btw, not sure why I was using 3.13.0-32 before... I also tested it with the latest, with same result
# uname -a Linux apparmortest 3.13.0-77-generic #121-Ubuntu SMP Wed Jan 20 10:50:42 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux
# tail -f /var/log/audit.log [...] type=AVC msg=audit(1455628235.420:56): apparmor="ALLOWED" operation="exec" profile="/root/tmp/test.bash" pid=1692 comm="test.bash" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/root/tmp/test.bash//null-1" [...]
btw, not sure why I was using 3.13.0-32 before... I also tested it with the latest, with same result
# uname -a
Linux apparmortest 3.13.0-77-generic #121-Ubuntu SMP Wed Jan 20 10:50:42 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux
# tail -f /var/log/audit.log 1455628235. 420:56) : apparmor="ALLOWED" operation="exec" profile= "/root/ tmp/test. bash" pid=1692 comm="test.bash" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target= "/root/ tmp/test. bash//null- 1"
[...]
type=AVC msg=audit(
[...]