Hi, we kindly ask for automatic-connection for both “dot-local-share-applications” and “dot-local-share-icons” for vivaldi, to help with creating the required files when PWAs are made.
Ok, it seems even adding these to our snapcraft.yaml caused a requirement for human review. If anyone can do that as well, I would appreciate it.
human review required due to 'allow-installation' constraint (bool) declaration-snap-v2_plugs_installation (dot-local-share-applications, personal-files)
human review required due to 'allow-installation' constraint (bool) declaration-snap-v2_plugs_installation (dot-local-share-icons, personal-files)
Similarly to the discussion in the linked topic, allowing write access to ~/.local/share/applications allows a trivial sandbox escape. @alexmurray - has there been any alternative since this was discussed for chromium?
No, there is no other mechanism, however @vivaldi is a Verified Account so I don’t think there should be any problem with granting such a privileged interface. As such, +1 from me.
Ok, it looks like I have to remove the “dot-local-share-applications” and “dot-local-share-icons” changes I made from our snapcraft.yaml for now as every build I make is just stuck in review (because of this) and I have a security update to get out
It seems that removing that removing that change has not helped and we are still stuck in review for all builds from now on. That is problematic as we are trying to get a security update out based on Chromium ESR (Extended Stable Release) 130.0.6723.129. This is pretty much the same build as Chrome 130.0.6723.127 which was released on the 12th of November 2024 https://chromereleases.googleblog.com/2024/11/extended-stable-updates-for-desktop.html. This ESR release has many of the same security fixes as 131.0.6778.69 https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_12.html, at least one of which is rated as HIGH (CVE-2024-11110) plus a number of medium security fixes.
The review status means we cannot update the Snap package with these important security fixes, along with a bunch of our own fixes, including:
[Address bar][Direct Match] Should not be picked for autocomplete when there is a fuzzy match (VB-111397)
[Calendar] Crash when creating online calendar (VB-110824)
[Calendar] The day view does not update on date selection (VB-110864)
[Chromium] Upgraded to 130.0.6723.129
[Crash][PWA] Google Meet when sharing from another tab (VB-110712)
[Crash] Occasionally when dragging the image over the browser window (VB-106861)
[Crash] On downloading encrypted zip files (VB-109645)
[Crash] Trying to open 2nd profile in a certain way (VB-108929)
[Crash] Upon accepting notifications in some cases (VB-110504)
[Crash][Menus] Problems with menus (VB-111236)
[Linux][Snap packages][IME] CJK typing does not work (VB-111427)
[Notes] Link addresses in the notes are not saved (VB-110547)
[Settings] “Add new address” form doesn’t show fully for some countries (VB-110888)
[Tab][Settings] Top margin breaks when using Tab Stack with the native window option (VB-111076)
[Tabs] Reopen window from window-panel should restore tabs as hibernated (VB-111046)
[Workspaces] Optimize switching between workspaces (VB-110678)
I will update our rpm/deb and (unofficial) flatpak in the mean time but Snap users will have to wait, which is a shame and perhaps gives the impression that Snap packages are less important to us (they aren’t).
+2 votes for, 0 votes against, granting auto-connect of system-files interfaces dot-local-share-applications and dot-local-share-icons to snap vivaldi. The publisher is verified. This is now live.