swanctl apparmor DENIED on ppc64el LXD
Bug #1999935 reported by
Andreas Hasenack
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
strongswan (Ubuntu) |
Fix Released
|
Undecided
|
Andreas Hasenack |
Bug Description
Given a very peculiar set of conditions, swanctl will segfault because apparmor will deny its execution on a ppc64el lunar LXD:
root@l1:~# swanctl
Segmentation fault
[Fri Dec 16 18:55:58 2022] audit: type=1400 audit(167121695
This was flagged in the new DEP8 test I added to this package in the lunar cycle:
This does not happen in other architectures in lunar, just ppc64el.
Adding the "m" flag to the swanctl binary rule fixes the issue.
To post a comment you must log in.
This bug was fixed in the package strongswan - 5.9.8-3ubuntu2
---------------
strongswan (5.9.8-3ubuntu2) lunar; urgency=medium
* d/usr.sbin.swanctl: allow "m" flag for /usr/sbin/swanctl
(LP: #1999935)
-- Andreas Hasenack <email address hidden> Fri, 16 Dec 2022 16:07:51 -0300