rsyslog apparmor denial on reading /proc/sys/net/ipv6/conf/all/disable_ipv6
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
apparmor (Ubuntu) |
New
|
Undecided
|
Unassigned | ||
rsyslog (Ubuntu) |
New
|
Undecided
|
Unassigned |
Bug Description
One of our Cockpit integration tests [1] spotted an AppArmor regression in rsyslogd. This is coincidental, the test passes and it doesn't do anything with rsyslogd -- just something happens to happen in the background to trigger this (and I can actually reproduce it locally quite reliably).
Mar 08 10:48:20 m1.cockpit.lan systemd[1]: dpkg-db-
Mar 08 10:48:20 m1.cockpit.lan systemd[1]: Finished dpkg-db-
Mar 08 10:48:20 m1.cockpit.lan systemd[1]: rsyslog.service: Sent signal SIGHUP to main process 752 (rsyslogd) on client request.
Mar 08 10:48:20 m1.cockpit.lan kernel: audit: type=1400 audit(161520050
Mar 08 10:48:20 m1.cockpit.lan kernel: audit: type=1400 audit(161520050
This happens on current Ubuntu 24.04 LTS noble devel, rsyslog 8.2312.0-3ubuntu8 and apparmor 4.0.0-beta3-
[1] https:/
[2] https:/