Re: Snap security questions

2017-02-07 Thread Jamie Strandboge
On Wed, 2017-02-01 at 08:46 -0600, Jamie Strandboge wrote: > On Wed, 2017-02-01 at 20:33 +0800, James Henstridge wrote: > > > > Hi, > > > > On our team we've been working to snap the thumbnailer project.  While > > there are some problems that are probably specific to this package, > > there were

Re: Snap security questions

2017-02-06 Thread Jamie Strandboge
On Fri, 2017-02-03 at 19:59 +0800, James Henstridge wrote: > On 1 February 2017 at 22:46, Jamie Strandboge wrote: > > > > On Wed, 2017-02-01 at 20:33 +0800, James Henstridge wrote: > > > > > > 2. Use of the libapparmor aa_is_enabled and aa_query_label APIs > > > > > > When deciding whether to d

Re: Snap security questions

2017-02-03 Thread James Henstridge
On 1 February 2017 at 22:46, Jamie Strandboge wrote: > On Wed, 2017-02-01 at 20:33 +0800, James Henstridge wrote: >> 2. Use of the libapparmor aa_is_enabled and aa_query_label APIs >> >> When deciding whether to do work on behalf of a client, >> thumbnailer-service uses a couple libapparmor API ca

Re: Snap security questions

2017-02-02 Thread Jamie Strandboge
On Thu, 2017-02-02 at 17:22 -0500, espy wrote: > > On 02/01/2017 09:46 AM, Jamie Strandboge wrote: > > > > On Wed, 2017-02-01 at 20:33 +0800, James Henstridge wrote: > > > > > > Hi, > [...] > > > > > > > > > 3. QNetworkAccessManager wants to access NetworkManager > > > > > > We use QNetworkA

Re: Snap security questions

2017-02-02 Thread espy
On 02/01/2017 09:46 AM, Jamie Strandboge wrote: On Wed, 2017-02-01 at 20:33 +0800, James Henstridge wrote: Hi, [...] 3. QNetworkAccessManager wants to access NetworkManager We use QNetworkAccessManager as our HTTP library. This results in a number of denials for D-Bus method calls to Net

Re: Snap security questions

2017-02-01 Thread Jamie Strandboge
On Wed, 2017-02-01 at 20:33 +0800, James Henstridge wrote: > Hi, > > On our team we've been working to snap the thumbnailer project.  While > there are some problems that are probably specific to this package, > there were a few that I suspect might affect other packages too: > > 1. Intra-snap D-

Snap security questions

2017-02-01 Thread James Henstridge
Hi, On our team we've been working to snap the thumbnailer project. While there are some problems that are probably specific to this package, there were a few that I suspect might affect other packages too: 1. Intra-snap D-Bus communication The thumbnailer D-Bus service exposes a number of meth