apparmor.d/apparmor.d
Jose Maldonado b4e5837bb9
Fix access to /tmp using libpam-tmpdir in Debian (#318)
In Debian with the use of libpam-tmpdir, the paths for $TMP and $TMPDIR
for PAM sessions are affected by much stronger rules and permissions,
providing additional security to the environment.

Those rules for the directory

/tmp/user/@{uid}/<affected_program>

In the case of qBitorrent this applies to the following directory:

/tmp/user/@{uid}/.qBitorrent

This PR fixes the bug and allows qBittorrent to work correctly
under these conditions.

Note: This PR would also have positive effects on Whonix, which uses
libpam-tmpdir according to this link
(https://forums.whonix.org/t/make-symlink-attacks-and-other-tmp-based-attacks-harder-or-impossible-using-libpam-tmpdir/8488)
2024-04-28 10:27:39 +00:00
..
abstractions Fix out-of-scope in abstractions/video and bad use abstraction in chromium 2024-04-27 23:51:48 +01:00
groups Fix support for Qt5CT and Qt6CT in kde groups profiles 2024-04-27 23:51:48 +01:00
profiles-a-f Fix profiles for support Qt5CT and Qt6CT 2024-04-27 23:51:48 +01:00
profiles-g-l Fix suppport for Qt5CT and Qt6CT in profiles-g-l 2024-04-27 23:51:48 +01:00
profiles-m-r Fix access to /tmp using libpam-tmpdir in Debian (#318) 2024-04-28 10:27:39 +00:00
profiles-s-z Fix support for Qt5CT and Qt6CT in profiles-s-z 2024-04-27 23:51:48 +01:00
tunables build(whonix): handle internal whonix conflict. 2024-04-05 23:44:43 +01:00