jeremiejig, thanks for your work on this. I think I am going to solve it in a different way however. It would be nice if AppArmor could merge profiles, but we can't yet, so we need to do like you initially did: have two mostly identical profiles. Because the lightdm remote sessions are shipping policy copies, the maintenance cost is getting high. I will be abstracting out the guest rules into abstracations/lightdm and then have a small snippet using a child profile in abstractions /lightdm_chromium-browser. The guest and remote lightdm profiles can just include these and all the policy is in the abstractions. Using a lightdm.d directory is a good idea, but upstream AppArmor is currently discussing how to best handle .d directories like this, and I'd rather not add another one until that discussions is finished.
** Changed in: lightdm-remote-session-freerdp (Ubuntu) Status: Triaged => In Progress -- You received this bug notification because you are a member of Desktop Packages, which is subscribed to gdm-guest-session in Ubuntu. https://bugs.launchpad.net/bugs/577919 Title: chromium-browser fails to start (guest account, OpenVZ): "Failed to move to new PID namespace: Operation not permitted" Status in Chromium Browser: Unknown Status in Light Display Manager: In Progress Status in OpenVZ kernel (patchset): Confirmed Status in “gdm-guest-session” package in Ubuntu: Confirmed Status in “lightdm” package in Ubuntu: In Progress Status in “lightdm-remote-session-freerdp” package in Ubuntu: In Progress Status in “lightdm-remote-session-uccsconfigure” package in Ubuntu: In Progress Bug description: Binary package hint: chromium-browser When i opened my guest account to let my friend to use the computer, he couldn't run chromium-browser. But it works ok when my user account is activated ProblemType: Bug DistroRelease: Ubuntu 10.04 Package: chromium-browser 5.0.342.9~r43360-0ubuntu2 ProcVersionSignature: Ubuntu 2.6.32-22.33-generic 2.6.32.11+drm33.2 Uname: Linux 2.6.32-22-generic i686 Architecture: i386 Date: Sun May 9 19:49:44 2010 InstallationMedia: Ubuntu 10.04 "Lucid Lynx" - Beta i386 (20100318) ProcEnviron: LANG=tr_TR.utf8 SHELL=/bin/bash SourcePackage: chromium-browser To manage notifications about this bug go to: https://bugs.launchpad.net/chromium-browser/+bug/577919/+subscriptions -- Mailing list: https://launchpad.net/~desktop-packages Post to : desktop-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~desktop-packages More help : https://help.launchpad.net/ListHelp