ntp apparmor profile insufficient ipv6 rights

Bug #892332 reported by Keith Johnson
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
ntp (Ubuntu)
Fix Released
Medium
Jamie Strandboge
Lucid
Won't Fix
Undecided
Unassigned
Precise
Fix Released
Medium
Jamie Strandboge

Bug Description

On one of my 10.04LTS systems, ntpd was failing to start with the following error messages. I modified the apparmor profile(/etc/apparmor.d/usr.sbin.ntpd) to add 'network inet6 dgram' and all appears to be well. Please let me know if there is any additional information I can provide that would be of assistance.

Nov 18 15:02:26 evans ntpd[15656]: ntpd 4.2.4p8@1.1612-o Tue Apr 19 07:08:18 UTC 2011 (1)
Nov 18 15:02:26 evans ntpd[15656]: set_process_priority: Leave priority alone: priority_done is <2>
Nov 18 15:02:26 evans ntpd[15656]: precision = 1.000 usec
Nov 18 15:02:26 evans ntpd[15656]: ntp_io: estimated max descriptors: 1024, initial socket boundary: 16
Nov 18 15:02:26 evans ntpd[15656]: Listening on interface #0 wildcard, 0.0.0.0#123 Disabled
Nov 18 15:02:26 evans ntpd[15656]: socket(AF_INET6, SOCK_DGRAM, 0) failed on address ::: Permission denied
Nov 18 15:02:26 evans ntpd[15656]: unexpected error code 13 (not PROTONOSUPPORT|AFNOSUPPORT|FPNOSUPPORT) - exiting
Nov 18 15:02:26 evans kernel: [368207.847994] type=1503 audit(1321646546.846:69): operation="socket_create" pid=15656 parent=13563 profile="/usr/sbin/ntpd" family="inet6" sock_type="dgram" protocol=0

ADDITIONAL INFORMATION:
~$ lsb_release -rd
Description: Ubuntu 10.04.2 LTS
Release: 10.04

~$ apt-cache policy ntp
ntp:
  Installed: 1:4.2.4p8+dfsg-1ubuntu2.1
  Candidate: 1:4.2.4p8+dfsg-1ubuntu2.1
  Version table:
 *** 1:4.2.4p8+dfsg-1ubuntu2.1 0
        500 http://us.archive.ubuntu.com/ubuntu/ lucid-updates/main Packages
        100 /var/lib/dpkg/status
     1:4.2.4p8+dfsg-1ubuntu2 0
        500 http://us.archive.ubuntu.com/ubuntu/ lucid/main Packages

Tags: apparmor

Related branches

Dave Walker (davewalker)
Changed in ntp (Ubuntu):
importance: Undecided → Medium
milestone: none → precise-alpha-1
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for using Ubuntu and reporting a bug. Does adding the following to /etc/apparmor.d/usr.sbin.ntpd fix the problem for you:
  network inet6 dgram,

(you'll need to run 'sudo apparmor_parser -r /etc/apparmor.d/usr.sbin.ntpd' after adjusting the profile)

Changed in ntp (Ubuntu):
assignee: nobody → Jamie Strandboge (jdstrand)
Changed in ntp (Ubuntu Hardy):
status: New → Invalid
Changed in ntp (Ubuntu Lucid):
status: New → Confirmed
Changed in ntp (Ubuntu Precise):
status: New → Confirmed
Revision history for this message
Keith Johnson (kj42) wrote :

Yes, as noted in my original report, adding that line did fix the problem for me.

Changed in ntp (Ubuntu Precise):
status: Confirmed → Triaged
no longer affects: ntp (Ubuntu Hardy)
Changed in ntp (Ubuntu Precise):
milestone: precise-alpha-1 → precise-alpha-2
Changed in ntp (Ubuntu Precise):
status: Triaged → In Progress
Changed in ntp (Ubuntu Precise):
status: In Progress → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package ntp - 1:4.2.6.p3+dfsg-1ubuntu2

---------------
ntp (1:4.2.6.p3+dfsg-1ubuntu2) precise; urgency=low

  * debian/apparmor-profile: adjust for IPv6 (LP: #892332)
 -- Jamie Strandboge <email address hidden> Tue, 03 Jan 2012 17:03:44 -0600

Changed in ntp (Ubuntu Precise):
status: Fix Committed → Fix Released
Revision history for this message
Rolf Leggewie (r0lf) wrote :

lucid has seen the end of its life and is no longer receiving any updates. Marking the lucid task for this ticket as "Won't Fix".

Changed in ntp (Ubuntu Lucid):
status: Confirmed → Won't Fix
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.