[pkg-apparmor] Bug#882597: libreoffice: Failed to start when apparmor is running because of user rights

intrigeri intrigeri at debian.org
Thu Dec 7 10:25:30 UTC 2017


Hi Rene,

(sorry for the delay, I was focusing on other issues that felt higher
priority than this one, since I've already workaround'ed the
problem successfully.)

Rene Engelhard:
>>     that everyone else can't benefit from AppArmor security benefits
>>     due to that, so I'm leaning towards:
>> 
>>       1. keep the AppArmor profile enforced by default, so the vast
>>          majority of users benefit from it;
>>       2. ensure the AppArmor profile supports customization and
>>          affected users can learn how to tweak it; in this case,
>>          I think adding in README.Debian "add your custom
>>          env:UserInstallation to @{libo_user_dirs}" would be sufficient.
>> 
>> What do you think? If you agree with my reasoning, then I could
>> provide a patch to implement the proposed change in README.Debian.

> Would be nice.

Great. I'll do this then :)

If you don't mind, once I have a patch I won't build a test package
locally: I suspect src:libreoffice takes a while to build, and my
changes should boil down to setting ENABLE_APPARMOR_PROFILES=y and
adding README.Debian that dh_installdocs should pick up automatically.

Cheers,
-- 
intrigeri



More information about the pkg-apparmor-team mailing list