apparmor="DENIED" operation="open" class="file" profile="/usr/sbin/chronyd" name="/etc/gnutls/config"

Bug #2056747 reported by Martin Pitt
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
chrony (Ubuntu)
New
Undecided
Unassigned
Noble
New
Undecided
Unassigned

Bug Description

Merely booting current noble cloud image with "chrony" installed causes this:

audit: type=1400 audit(1710152842.540:107): apparmor="DENIED" operation="open" class="file" profile="/usr/sbin/chronyd" name="/etc/gnutls/config" pid=878 comm="chronyd" requested_mask="r" denied_mask="r" fsuid=0 ouid=0

It's not harmful, but causes noise in the logs. This is similar to bug #2056739 for libvirt.

apparmor 4.0.0~alpha4-0ubuntu1
chrony 4.5-1ubuntu1
libgnutls30 3.8.3-1ubuntu1

Martin Pitt (pitti)
tags: added: cockpit-test
Revision history for this message
Christian Ehrhardt  (paelzer) wrote :

Hi Martin,
as always thanks for your post FF testing and reports.

Thank you for also filing bug 2056747 - it starts to show that this is a generic thing which probably anything linked against gnutls and being confined will hit.

reverse-depends --release=noble --build-depends libgnutls28-dev | wc -l
182

Unless later decided otherwise I'd think we should not look for many many individual rules but adding it to an abstraction or so, so for now I'd mark these as dups to each other and file it against gnutls as well.

Revision history for this message
Martin Pitt (pitti) wrote :

Absolutely agree, thanks Christian!

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.