apparmor service not started on fresh install
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
apparmor (Ubuntu) |
Expired
|
Undecided
|
Unassigned |
Bug Description
On fresh install of LXC, apparmor service (a dependency) is not started. In that case, it causes LXC guest startup to fail. apparmor postinstall seems only to configure the service but does not start it:
if [ "$1" = "configure" ] || [ "$1" = "abort-upgrade" ]; then
if [ -x "/etc/init.
fi
fi
To me it is not clear, if this is just an apparmor/lxc combination issue or may affect apparmor installs in general: in later case, machines might be unprotected till the first reboot (which might be quite some time on servers when there are no upstream security fixes requiring reboot).
# lsb_release -rd
Description: Ubuntu 16.04 LTS
Release: 16.04
# apt-cache policy apparmor
apparmor:
Installed: 2.10.95-0ubuntu2
Candidate: 2.10.95-0ubuntu2
Version table:
*** 2.10.95-0ubuntu2 500
500 http://
100 /var/lib/
information type: | Private Security → Public Security |
affects: | ubuntu → apparmor (Ubuntu) |
Changed in apparmor (Ubuntu): | |
status: | Expired → Won't Fix |
status: | Won't Fix → New |
Status immediately after install:
# systemctl status apparmor.service d/apparmor; bad; vendor preset: enabled) sysv-generator( 8)
● apparmor.service - LSB: AppArmor initialization
Loaded: loaded (/etc/init.
Active: inactive (dead)
Docs: man:systemd-
Jun 21 07:44:20 hostname systemd[1]: apparmor.service: Unit cannot be reloaded because it is inactive.
Status after reboot:
# systemctl status apparmor.service d/apparmor; bad; vendor preset: enabled) sysv-generator( 8)
● apparmor.service - LSB: AppArmor initialization
Loaded: loaded (/etc/init.
Active: active (exited) since Tue 2016-06-21 07:48:37 UTC; 51s ago
Docs: man:systemd-
Tasks: 0
Memory: 0B
CPU: 0
Jun 21 07:48:37 hostname systemd[1]: Starting LSB: AppArmor initialization... d/disa
Jun 21 07:48:37 hostname apparmor[369]: * Starting AppArmor profiles
Jun 21 07:48:37 hostname apparmor[369]: Skipping profile in /etc/apparmor.
Jun 21 07:48:37 hostname apparmor[369]: ...done.
Jun 21 07:48:37 hostname systemd[1]: Started LSB: AppArmor initialization.
lines 1-13/13 (END)