denial for creating /run/user/32011/scopes/leaf-net/

Bug #1378805 reported by Jamie Strandboge
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Canonical System Image
Fix Released
Undecided
Unassigned
unity-scopes-api (Ubuntu)
Fix Released
Critical
Michi Henning
Utopic
Fix Released
Undecided
Unassigned

Bug Description

I feel like this bug is known and I thought there was a bug for this, but I can't seem to find it now so filing a new one....

Most scopes are seeing:
apparmor="DENIED" operation="mkdir" profile="com.ubuntu.scopes.youtube_youtube_1.0.13" name="/run/user/32011/scopes/leaf-net/" pid=NNN comm="scoperunner" requested_mask="c" denied_mask="c" fsuid=32011 ouid=32011

Scopes aren't allowed to create /run/user/32011/scopes/leaf-net/ (they are allowed to create their own scopes directory under it). This was mentioned in https://bugs.launchpad.net/unity-scopes-api/+bug/1356409/comments/3 and it was mentioned that this branch may fix it: https://code.launchpad.net/~michihenning/unity-scopes-api/test-before-mkdir/+merge/231110. However, the problem seems to be that nothing is creating that directory at all before the scopes try to create it for themselves. Pete said in the above comment "I think the runtime should probably not be trying to create this while inside confinement, as it will always fail." -- that is precisely the problem. Something unconfined outside of the scopes themselves needs to create it.

Marking rtm14 and Critical-- it is causing a lot of noise in the logs and presumably scopes aren't able to function correctly. Please adjust as needed.

Related branches

Thomas Strehl (strehl-t)
tags: added: touch-2014-10-16
Changed in unity-scopes-api (Ubuntu):
assignee: nobody → Pawel Stolowski (stolowski)
Changed in unity-scopes-api (Ubuntu):
assignee: Pawel Stolowski (stolowski) → nobody
Changed in unity-scopes-api (Ubuntu):
assignee: nobody → Michi Henning (michihenning)
Revision history for this message
Michi Henning (michihenning) wrote :

Thanks for reporting this!

The registry now creates the parent dirs for confined scopes. This should avoid the noise in the logs.

Changed in unity-scopes-api (Ubuntu):
status: New → Fix Committed
Changed in unity-scopes-api (Ubuntu):
status: Fix Committed → In Progress
Changed in unity-scopes-api (Ubuntu):
status: In Progress → Fix Committed
Changed in unity-scopes-api (Ubuntu):
status: Fix Committed → Fix Released
Changed in unity-scopes-api (Ubuntu Utopic):
status: New → Fix Released
tags: added: ota-1
Changed in canonical-devices-system-image:
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.