So this is an existing issue that we sometimes tried to work around by
granting snap-confine more permissions. This is a limitation in apparmor
itself, where we cannot say that snap-confine can inherit and pass a
file descriptor to another process, whatever that file may be.

I had a quick look if that workaround handles /tmp/* but I couldn't see
anything. Perhaps it needs to be added but I'd like to write a test
first.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1849753

Title:
  AppArmor profile prohibits classic snap from inheriting file
  descriptors

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/snapd/+bug/1849753/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to