This bug is awaiting verification that the kernel in -proposed solves
the problem. Please test the kernel and update this bug with the
results. If the problem is solved, change the tag 'verification-needed-
xenial' to 'verification-done-xenial'. If the problem still exists,
change the tag 'verification-needed-xenial' to 'verification-failed-
xenial'.

If verification is not done by 5 working days from today, this fix will
be dropped from the source code, and this bug will be closed.

See https://wiki.ubuntu.com/Testing/EnableProposed for documentation how
to enable and use -proposed. Thank you!


** Tags added: verification-needed-xenial

-- 
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux in Ubuntu.
https://bugs.launchpad.net/bugs/1839037

Title:
  Stacked onexec transitions fail when under NO NEW PRIVS restrictions

Status in linux package in Ubuntu:
  Incomplete
Status in linux source package in Xenial:
  Fix Committed
Status in linux source package in Bionic:
  Fix Committed

Bug description:
  running the apparmor nnp regression tests results in the following
  failure

  Error: transition failed. Test 'NNP (stack onexec - NNP)' was expected
  to 'pass'. Reason for failure 'FAIL - execv: Operation not permitted'

  with a log message of

  [ 1169.863302] audit: type=1400 audit(1565046042.144:280686):
  apparmor="DENIED" operation="exec" info="no new privs" error=-1
  profile="/home/jj/apparmor.git/tests/regression/apparmor/transition"
  name="/home/jj/apparmor.git/tests/regression/apparmor/open" pid=1888
  comm="transition" requested_mask="x" denied_mask="x" fsuid=0 ouid=1000
  target="/home/jj/apparmor.git/tests/regression/apparmor/open"

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1839037/+subscriptions

-- 
Mailing list: https://launchpad.net/~kernel-packages
Post to     : kernel-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~kernel-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to