Apparmor needs execute rights on /usr/bin/gsettings

Bug #1021876 reported by Jean-Louis Dupond
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
telepathy-mission-control-5 (Ubuntu)
Fix Released
Medium
Jamie Strandboge

Bug Description

My dmesg is getting flooded with the following DENIED entries:
[25330.061495] type=1400 audit(1341600140.287:375): apparmor="DENIED" operation="exec" parent=2235 profile="/usr/lib/telepathy/telepathy-*" name="/usr/bin/gsettings" pid=14660 comm="telepathy-haze" requested_mask="x" denied_mask="x" fsuid=1000 ouid=0

Seems like access is needed for /usr/bin/gsettings.

This is on Ubuntu Quantal
---
ApportVersion: 2.2.5-0ubuntu2
Architecture: amd64
DistroRelease: Ubuntu 12.10
InstallationMedia: Ubuntu 11.10 "Oneiric Ocelot" - Alpha amd64 (20110705.1)
Package: telepathy-mission-control-5 1:5.12.0-0ubuntu5
PackageArchitecture: amd64
ProcCmdline: BOOT_IMAGE=/boot/vmlinuz-3.5.0-3-generic root=UUID=af3a67b1-5cbf-48f1-b0b7-0848ae3017b4 ro quiet splash modeset=1 pcie_aspm=force i915.i915_enable_rc6=1 i915.i915_enable_fbc=1 i915.lvds_downclock=1 vt.handoff=7
ProcEnviron:
 LANGUAGE=nl:en_AU:en
 TERM=xterm
 PATH=(custom, no user)
 LANG=nl_BE.UTF-8
 SHELL=/bin/bash
ProcVersionSignature: Ubuntu 3.5.0-3.3-generic 3.5.0-rc5
Tags: quantal apparmor
Uname: Linux 3.5.0-3-generic x86_64
UpgradeStatus: Upgraded to quantal on 2012-06-19 (16 days ago)
UserGroups: adm admin cdrom dialout libvirtd lpadmin plugdev sambashare

description: updated
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for using Ubuntu and filing a bug. Can you use 'apport-collect 1021876' to attach relevant logs and system info?

tags: added: apparmor
Changed in telepathy-mission-control-5 (Ubuntu):
status: New → Incomplete
Revision history for this message
Jean-Louis Dupond (dupondje) wrote : Dependencies.txt

apport information

tags: added: apport-collected quantal
description: updated
Revision history for this message
Jean-Louis Dupond (dupondje) wrote : KernLog.txt

apport information

Revision history for this message
Jean-Louis Dupond (dupondje) wrote : RelatedPackageVersions.txt

apport information

Changed in telepathy-mission-control-5 (Ubuntu):
status: Incomplete → New
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thanks, is there anything unique about your haze usage? How did you set up the account (it might just be changes in telepathy-haze, but I'd like to rule this out).

Changed in telepathy-mission-control-5 (Ubuntu):
status: New → Confirmed
Revision history for this message
Jean-Louis Dupond (dupondje) wrote :

Nothing special, just 3 MSN accounts and one Jabber account.
Noticing this only recently, so must be because of some update :)

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Can you add the following to /etc/apparmor.d/local/usr.lib.telepathy:
  /usr/bin/gsettings ix,

Then run:
$ sudo apparmor_parser -r /etc/apparmor.d/usr.lib.telepathy

and report back if it fixes the problem?

Revision history for this message
Jean-Louis Dupond (dupondje) wrote :

This seems to work fine! No more errors in dmesg.

Changed in telepathy-mission-control-5 (Ubuntu):
status: Confirmed → Triaged
Changed in telepathy-mission-control-5 (Ubuntu):
status: Triaged → In Progress
assignee: nobody → Jamie Strandboge (jdstrand)
importance: Undecided → Medium
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package telepathy-mission-control-5 - 1:5.12.0-0ubuntu6

---------------
telepathy-mission-control-5 (1:5.12.0-0ubuntu6) quantal; urgency=low

  * debian/apparmor-profile:
    - add ix to /usr/bin/gsettings for telepathy-haze (LP: #1021876)
    - use sanitized_helper instead of PUx for skype
 -- Jamie Strandboge <email address hidden> Mon, 09 Jul 2012 07:25:52 -0500

Changed in telepathy-mission-control-5 (Ubuntu):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.