Mailinglist Archive: opensuse (2058 mails)
| < Previous | Next > |
[opensuse] apparmor and bin.ping from factory
- From: Jan Engelhardt <jengelh@xxxxxxxxxxxxxxx>
- Date: Fri, 10 Aug 2007 20:23:55 +0200 (CEST)
- Message-id: <Pine.LNX.4.64.0708102022140.13912@xxxxxxxxxxxxxxxxxxxxxxxxx>
Hi,
so by default, the yast control panel apparmoar/"Profile Mode
Configuration" shows:
bin.ping enforce
sbin.klogd enforce
etc.
With bin.ping being enabled, one cannot use the ping utility anymore,
neither as normal user nor as root. According to strace,
socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = -1 EACCES (Permission denied)
already fails. Is this really intended?
Jan
--
--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx
so by default, the yast control panel apparmoar/"Profile Mode
Configuration" shows:
bin.ping enforce
sbin.klogd enforce
etc.
With bin.ping being enabled, one cannot use the ping utility anymore,
neither as normal user nor as root. According to strace,
socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = -1 EACCES (Permission denied)
already fails. Is this really intended?
Jan
--
--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx
| < Previous | Next > |