Using tor 0.2.9.9-1ubuntu1 with Linux 4.10.0-9-generic on Zesty, tor fails to start after installing the tor package. "systemctl status tor@default" reports:
Mar 06 16:04:00 zesty systemd[1]: <email address hidden>: Main process exited, code=killed, status=11/SEGV
Mar 06 16:04:00 zesty systemd[1]: Failed to start Anonymizing overlay network for TCP.
Mar 06 16:04:00 zesty systemd[1]: <email address hidden>: Unit entered failed state.
Mar 06 16:04:00 zesty systemd[1]: <email address hidden>: Failed with result 'signal'.
Workaround: add the following two lines to /etc/apparmor.d/system_tor:
/usr/bin/tor m,
/run/systemd/journal/stdout rw,
I couldn't remember how to that that profile reloaded, so I rebooted, and after the reboot tor does start up successfully. "systemctl tor@default" reports it as running.
I haven't checked to see if only one or other rule is actually required.
Importance -> High since this bug makes the package unusable in its default configuration on Zesty. Since the AppArmor profile comes from Debian's 0.2.9.9-1, this should probably be fixed in Debian.
Using tor 0.2.9.9-1ubuntu1 with Linux 4.10.0-9-generic on Zesty, tor fails to start after installing the tor package. "systemctl status tor@default" reports:
Mar 06 16:04:00 zesty systemd[1]: <email address hidden>: Main process exited, code=killed, status=11/SEGV
Mar 06 16:04:00 zesty systemd[1]: Failed to start Anonymizing overlay network for TCP.
Mar 06 16:04:00 zesty systemd[1]: <email address hidden>: Unit entered failed state.
Mar 06 16:04:00 zesty systemd[1]: <email address hidden>: Failed with result 'signal'.
There are two AppArmor denials in the kernel log:
Mar 6 15:53:12 zesty-test kernel: [ 102.699647] audit: type=1400 audit(148881559 2.268:35) : apparmor="DENIED" operation= "file_inherit" namespace= "root// lxd-zesty_ <var-lib- lxd>" profile= "system_ tor" name="/ run/systemd/ journal/ stdout" pid=3520 comm="tor" requested_mask="wr" denied_mask="wr" fsuid=100000 ouid=100000
Mar 6 15:53:12 zesty-test kernel: [ 102.702418] audit: type=1400 audit(148881559 2.272:37) : apparmor="DENIED" operation= "file_mmap" namespace= "root// lxd-zesty_ <var-lib- lxd>" profile= "system_ tor" name="/usr/bin/tor" pid=3520 comm="tor" requested_mask="m" denied_mask="m" fsuid=100000 ouid=100000
Workaround: add the following two lines to /etc/apparmor. d/system_ tor:
/usr/bin/tor m, journal/ stdout rw,
/run/systemd/
I couldn't remember how to that that profile reloaded, so I rebooted, and after the reboot tor does start up successfully. "systemctl tor@default" reports it as running.
I haven't checked to see if only one or other rule is actually required.
Importance -> High since this bug makes the package unusable in its default configuration on Zesty. Since the AppArmor profile comes from Debian's 0.2.9.9-1, this should probably be fixed in Debian.