Bug ID 918787
Summary logprof fails to parse audit.log
Classification openSUSE
Product openSUSE Distribution
Version 13.2
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component AppArmor
Assignee suse-beta@cboltz.de
Reporter asn@cryptomilk.org
QA Contact qa-bugs@suse.de
Found By ---
Blocker ---

A lot of daemons produce log entries like:

type=AVC msg=audit(1424425690.883:716630): apparmor="ALLOWED"
operation="file_mmap" info="Failed name lookup - disconnected path" error=-13
profile="/usr/sbin/httpd2-prefork//null-4172" name="var/run/nscd/passwd"
pid=25333 comm="id" requested_mask="r" denied_mask="r" fsuid=1002 ouid=0

but logprof is not able to parse this entry cause name="var/run/nscd/passwd" is
an invalid entry for it.

So either apparmor produces wrong entries in audid.log or the tool should be
able to handle it!


You are receiving this mail because: