[MIR] bubblewrap
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
bubblewrap (Ubuntu) |
Fix Released
|
High
|
Unassigned |
Bug Description
Availability
============
Built for all supported architectures.
In sync with Debian.
Rationale
=========
The gnome-desktop3 library 3.25.90+ requires bubblewrap. bubblewrap is most commonly used as part of Flatpak's security isolation feature. Here it's being used to sandbox the thumbnailers.
See https:/
The bubblewrap feature was disabled in Ubuntu 17.10's gnome-desktop3 package because this MIR was not processed.
Security
========
No known open security vulnerabilities in any Ubuntu releases.
https:/
I helped prepare a security update (LP: #1657357) (CVE-2017-5226) for bubblewrap/flatpak several months ago.
Security-sensitive package.
Quality assurance
=================
Bug subscriber: should be Ubuntu Desktop Bugs
https:/
https:/
https:/
dh_auto_test runs the build tests but they appear to be set as SKIP upstream. (See comment #4)
Multiple autopkgtests passing on all Ubuntu architectures. Because the tests require machine isolation, the autopkgtests don't run on Debian's infrastructure currently.
Dependencies
============
check-mir reports all other binary dependencies are in main
Standards compliance
=======
4.0.0
Maintenance
===========
- Actively developed upstream
https:/
- Maintained in Debian by the pkg-utopia team but more specifically, it is maintained by Simon McVittie (smcv) who also maintains Flatpak and ostree in Debian and Ubuntu.
short dh7 style rules, dh compat 10
Background information
=======
William Hua (attente) had been working last year on a snapcraft plugin that used bubblewrap.
So maybe more stuff will use bubblewrap in the future.
CVE References
summary: |
- [FFe][MIR] bubblewrap + FFe: [MIR] bubblewrap |
summary: |
- FFe: [MIR] bubblewrap + [MIR] bubblewrap |
description: | updated |
description: | updated |
Changed in bubblewrap (Ubuntu): | |
assignee: | Seth Arnold (seth-arnold) → Alex Murray (alexmurray) |
Changed in bubblewrap (Ubuntu): | |
status: | Triaged → Fix Released |
Status changed to 'Confirmed' because the bug affects multiple users.