[apparmor] Firefox profile and ~/Downloads, ~/Public folders permission.

Christian Boltz apparmor at cboltz.de
Sun Apr 28 22:32:05 UTC 2013


Hello,

Am Sonntag, 28. April 2013 schrieb Daniel Curtis:
> Hi. As we know, default Firefox profile contains something like this;
> 
> ,-----[ Default profile allows (...) ]
> 
> | owner @{HOME}/ r,
> | owner @{HOME}/Public/ r,
> | owner @{HOME}/Public/* r,
> | owner @{HOME}/Download/ r,
> | owner @{HOME}/Download/* rw,
> 
> `-----
> 
> Default profile allows downloads to ~/Downloads and uploads from
> ~/Public, right? So, what should I do or add to achieve this
> functionality. For now I can upload and download files everywhere I
> want. I would like to achieve that the profile will block (permission
> denied etc.) any attempts to save files in another directory.

I don't know what else you have in the profile, but my first guess would 
be that the profile isn't loaded or the firefox binary moved to another 
path than the profile expects.

Please check with aa-status (while firefox is running) what is going on. 
If unsure, just paste the output into a mail ;-)


Regards,

Christian Boltz
-- 
Der von Ihnen vielleicht erwartete Input wird zu dem eines verstimmten
Mitarbeiters oder eines Crackers der Monate Zeit hat, oder einer Katze,
die über die Tastatur läuft in keinerlei Zusammenhang stehen.
[http://php.net/manual/de/security.general.php]




More information about the AppArmor mailing list