central apparmor profile for net-tools causes hostname -F to fail

Bug #2133738 reported by Lena Voytek
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
AppArmor
New
Unknown
apparmor (Ubuntu)
Triaged
Low
Lena Voytek
net-tools (Ubuntu)
Won't Fix
Undecided
Lena Voytek

Bug Description

hostname -F requires an arbitrary file read in order to grab a hostname from file contents. Currently only a few specific files can be read, including /etc/hostname.

This currently affects the hostname-set-get autopkgtest for net-tools

Lena Voytek (lvoytek)
description: updated
tags: added: server-todo
Changed in apparmor (Ubuntu):
assignee: nobody → Lena Voytek (lvoytek)
Changed in net-tools (Ubuntu):
assignee: nobody → Lena Voytek (lvoytek)
Ryan Lee (rlee287)
tags: added: sec-8110
Revision history for this message
Lena Voytek (lvoytek) wrote :

This did not end up blocking the migration of net-tools in Ubuntu, so the priority is lower. This should still be fixed in some way for hostname -F to work at all though

Changed in net-tools (Ubuntu):
status: New → Won't Fix
Changed in apparmor (Ubuntu):
status: New → Triaged
importance: Undecided → Wishlist
importance: Wishlist → Low
Revision history for this message
Lena Voytek (lvoytek) wrote :

Marked net-tools as wont-fix as the aa profile is located in the apparmor package

Lena Voytek (lvoytek)
affects: net-tools → apparmor
Changed in apparmor:
status: Unknown → New
Revision history for this message
Lena Voytek (lvoytek) wrote :

Awaiting a decision on this from upstream. If nothing else the best workaround would be to include file read allowances to the local hostname aa profile

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.