[apparmor] [profile] Firefox: "org.mozilla.firefox.*" and "dbus_bind" -- DENIED.

daniel curtis sidetripping at gmail.com
Wed Mar 28 18:17:00 UTC 2018


Hello Mr McVittie.

>> Where did {DBus,dbus} come from?

I just thought, that such a "version" could be more useful, for
example, in the future? Thanks for an information about dbus-daemon's
API etc. So, according to your answer, I should change this rule to
something like:

dbus (send)
       bus=session
       path=/org/freedesktop/DBus
       interface=org.freedesktop.DBus
       member=RequestName

But You've written: "would be better". However, I've changed "path="
and removed "peer=". Is it OK now? Can I make above changes in Firefox
profile?

If it's about the second rule: I'd asked what should I use for "path="
(please see my previous message and "DENIED" entry). It was:
"firefox.*" and "firefox/*". And I'd asked, which variant is correct?
I should put it this way:

path=/org/mozilla/firefox.*
path=/org/mozilla/firefox/*

According to You and your answer, I should use:

dbus (bind) bus=session name=org.mozilla.firefox.*,

Is this correct? Both rules needs changes, right? Does above changes
made in rules - based on your answer - match what you mean and what
you have written?

I apologize for such a questions, but I have to be one hundred percent
sure. Thanks.



More information about the AppArmor mailing list