[Bug 421728] New: AppArmor prevents some network utilities from accessing avahi-daemon socket
https://bugzilla.novell.com/show_bug.cgi?id=421728 Summary: AppArmor prevents some network utilities from accessing avahi-daemon socket Product: openSUSE 11.1 Version: Alpha 2 Platform: Other OS/Version: Other Status: NEW Severity: Minor Priority: P5 - None Component: AppArmor AssignedTo: jjohansen@novell.com ReportedBy: receive-spam@yandex.ru QAContact: qa@suse.de Found By: --- By default, AppArmor configuration from apparmor-profiles package allows "dangerous" network utilites (like ping) to access /var/run/mdnsd and /etc/nss_mdns.conf (which is for mDNS lookups via mDNSResponder), but does not provide access to /var/run/avahi-daemon/socket. It prevents ping, traceroute, etc. from mDNS lookups via libnss_dns. Since mDNSResponder is obsolete and has been replaced with Avahi, it's only natural to correct AppArmor rules so that network utilities could access Avahi's socket for mDNS lookups. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=421728 User jeffm@novell.com added comment https://bugzilla.novell.com/show_bug.cgi?id=421728#c2 Jeff Mahoney <jeffm@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |NEEDINFO Info Provider| |receive-spam@yandex.ru --- Comment #2 from Jeff Mahoney <jeffm@novell.com> 2009-02-11 13:23:48 MST --- Can you give me a test case that demonstrates this problem? Does it still occur in 11.1? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=421728 User receive-spam@yandex.ru added comment https://bugzilla.novell.com/show_bug.cgi?id=421728#c3 Arseniy Lartsev <receive-spam@yandex.ru> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEEDINFO |RESOLVED Info Provider|receive-spam@yandex.ru | Resolution| |FIXED --- Comment #3 from Arseniy Lartsev <receive-spam@yandex.ru> 2009-02-12 06:17:53 MST --- (In reply to comment #2)
Does it still occur in 11.1?
No, it doesn't. Somebody has silently fixed it in /etc/apparmor.d/abstractions/nameservice. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=421728 User jeffm@novell.com added comment https://bugzilla.novell.com/show_bug.cgi?id=421728#c4 --- Comment #4 from Jeff Mahoney <jeffm@novell.com> 2009-02-12 07:57:55 MST --- Great, thanks. That seems to be the case with a number of open AppArmor bugs. Thanks for the quick testing and feedback. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com