apparmor: Allow cups-browsed to change nice value (CAP_SYS_NICE)
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
cups-filters (Debian) |
New
|
Unknown
|
|||
cups-filters (Ubuntu) |
Triaged
|
Low
|
Till Kamppeter |
Bug Description
In Ubuntu 20.04.1 with *cups-browsed* 1.27.4-1, apparmor prevents `/usr/sbin/
$ sudo dmesg | grep apparmor
[541870.509461] audit: type=1400 audit(160089842
[628298.779668] audit: type=1400 audit(160098485
[714667.424963] audit: type=1400 audit(160107122
Changed in cups (Ubuntu): | |
importance: | Undecided → Low |
Changed in cups-filters (Debian): | |
status: | Unknown → New |
From the manual page capabilities(7):
CAP_SYS_NICE
change the nice value for arbitrary processes;
scheduling policies and priorities for arbitrary processes
(sched_ setscheduler( 2), sched_setparam(2), sched_setattr(2));
ity(2) );
(ioprio_ set(2)) ;
cesses to be migrated to arbitrary nodes;
* Lower the process nice value (nice(2), setpriority(2)) and
* set real-time scheduling policies for calling process, and set
* set CPU affinity for arbitrary processes (sched_setaffin‐
* set I/O scheduling class and priority for arbitrary processes
* apply migrate_pages(2) to arbitrary processes and allow pro‐
* apply move_pages(2) to arbitrary processes;
* use the MPOL_MF_MOVE_ALL flag with mbind(2) and move_pages(2)
No idea, if cups-browsed should be allowed to change the nice value of *arbitrary* processes.