![](https://seccdn.libravatar.org/avatar/9435667f7160374bc34a8600b686aecd.jpg?s=120&d=mm&r=g)
07.01.2019 9:34, Per Jessen пишет:
Bonus question: will these files only be used by nscd, or will they be used by "everything"? (In other words, should they be allowed in the nscd profile or in abstractions/nameservice?)
I can only guess - judging by the fact that everything worked without nscd, it is only nscd that has a problem when accessing them. 'getent', for instance, works fine with no apparmor additions. I use this setup on numerous systems, only that one addition.
getent is unconfined. Any program that a) has apparmor profile b) needs to access actual user information beyond static list in /etc/passwd will need this. So I would say it logically should be part of libnss-mysql package (if it exists) as global setting. -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse+owner@opensuse.org