Apparmor denials on configure hook

Bug #1672774 reported by Pat McGowan
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
snapweb
Triaged
Undecided
Unassigned

Bug Description

Tracking edge on amd64 laptop, refresh to get 0.26b1

Mar 14 11:25:19 samsung930X3G /usr/lib/snapd/snapd[3855]: taskrunner.go:353: DEBUG: Running task 3690 on Do: Clean up "snapweb" (159) install
Mar 14 11:25:19 samsung930X3G /usr/lib/snapd/snapd[3855]: taskrunner.go:353: DEBUG: Running task 3691 on Do: Run configure hook of "snapweb" snap if present
Mar 14 11:25:20 samsung930X3G audit[9698]: AVC apparmor="DENIED" operation="create" profile="snap.snapweb.hook.configure" pid=9698 comm="snapctl" family="inet" sock_type="stream" protocol=6 requested_mask="create" denied_mask="create"
Mar 14 11:25:20 samsung930X3G audit[9698]: AVC apparmor="DENIED" operation="create" profile="snap.snapweb.hook.configure" pid=9698 comm="snapctl" family="inet6" sock_type="stream" protocol=6 requested_mask="create" denied_mask="create"
Mar 14 11:25:20 samsung930X3G kernel: audit: type=1400 audit(1489505120.553:8215): apparmor="DENIED" operation="create" profile="snap.snapweb.hook.configure" pid=9698 comm="snapctl" family="inet" sock_type="stream" protocol=6 requested_mask="create" denied_mask="create"
Mar 14 11:25:20 samsung930X3G kernel: audit: type=1400 audit(1489505120.553:8216): apparmor="DENIED" operation="create" profile="snap.snapweb.hook.configure" pid=9698 comm="snapctl" family="inet6" sock_type="stream" protocol=6 requested_mask="create" denied_mask="create"
Mar 14 11:25:20 samsung930X3G kernel: audit: type=1400 audit(1489505120.553:8217): apparmor="DENIED" operation="create" profile="snap.snapweb.hook.configure" pid=9698 comm="snapctl" family="inet6" sock_type="stream" protocol=6 requested_mask="create" denied_mask="create"
Mar 14 11:25:20 samsung930X3G audit[9698]: AVC apparmor="DENIED" operation="create" profile="snap.snapweb.hook.configure" pid=9698 comm="snapctl" family="inet6" sock_type="stream" protocol=6 requested_mask="create" denied_mask="create"
Mar 14 11:25:20 samsung930X3G audit[9698]: AVC apparmor="DENIED" operation="open" profile="snap.snapweb.hook.configure" name="/run/snapd.socket" pid=9698 comm="snapctl" requested_mask="wr" denied_mask="wr" fsuid=0 ouid=0
Mar 14 11:25:20 samsung930X3G kernel: audit: type=1400 audit(1489505120.565:8218): apparmor="DENIED" operation="open" profile="snap.snapweb.hook.configure" name="/run/snapd.socket" pid=9698 comm="snapctl" requested_mask="wr" denied_mask="wr" fsuid=0 ouid=0
Mar 14 11:25:20 samsung930X3G /usr/lib/snapd/snapd[3855]: daemon.go:176: DEBUG: @ POST /v2/snapctl 8.583434ms 200
Mar 14 11:25:20 samsung930X3G audit[9705]: AVC apparmor="DENIED" operation="create" profile="snap.snapweb.hook.configure" pid=9705 comm="snapctl" family="inet" sock_type="stream" protocol=6 requested_mask="create" denied_mask="create"
Mar 14 11:25:20 samsung930X3G audit[9705]: AVC apparmor="DENIED" operation="create" profile="snap.snapweb.hook.configure" pid=9705 comm="snapctl" family="inet6" sock_type="stream" protocol=6 requested_mask="create" denied_mask="create"
Mar 14 11:25:20 samsung930X3G audit[9705]: AVC apparmor="DENIED" operation="create" profile="snap.snapweb.hook.configure" pid=9705 comm="snapctl" family="inet6" sock_type="stream" protocol=6 requested_mask="create" denied_mask="create"
Mar 14 11:25:20 samsung930X3G audit[9705]: AVC apparmor="DENIED" operation="open" profile="snap.snapweb.hook.configure" name="/run/snapd.socket" pid=9705 comm="snapctl" requested_mask="wr" denied_mask="wr" fsuid=0 ouid=0
Mar 14 11:25:20 samsung930X3G /usr/lib/snapd/snapd[3855]: daemon.go:176: DEBUG: @ POST /v2/snapctl 191.686µs 200
Mar 14 11:25:20 samsung930X3G kernel: audit: type=1400 audit(1489505120.581:8219): apparmor="DENIED" operation="create" profile="snap.snapweb.hook.configure" pid=9705 comm="snapctl" family="inet" sock_type="stream" protocol=6 requested_mask="create" denied_mask="create"
Mar 14 11:25:20 samsung930X3G kernel: audit: type=1400 audit(1489505120.581:8220): apparmor="DENIED" operation="create" profile="snap.snapweb.hook.configure" pid=9705 comm="snapctl" family="inet6" sock_type="stream" protocol=6 requested_mask="create" denied_mask="create"
Mar 14 11:25:20 samsung930X3G kernel: audit: type=1400 audit(1489505120.581:8221): apparmor="DENIED" operation="create" profile="snap.snapweb.hook.configure" pid=9705 comm="snapctl" family="inet6" sock_type="stream" protocol=6 requested_mask="create" denied_mask="create"

Revision history for this message
Pat McGowan (pat-mcgowan) wrote :

ubuntu-personal-store snap had similar denials

Revision history for this message
Zygmunt Krynicki (zyga) wrote :

Those look like go's internal bootstrap trying to check if it has ipv6 connectivity. We ran into this issue earlier (this is a dupe of another bug) but weren't able to come up with any solutions.

Changed in snapweb:
status: New → Triaged
Revision history for this message
Alexandre Abreu (abreu-alexandre) wrote :

@zyga: do you have a ref for the other bug you mentioned?

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.