jeremiejig, thanks for your work on this. I think I am going to solve it
in a different way however. It would be nice if AppArmor could merge
profiles, but we can't yet, so we need to do like you initially did:
have two mostly identical profiles. Because the lightdm remote sessions
are shipping policy copies, the maintenance cost is getting high. I will
be abstracting out the guest rules into abstracations/lightdm and then
have a small snippet using a child profile in abstractions
/lightdm_chromium-browser. The guest and remote lightdm profiles can
just include these and all the policy is in the abstractions. Using a
lightdm.d directory is a good idea, but upstream AppArmor is currently
discussing how to best handle .d directories like this, and I'd rather
not add another one until that discussions is finished.

** Changed in: lightdm-remote-session-freerdp (Ubuntu)
       Status: Triaged => In Progress

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to gdm-guest-session in Ubuntu.
https://bugs.launchpad.net/bugs/577919

Title:
  chromium-browser fails to start (guest account, OpenVZ): "Failed to
  move to new PID namespace: Operation not permitted"

Status in Chromium Browser:
  Unknown
Status in Light Display Manager:
  In Progress
Status in OpenVZ kernel (patchset):
  Confirmed
Status in “gdm-guest-session” package in Ubuntu:
  Confirmed
Status in “lightdm” package in Ubuntu:
  In Progress
Status in “lightdm-remote-session-freerdp” package in Ubuntu:
  In Progress
Status in “lightdm-remote-session-uccsconfigure” package in Ubuntu:
  In Progress

Bug description:
  Binary package hint: chromium-browser

  When i opened my guest account to let my friend to use the computer,
  he couldn't run chromium-browser.

  But it works ok when my user account is activated

  ProblemType: Bug
  DistroRelease: Ubuntu 10.04
  Package: chromium-browser 5.0.342.9~r43360-0ubuntu2
  ProcVersionSignature: Ubuntu 2.6.32-22.33-generic 2.6.32.11+drm33.2
  Uname: Linux 2.6.32-22-generic i686
  Architecture: i386
  Date: Sun May  9 19:49:44 2010
  InstallationMedia: Ubuntu 10.04 "Lucid Lynx" - Beta i386 (20100318)
  ProcEnviron:
   LANG=tr_TR.utf8
   SHELL=/bin/bash
  SourcePackage: chromium-browser

To manage notifications about this bug go to:
https://bugs.launchpad.net/chromium-browser/+bug/577919/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to     : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to