Bug ID 982112
Summary Maybe missing entries in apparmor profile for syslog-ng
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.1
Hardware x86-64
OS openSUSE 42.1
Status NEW
Severity Normal
Priority P5 - None
Component Basesystem
Assignee bnc-team-screening@forge.provo.novell.com
Reporter ronnypeine@gmx.de
QA Contact qa-bugs@suse.de
Found By ---
Blocker ---

After upgrading 2 of my systems to openSUSE Leap 42.1 I see the following
entries in my audit.log every 5-10 minutes:
type=AVC msg=audit(1464385501.159:1184): apparmor="DENIED" operation="ptrace"
profile="syslog-ng" pid=7239 comm="syslog-ng"
target=80768C260288FFFF80768C260288FFFF10C489260288FFFF10C489260288FFFF20C489260288FFFF20C489260288FFFF2F02
type=AVC msg=audit(1464385627.924:1206): apparmor="DENIED" operation="open"
profile="syslog-ng" name="/proc/7332/cmdline" pid=11935 comm="syslog-ng"
requested_mask="r" denied_mask="r" fsuid=0 ouid=0
type=AVC msg=audit(1464385627.924:1207): apparmor="DENIED" operation="open"
profile="syslog-ng" name="/proc/7332/loginuid" pid=11935 comm="syslog-ng"
requested_mask="r" denied_mask="r" fsuid=0 ouid=0
type=AVC msg=audit(1464385627.924:1208): apparmor="DENIED" operation="open"
profile="syslog-ng" name="/proc/7332/sessionid" pid=11935 comm="syslog-ng"
requested_mask="r" denied_mask="r" fsuid=0 ouid=0
type=AVC msg=audit(1464385634.588:1212): apparmor="DENIED" operation="capable"
profile="syslog-ng" pid=11936 comm="syslog-ng" capability=19 
capname="sys_ptrace"

I looked for the mentioned pids but they are not existing anymore. Seems like a
short start of a process which then does things which are not permitted by the
apparmor profile.

Any idea what this can be? Maybe some missing entries in the syslog-ng apparmor
profile?

Kind regards,
Ronny


You are receiving this mail because: