Enable bubblewrap in gnome-desktop3 for Ubuntu 18.04 LTS
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
bubblewrap (Ubuntu) |
Fix Released
|
High
|
Steve Beattie | ||
gnome-desktop3 (Ubuntu) |
Fix Released
|
High
|
Steve Beattie |
Bug Description
Impact
======
gnome-desktop 3.26 hardened the thumbnailers with bubblewrap to mitigate several vulnerabilities. Ubuntu had to disable that feature until bubblewrap could be promoted to main.
bubblewrap is now in main for 18.10 and the feature is now enabled there. The intention has been for that change to be backported to 18.04 LTS as a security fix.
The bubblewrap MIR is https:/
We'll need to promote bubblewrap to main before this update should be pushed to bionic.
Can you sponsor directly from the git repo instead of with a debdiff?
gbp clone https:/
git checkout ubuntu/bionic
gbp clone https:/
Testing Done
============
I test built bubblewrap and its autopkgtest passes:
https:/
Changed in gnome-desktop3 (Ubuntu): | |
status: | New → Confirmed |
description: | updated |
description: | updated |
Changed in bubblewrap (Ubuntu): | |
status: | New → Confirmed |
description: | updated |
Changed in bubblewrap (Ubuntu): | |
assignee: | nobody → Steve Beattie (sbeattie) |
Changed in gnome-desktop3 (Ubuntu): | |
assignee: | nobody → Steve Beattie (sbeattie) |
Changed in bubblewrap (Ubuntu): | |
importance: | Undecided → High |
Changed in gnome-desktop3 (Ubuntu): | |
importance: | Undecided → High |
Don't we need the changes to bubblewrap itself too?