lp://staging/~elopio/snap-confine/autopkgtest
- Get this branch:
- bzr branch lp://staging/~elopio/snap-confine/autopkgtest
Branch merges
- Snappy Developers: Pending requested
-
Diff: 183 lines (+70/-19)8 files modifieddebian/tests/control (+3/-0)
tests/common.sh (+10/-1)
tests/test_bad_appname_whitelist (+29/-0)
tests/test_complain (+4/-0)
tests/test_create_user_data (+9/-0)
tests/test_good_appname_whitelist (+7/-18)
tests/test_restrictions_working (+4/-0)
tests/test_unrestricted (+4/-0)
Branch information
Recent revisions
- 135. By Jamie Strandboge
-
debian/
usr.bin. ubuntu- core-launcher: add workaround rules for ecryptfs
until the upcoming kernel fix lands everywhere (LP: #1574556) - 134. By Jamie Strandboge
-
* SECURITY UPDATE: delayed attack snap data theft and privilege escalation
when using Snappy on traditional Ubuntu (classic) systems (LP: #1576699)
- src/main.c: remove glob code and hardcode /snap/ubuntu-core/current
instead. The glob code both used an improper glob and performed an
incorrect check due to a typo which allowed a snap named ubuntu-core-...
to be bind mounted into application runtimes instead of the ubuntu-core
OS snap. Ubuntu Core removed .<origin> and .sideload from the SNAP path
so the glob can simply be dropped.
- CVE-2016-1580
* debian/usr.bin. ubuntu- core-launcher:
- only allow mounting /snap/ubuntu-core/*/ ... to safeguard against this in
the future
- add lib32 and libx32 to match setup_snappy_os_mounts( ) - 132. By Jamie Strandboge
-
- make whitelist_re strictly follow the 16.04 specification and adjust
testsuite accordingly - 131. By Jamie Strandboge
-
src/main.c: don't prepend snap. or snap_ since snapd is doing that for us
now (LP: #1571048)
Branch metadata
- Branch format:
- Branch format 7
- Repository format:
- Bazaar repository format 2a (needs bzr 1.16 or later)
- Stacked on:
- lp://staging/~snappy-dev/snap-confine/trunk