Control: tag -1 - moreinfo Control: tag -1 + upstream Control: tag -1 + fixed-upstream Control: retitle -1 silently fails to start torbrowser due to incomplete AppArmor profiles
Hi, [email protected] wrote (15 Sep 2014 18:57:36 GMT) : > Those AppArmor policy changes fixed the issue. Thanks for confirming! > If you still want to see the kernel message anyway, here it is: > Sep 15 13:20:05 bolin kernel: [15363.513255] audit: type=1400 > audit(1410805205.021:326): apparmor="DENIED" operation="file_mprotect" > profile="/home/*/.local/share/torbrowser/tbb/{i686,x86_64}/tor-browser_*/{Browser/,}start-tor-browser" > name="/bin/dash" pid=7495 comm="start-tor-brows" requested_mask="r" > denied_mask="r" > fsuid=1000 ouid=0 Yep, this is exactly one of the denials I was expecting. > Thanks for the quick response, this should be fixed once these > changes make their way into the next package update. Since then, my branch was merged upstream. I think we should upload a package with the corrected profiles ASAP, as letting this kind of problems rot too long may slow down AppArmor adoption in Debian, and make our case weaker when we want to have it enabled by default => if I don't do it in the next 3 hours, I'd be glad if someone else on the team did. Cheers, -- intrigeri -- To UNSUBSCRIBE, email to [email protected] with a subject of "unsubscribe". Trouble? Contact [email protected]

