ptrace doesnt't trigger/work as expected

Bug #1719471 reported by Christian Ehrhardt  on 2017-09-25
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
apparmor (Ubuntu)
Undecided
Unassigned

Bug Description

Hi,
we looked into a discussion [1] which was triggered by [2].
For Ubunutu all these features existed for quite a while, so since [3] we had [4].

So I was looking into dropping [4] later on in favor of the fix in [1].
But while doing so I was puzzles why things even work.

I discussed with jjohansen and ptrace rules should have a traced and trace "end" of the rule.
Our old change was not as restrictive as the better change now suggested, but it had both ends.
While quickly trying to check on this we found that it actually works with just one side of the rules, but it shouldn't.

Jjohansen said he will look into that and get back to us, this bug is to allow everybody involved to track this.

[1]: https://www.redhat.com/archives/libvir-list/2017-September/msg00844.html
[2]: https://bugzilla.suse.com/show_bug.cgi?id=1058847
[3]: https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1298611
[4]: https://git.launchpad.net/~libvirt-maintainers/ubuntu/+source/libvirt/commit/?h=ubuntu/artful-3.6&id=f614b472657d93e1f6c62afaf6a887bd38384a97

I see more and more ptrace changes in upstream libvirt now that 4.13 is out.
I expect signal related changes when 4.14 is there.

So I beg your pardon for pinging here, having a see a glimpse of your list of bugs - but any chance of updates to this one?

John Johansen (jjohansen) wrote :

signal is actually in 4.13 as well

John Johansen (jjohansen) wrote :

I have not had time to chase this one enough to answer it, yet. It is high on the priority list but it seems that list is growing faster than I can service it lately.

In general I can say ubuntu does have both rules as there are some in the includes. And their is of course the unconfined exception, that is it implicitly already has both rules.

To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers