/srv/irclogs.ubuntu.com/2022/04/03/#ubuntu-security.txt

hallynahasenack: i don't even know enough to know whether /run/user gets bind-mounted into the snap's chroot16:48
ahasenackyeah, but it wouldn't load from /home either21:18
ahasenackexcept I didn't see an apparmor DENIED message in that case21:18
ahasenackI filed this bug, but I'm unsure canonical will tackle it, since the snap comes from mozilla: https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/196763221:20
ubottuLaunchpad bug 1967632 in firefox (Ubuntu) "apparmor denied when trying to load pkcs11 module for smart card authentication" [Undecided, New]21:20
ahasenackupstream bug: https://bugzilla.mozilla.org/show_bug.cgi?id=173437121:23
ubottuMozilla bug 1734371 in Release Engineering "Firefox snap can't load PKCS#11 modules on the host system" [S2, New]21:23
JanCMozilla already broke some PKCS#11 support in recent Firefox versions, unrelated to snaps...  :-(22:41
JanCI'm starting to wonder if Mozilla even care about Firefox at all22:42
JanCBTW: if Firefox will be forced to become a snap, I will be forced to move away from using Ubuntu, in part because of this sort of bugs (I can’t allow automatic updates when they possibly block me from interacting with the government)22:57
JanCmaybe that's something Canonical should consider...22:58
JanCFirefox-as-a-snap is a security issue22:59
jjohansenwell, the last few years sure has provided evidence that they don't care about FF23:03
jjohansenand yes FF as a snap is a huge issue for many people23:03
JanCbased on https://bugzilla.mozilla.org/show_bug.cgi?id=1759162 it also seems like upstream Mozilla are testing Firefox on Ubuntu 16.04 instead of (also) on more recent versions...23:07
ubottuMozilla bug 1759162 in WebExtensions "PKCS#11 loading on Linux through the browser.pkcs11 API is broken since Bug 1745352 landed" [S2, Verified: Fixed]23:07
JanCit's rather disturbing23:09
JanCsupposedly these people are now maintaining browser packages in Ubuntu...23:09
JanCwhile using Ubuntu versions that are out of security support23:09
JanChow hard can it be for Canonical to pay 1-2 people to maintain a proper browser package?23:10
EickmeyerJanC: That wasn't the point. The entire reason FF went Snap was because Mozilla chose that as part of their distribution agreement with Canonical, not the other way around. This was Mozilla's decision, not Canonical's.23:14
JanCI don't care if it's called "Ubuntu browser" or "Firefox" BTW23:14
JanCEickmeyer: and I think Canonical shouldn't accept that23:14
JanCUbuntu/Canonical23:15
EickmeyerThen we wouldn't be able to redistribute Firefox at all.23:15
JanC<JanC> I don't care if it's called "Ubuntu browser" or "Firefox" BTW23:15
JanCfuck Mozilla if they want to lose even more name recognition23:15
JanCit's their loss23:15
EickmeyerJanC: Please abide by the CoC.23:15
JanCMozilla don't abide to the CoC, but you happily accept that...23:17
EickmeyerJanC: I don't work for Canonical, and you are responsible for your behavior, not Mozilla's.23:17
JanCI used 1 word that a minority of people might maybe consider to be a violation of the CoC (although I would claim it shows humanity so it's perfectly fine under the CoC :P ), meanwhile Canonical/Ubuntu accept repeated Mozilla's anti-CoC behaviour without a single complaints23:22
JanCmaybe I should file a complaint with the CC23:22
EickmeyerJanC: I'm on the CC.23:23
JanCso, did you or will you put Mozilla's actual anti-CoC behaviour on the agenda, or will you only complain about people's silly choice of words on IRC?23:26
EickmeyerJanC: I don't consider Mozilla to be violating the CoC right now, but I've seen multiple problems from you in this channel alone. So do yourself a favor: take a walk.23:27
JanCare you saying now that Mozilla is listening to and working with the community? because almost nobody I know actually agrees with that…23:40
JanCand that's part of the CoC...23:41
EickmeyerJanC: This is not the place for this discussion. If you believe there is an *actual* CoC violation (btw, Mozilla doesn't participate as part of the Ubuntu community), then email community-council@lists.ubuntu.com.23:45
JanCyes, Mozilla is part of the Ubuntu community (maybe they don't want to be, and don't want to abide by the rules, but they are by the simple fact of insisting they make the official packages)23:46
EickmeyerJanC: Ok, I've said this isn't the place for this discussion and I mean it. Further discussion will happen via email thread, but you have to initiate it.23:48
amurrayshalocin[m]: thanks - but I can't take any credit - it's all ccdm94's awesomeness23:52

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!