Bug ID | 982112 |
---|---|
Summary | Maybe missing entries in apparmor profile for syslog-ng |
Classification | openSUSE |
Product | openSUSE Distribution |
Version | Leap 42.1 |
Hardware | x86-64 |
OS | openSUSE 42.1 |
Status | NEW |
Severity | Normal |
Priority | P5 - None |
Component | Basesystem |
Assignee | bnc-team-screening@forge.provo.novell.com |
Reporter | ronnypeine@gmx.de |
QA Contact | qa-bugs@suse.de |
Found By | --- |
Blocker | --- |
After upgrading 2 of my systems to openSUSE Leap 42.1 I see the following entries in my audit.log every 5-10 minutes: type=AVC msg=audit(1464385501.159:1184): apparmor="DENIED" operation="ptrace" profile="syslog-ng" pid=7239 comm="syslog-ng" target=80768C260288FFFF80768C260288FFFF10C489260288FFFF10C489260288FFFF20C489260288FFFF20C489260288FFFF2F02 type=AVC msg=audit(1464385627.924:1206): apparmor="DENIED" operation="open" profile="syslog-ng" name="/proc/7332/cmdline" pid=11935 comm="syslog-ng" requested_mask="r" denied_mask="r" fsuid=0 ouid=0 type=AVC msg=audit(1464385627.924:1207): apparmor="DENIED" operation="open" profile="syslog-ng" name="/proc/7332/loginuid" pid=11935 comm="syslog-ng" requested_mask="r" denied_mask="r" fsuid=0 ouid=0 type=AVC msg=audit(1464385627.924:1208): apparmor="DENIED" operation="open" profile="syslog-ng" name="/proc/7332/sessionid" pid=11935 comm="syslog-ng" requested_mask="r" denied_mask="r" fsuid=0 ouid=0 type=AVC msg=audit(1464385634.588:1212): apparmor="DENIED" operation="capable" profile="syslog-ng" pid=11936 comm="syslog-ng" capability=19 capname="sys_ptrace" I looked for the mentioned pids but they are not existing anymore. Seems like a short start of a process which then does things which are not permitted by the apparmor profile. Any idea what this can be? Maybe some missing entries in the syslog-ng apparmor profile? Kind regards, Ronny