Complain is not set on nova-compute aa-profile at install time
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Nova Compute Charm |
New
|
Undecided
|
Unassigned |
Bug Description
To workaround LP#1960231 we set:
juju config nova-compute aa-profile-
But when adding new units with:
juju add-unit nova-compute
we see that this is not applied and apparmor status shows:
0 profiles are in complain mode.
7 processes have profiles defined.
7 processes are in enforce mode.
/usr/
/usr/
/usr/
/usr/
/usr/
/snap/
/snap/
0 processes are in complain mode.
To workaround that we had to manually set complain with:
sudo aa-complain /usr/bin/
While this was applied to existing units with the config-change correctly.
At first glance, it appears that the aa-profile-mode is ignored at install time
This affects charm nova-compute rev. 337
description: | updated |
description: | updated |
description: | updated |