[Bug 1583057] Re: Deny audio recording for all snap applications

2017-08-03 Thread Jamie Strandboge
** Changed in: pulseaudio (Ubuntu Xenial) Status: In Progress => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1583057 Title: Deny audio recording for all snap applications To mana

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-07-06 Thread Jamie Strandboge
@Simon, thanks for the updates. It looks I did not have the module- snappy-policy module loaded and appreciate the update to default.pa and the updated patch that addresses the other issues. The only remaining issue is making sure that recording continues to work in devmode. I think you will want

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-07-06 Thread Simon Fels
Updated the patch. We now add snappy-policy always to default.pa. I couldn't figure out what I have to change to make the ifelse statement work properly to add the snappy policy module only conditionally to default.pa Also fixed the compiler warnings and other small things. ** Patch added: "pa-sn

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-07-06 Thread Simon Fels
@Jamie: Works fine here for me. Using a simple snap name: pulseaudio-clients version: 8.0-1 summary: Clients for PulseAudio description: | Contains PulseAudio client utilities apps: pactl: command: usr/bin/pactl plugs: [pulseaudio] paplay: command: usr/bin/paplay plugs: [puls

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-07-05 Thread Jamie Strandboge
** Description changed: - [Impact] + [Impact] Currently snaps on Ubuntu Classic may declare in their snap.yaml that they want access to pulseaudio. When installed, snapd will auto-connect the pulseaudio interface giving the snap access to the pulseaudio server for playback and recording. Bec

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-07-05 Thread Jamie Strandboge
@Simon, per the SRU process, I've done the paperwork to pursue the SRU but leaving this as 'In Progress' due to my comments. Please attach an updated debdiff and I'll review and adjust the bug as appropriate. -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-07-05 Thread Jamie Strandboge
@Simon, finally, in reading the patch this will affect both strict and devmode and so the patch should "if startswith 'snap.' and process is in enforce mode ; then block recording". This will be needed for the phase 2 implementation as well, so it is not wasted effort. I've asked the apparmor devs

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-07-05 Thread Jamie Strandboge
** Description changed: - Until we have a proper trust-store implementation with snappy and on the - desktop/ubuntu core we want pulseaudio to simply deny any audio - recording request coming from an app shipped as part of a snap. + [Impact] + Currently snaps on Ubuntu Classic may declare in thei

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-07-05 Thread Jamie Strandboge
The functionality does not work as expected and I am able to record when running parecord under an apparmor profile that starts with 'snap.' (see attached). ** Attachment added: "1583057-test.sh" https://bugs.launchpad.net/ubuntu/+source/pulseaudio/+bug/1583057/+attachment/4696048/+files/15830

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-07-05 Thread Jamie Strandboge
I should mention that when testing this installed test packages then logged out of my session, killed my user's pulseaudio then logged back in. I suppose I could have also done 'killall pulseaudio' and have it restart automatically instead. -- You received this bug notification because you are a

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-07-05 Thread Jamie Strandboge
The functionality does not work as expected and I am able to record when running parecord under an apparmor profile that starts with 'snap.' (see attached). -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bug

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-07-05 Thread Jamie Strandboge
** Changed in: pulseaudio (Ubuntu Xenial) Importance: Undecided => High ** Changed in: pulseaudio (Ubuntu Xenial) Assignee: (unassigned) => Simon Fels (morphis) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.laun

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-07-05 Thread Jamie Strandboge
@Simon, couple of small things: * you should use 8.0-0ubuntu3.1 as the version instead of 8.0-0ubuntu4 * the changelog has a date of 'Tue, 17 May 2016 17:59:58 +0200' which is quite old, yet the diff was only recently uploaded. You can use 'dch -r' to update the date More importantly: * the pat

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-07-05 Thread Jamie Strandboge
** Changed in: pulseaudio (Ubuntu Xenial) Status: Triaged => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1583057 Title: Deny audio recording for all snap applications To manage

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-07-05 Thread Jamie Strandboge
@Simon, thanks, I'll work on sponsoring this. @Zygmunt, I'm not sure this is the patch to upstream-- it is the phase 1 approach and the phase 2 approach is pulseaudion/trust-store/snappy interfaces which we will be discussing this week. -- You received this bug notification because you are a mem

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-07-04 Thread Zygmunt Krynicki
Can we please try to upstream this patch? This will help with making other distributions share the security features and advantages of snaps. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1583057 Titl

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-07-04 Thread Simon Fels
@Jamie: Attached is a debdiff to update the pulse pacakge with snappy support. ** Patch added: "pulseaudio-snappy-deny-recording.diff" https://bugs.launchpad.net/ubuntu/+source/pulseaudio/+bug/1583057/+attachment/4695115/+files/pulseaudio-snappy-deny-recording.diff -- You received this bug n

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-06-10 Thread Jamie Strandboge
Ping, who will be providing this update to xenial? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1583057 Title: Deny audio recording for all snap applications To manage notifications about this bug

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-06-03 Thread Jamie Strandboge
** Changed in: pulseaudio (Ubuntu Xenial) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1583057 Title: Deny audio recording for all snap applications To manage notific

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-06-02 Thread Jamie Strandboge
Thanks for working on this! Per the snappy team, this will also need a SRU for xenial. ** Also affects: pulseaudio (Ubuntu Yakkety) Importance: High Assignee: Luke Yelavich (themuso) Status: Fix Released ** Also affects: pulseaudio (Ubuntu Xenial) Importance: Undecided St

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-06-02 Thread Jamie Strandboge
Adding xenial task and marking triaged since a fix is available in yakkety. Who will be providing this update? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1583057 Title: Deny audio recording for a

Re: [Bug 1583057] Re: Deny audio recording for all snap applications

2016-06-01 Thread Luke Yelavich
I was under the impression that this had been tested given its waiting to be landed in overlays etc. If it has not beentested, I am happy to back it out, since I am not in a position to test this right now. -- You received this bug notification because you are a member of Ubuntu Bugs, which is s

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-06-01 Thread Simon Fels
@Luke: How did you test the change before landing it? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1583057 Title: Deny audio recording for all snap applications To manage notifications about this

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-05-31 Thread Launchpad Bug Tracker
This bug was fixed in the package pulseaudio - 1:8.0-2ubuntu2 --- pulseaudio (1:8.0-2ubuntu2) yakkety; urgency=medium [ Simon Fels ] * debian/patches/0700-modules-add-snappy-policy-module.patch: - Add initial support for a snappy specific policy manager which will deny a

[Bug 1583057] Re: Deny audio recording for all snap applications

2016-05-18 Thread Sebastien Bacher
Hey Luke, could you work with Simon to help landing that to yakkety and probably SRU to xenial (needed for snappy)? ** Changed in: pulseaudio (Ubuntu) Importance: Undecided => High ** Changed in: pulseaudio (Ubuntu) Assignee: (unassigned) => Luke Yelavich (themuso) -- You received this