umount fstype=... not mediated
Bug #1613403 reported by
Jamie Strandboge
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
AppArmor |
Confirmed
|
Wishlist
|
Unassigned |
Bug Description
These two rules are accepted by the parser and generate equivalent policy:
umount,
umount fstype=fuse.*,
apparmor.d(5) suggests that fstype should be mediated, but it currently is not. Kernel audit suggests it is not mediated:
kernel: [538611.251087] audit: type=1400 audit(147128643
(note fstype is not listed in the denial).
While I found this while developing snappy policy, the interface in question is privileged anyway and so I don't think this is a critical bug for Ubuntu at this time.
summary: |
- umount fstype=... ignored + umount fstype=... not mediated |
Changed in apparmor: | |
importance: | Undecided → Wishlist |
To post a comment you must log in.
This also affects https:/ /github. com/snapcore/ snapd/pull/ 9547