*** This bug is a duplicate of bug 2064849 ***
    https://bugs.launchpad.net/bugs/2064849

Ubuntu can not ship an unconfined bwrap profile, doing so allows a
trivial by-pass of the unprivileged user namespace restrictions.

An alternative profile for bwrap is provided by the apparmor-profiles
package in /usr/share/apparmor/extra-profiles/bwrap-userns-restrict

it is not enabled by default at this time due to a need to fix an
interaction with flatpak.

-- 
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to apparmor in Ubuntu.
https://bugs.launchpad.net/bugs/2079983

Title:
  Thumbnails in desktop doesn't work due to apparmor restrictions

Status in apparmor package in Ubuntu:
  New

Bug description:
  DesktopIconsNG uses the gnome-desktop library to generate thumbnails.
  Unfortunately, it uses bwrap to launch the thumbnailers, which
  requires unprivileged user mamespaces, so it fails in Ubuntu 24.04.
  Creating /etc/apparmor.d/bwrap file with the attached patch does solve
  the problem.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2079983/+subscriptions


-- 
Mailing list: https://launchpad.net/~touch-packages
Post to     : touch-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~touch-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to