Mailinglist Archive: opensuse-bugs (3354 mails)

< Previous Next >
[Bug 982112] New: Maybe missing entries in apparmor profile for syslog-ng
  • From: bugzilla_noreply@xxxxxxxxxx
  • Date: Fri, 27 May 2016 21:59:36 +0000
  • Message-id: <bug-982112-21960@http.bugzilla.opensuse.org/>
http://bugzilla.opensuse.org/show_bug.cgi?id=982112


Bug ID: 982112
Summary: Maybe missing entries in apparmor profile for
syslog-ng
Classification: openSUSE
Product: openSUSE Distribution
Version: Leap 42.1
Hardware: x86-64
OS: openSUSE 42.1
Status: NEW
Severity: Normal
Priority: P5 - None
Component: Basesystem
Assignee: bnc-team-screening@xxxxxxxxxxxxxxxxxxxxxx
Reporter: ronnypeine@xxxxxx
QA Contact: qa-bugs@xxxxxxx
Found By: ---
Blocker: ---

After upgrading 2 of my systems to openSUSE Leap 42.1 I see the following
entries in my audit.log every 5-10 minutes:
type=AVC msg=audit(1464385501.159:1184): apparmor="DENIED" operation="ptrace"
profile="syslog-ng" pid=7239 comm="syslog-ng"
target=80768C260288FFFF80768C260288FFFF10C489260288FFFF10C489260288FFFF20C489260288FFFF20C489260288FFFF2F02
type=AVC msg=audit(1464385627.924:1206): apparmor="DENIED" operation="open"
profile="syslog-ng" name="/proc/7332/cmdline" pid=11935 comm="syslog-ng"
requested_mask="r" denied_mask="r" fsuid=0 ouid=0
type=AVC msg=audit(1464385627.924:1207): apparmor="DENIED" operation="open"
profile="syslog-ng" name="/proc/7332/loginuid" pid=11935 comm="syslog-ng"
requested_mask="r" denied_mask="r" fsuid=0 ouid=0
type=AVC msg=audit(1464385627.924:1208): apparmor="DENIED" operation="open"
profile="syslog-ng" name="/proc/7332/sessionid" pid=11935 comm="syslog-ng"
requested_mask="r" denied_mask="r" fsuid=0 ouid=0
type=AVC msg=audit(1464385634.588:1212): apparmor="DENIED" operation="capable"
profile="syslog-ng" pid=11936 comm="syslog-ng" capability=19
capname="sys_ptrace"

I looked for the mentioned pids but they are not existing anymore. Seems like a
short start of a process which then does things which are not permitted by the
apparmor profile.

Any idea what this can be? Maybe some missing entries in the syslog-ng apparmor
profile?

Kind regards,
Ronny

--
You are receiving this mail because:
You are on the CC list for the bug.
< Previous Next >
This Thread
  • No further messages