version:

Ouch, I think this is probably a mistake. Good catch!

-- 

⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Jonathan Dowland
⢿⡄⠘⠷⠚⠋⠀ https://jmtd.net
⠈⠳⣄⠀⠀⠀⠀ Please do not CC me, I am subscribed to the list.

[toc] | [prev] | [next] | [standalone]


#189436

FromBen Caradoc-Davies <ben@transient.nz>
Date2017-11-30 22:40 +0100
Message-ID<uREIP-3Ta-13@gated-at.bofh.it>
In reply to#189427
On 30/11/17 18:45, solitone wrote:
> The only other suspect I have is apparmor, which was installed in a 
> recent security update. But can this be the reason?

Yes. For example:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=882043

Kind regards,

-- 
Ben Caradoc-Davies <ben@transient.nz>
Director
Transient Software Limited <http://transient.nz/>
New Zealand

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web