Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Whonix and AppArmor #5

Open
fyqwbdzsfjh opened this issue Sep 10, 2021 · 6 comments
Open

Whonix and AppArmor #5

fyqwbdzsfjh opened this issue Sep 10, 2021 · 6 comments

Comments

@fyqwbdzsfjh
Copy link

Getting bookmarks to work in Tor Browser in Whonix with AppArmor enabled (following instructions from hereclearnet) required some changes to these rules.

I added the following to /etc/apparmor.d/local/home.tor-browser.firefox

/usr/share/split-browser-disp/firefox/sb-load.js r,
/run/split-browser-disp/into-firefox rw,
/run/split-browser-disp/from-firefox rw,

Is this something that could be supplied with the package (either this one or upstream) and do these rules seem sensible?

I did not try other features of split-browser other than saving and opening bookmarks.

@fyqwbdzsfjh fyqwbdzsfjh changed the title Whonix AppArmor Whonix and AppArmor Sep 10, 2021
@adrelanos
Copy link

@fyqwbdzsfjh
Copy link
Author

@adrelanos sure thing! I'll test the other features of split-browser just in case (like logins)

@rustybird
Copy link
Owner

The "move downloads to a VM of your choice" feature (Ctrl-Shift-s) probably needs a rule for /bin/bash - like the existing rule for /bin/dash?

@fyqwbdzsfjh
Copy link
Author

@rustybird good shout. I tried it out, and it seems like bash isn't an issue, but qvm-copy-to-vm.gnome is. (which I don't quite understand, since it seems to try to call qvm-move-to-vm.kde here)

I could give execute permission to that, but since it tries to call a bunch of other stuff, that alone would not work. Something like:

/usr/lib/qubes/qvm-copy-to-vm.gnome Ux,

works, but rather than having it unconfined, maybe it should have its own profile.

@fyqwbdzsfjh
Copy link
Author

I'll close this for now, as further discussion should probably happen in the Whonix/apparmor-profile-torbrowser-repo.

@rustybird
Copy link
Owner

rustybird commented Aug 13, 2022

With AppArmor now(?) enabled by default on Whonix Workstation, the "move downloads to a VM of your choice" feature (Ctrl-Shift-s) is currently broken.

@rustybird rustybird reopened this Aug 13, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants