Right, we don't really make particular promises about guest's data integrity, as all of its files are wiped after logout anyway. So I'd much rather ensure that we preserve the "inaccessible files from all other users" property than being more defensive against evince/flash exploits, but open up other user files through that.
Thanks! ** Changed in: gdm-guest-session (Ubuntu) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/673034 Title: gdm-guest-session AppArmor profile improvements -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs