Base abstraction for writing to the systemd journal doesn't work
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
AppArmor |
Incomplete
|
Undecided
|
Unassigned |
Bug Description
The base abstractions file contains:
/{,var/
and the usr.lib.dovecot.log profile includes this:
#include <tunables/global>
/usr/lib/
#include <abstractions/base>
#include <abstractions/
/usr/
# Site-specific additions and overrides. See local/README for details.
#include <local/
}
but it doesn't seem to work, despite reloading the profile I get:
Jul 23 11:23:40 a kernel: [69753.983562] audit: type=1400 audit(146926942
Sounds like you'll need to add (attach_ disconnected)
flags=
to your dovecot/log profile.
Interestingly, I've never seen this (I'm using dovecot on several openSUSE servers), so I wonder if it is specific to your system or if we need to adjust the official profile.