ntpd daemon request capability "dac_override"

Bug #749727 reported by c
14
This bug affects 2 people
Affects Status Importance Assigned to Milestone
AppArmor
Fix Released
Undecided
Unassigned
NTP
New
Undecided
Unassigned

Bug Description

Environment: Ubuntu Desktop x64 10.10

The following message is observed in syslog

Apr 3 17:47:22 universe kernel: [ 20.235357] type=1400 audit(1301824042.778:24): apparmor="DENIED" operation="capable" parent=1 profile="/usr/sbin/ntpd" pid=1459 comm="ntpd" capability=1 capname="dac_override"

either apparmor security profile is too restrictive or daemon "ntpd" has bug

Revision history for this message
c (lsching17) wrote :
Revision history for this message
c (lsching17) wrote :
Revision history for this message
Seth Arnold (seth-arnold) wrote :

I have a very similar profile and ntp.conf, but don't see the DAC capability requested in my logs; perhaps one of your file permissions is different from mine? Of the files and directories listed in the profile that I thought might have different DAC permissions, here's what mine look like:

-rw-r--r-- 1 root root 1633 2010-08-06 17:36 /etc/ntp.conf
-rw-r--r-- 1 ntp ntp 7 2011-04-03 15:09 /var/lib/ntp/ntp.drift
-rw-r--r-- 1 root root 5 2011-04-03 15:09 /var/run/ntpd.pid
drwxr-xr-x 2 ntp ntp 4096 2010-08-06 17:36 /var/log/ntpstats

What do the permissions look like for your files?

Revision history for this message
c (lsching17) wrote :

mine is same as yours

$ ls -la /etc/ntp.conf
-rw-r--r-- 1 root root 1633 2010-11-15 07:10 /etc/ntp.conf
$ ls -la /var/lib/ntp/ntp.drift
-rw-r--r-- 1 ntp ntp 7 2011-04-04 07:00 /var/lib/ntp/ntp.drift
$ ls -la /var/run/ntpd.pid
-rw-r--r-- 1 root root 4 2011-04-04 06:00 /var/run/ntpd.pid
$ ls -la /var/log/ntpstats
total 8
drwxr-xr-x 2 ntp ntp 4096 2010-08-07 08:36 .
drwxr-xr-x 17 root root 4096 2011-04-04 07:35 ..

Revision history for this message
c (lsching17) wrote :

The entry is just observed once, there is no more similar trace in syslog.

Revision history for this message
c (lsching17) wrote :

The entry is observed again, it seems that it cannot access /var/lib/ntp/ntp.drift.TEMP
syslog attached

Changed in apparmor:
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.