[apparmor] rkhunter profile oddities

2020-07-16 Thread mailinglis...@posteo.de
Hi there! I created a very simple profile to confine rkhunter (version numbers below). This profile contains /** r, to be sure, everything can be read by rkhunter. Despite using /** r, I get plenty of these error messages: Profile: /usr/bin/rkhunter Operation: getattr Name: usr/sbin/ModemMana

Re: [apparmor] rkhunter profile oddities

2020-07-16 Thread John Johansen
On 7/16/20 12:36 PM, mailinglis...@posteo.de wrote: > Hi there! > > I created a very simple profile to confine rkhunter (version numbers below). > > This profile contains /** r, to be sure, everything can be read by > rkhunter. > > Despite using /** r, I get plenty of these error messages: >

Re: [apparmor] rkhunter profile oddities

2020-07-16 Thread Seth Arnold
On Thu, Jul 16, 2020 at 09:36:11PM +0200, mailinglis...@posteo.de wrote: > Instead, as you can see, apparmor reports: >$ > Name: usr/sbin/ModemManager > Name: usr/sbin/NetworkManager >$ >$ > Is this probably an error in rkhunter and not in apparmor? This is because rkhunter is executing in its own

Re: [apparmor] rkhunter profile oddities

2020-07-16 Thread mailinglis...@posteo.de
Am 16.07.20 um 23:51 schrieb Seth Arnold: > On Thu, Jul 16, 2020 at 09:36:11PM +0200, mailinglis...@posteo.de wrote: >> Instead, as you can see, apparmor reports: >> $ >> Name: usr/sbin/ModemManager >> Name: usr/sbin/NetworkManager >> $ >> $ >> Is this probably an error in rkhunter and not in appar