[Bug 1852485] Re: [SRU] Add AssumedAppArmorLabel to fwupd service

Ɓukasz Zemczak 1852485 at bugs.launchpad.net
Mon Dec 16 09:47:50 UTC 2019


Ken, could you address Chris's and Mario's concerns? We can't release
the update with this situation unclear.

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to fwupd-signed in Ubuntu.
https://bugs.launchpad.net/bugs/1852485

Title:
  [SRU] Add AssumedAppArmorLabel to fwupd service

Status in fwupd package in Ubuntu:
  Fix Released
Status in fwupd-signed package in Ubuntu:
  Fix Released
Status in fwupd source package in Bionic:
  New
Status in fwupd-signed source package in Bionic:
  New
Status in fwupd source package in Disco:
  New
Status in fwupd-signed source package in Disco:
  New
Status in fwupd source package in Eoan:
  Fix Committed
Status in fwupd-signed source package in Eoan:
  Fix Committed

Bug description:
  In order for strictly confined snaps to work with the host's fwupd we
  need to add the AssumedAppArmorLabel=unconfined to the DBus service
  file.

  [Impact]

   * Without this label, strictly confined snaps can not work with the
  host's fwupd service

  
  [Test Case]

   * snap install --edge gnome-firmware
   * snap connect gnome-firmware:fwupd
   * snap run gnome-firmware
   * Expected results: Display devices with upgradable firmware
     
  [Regression Potential] 

   * There should be no potential for regression, this is adding an
  optional label that will not effect other services communicating with
  the fwupd service.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/fwupd/+bug/1852485/+subscriptions



More information about the foundations-bugs mailing list