I see that ntp is now using AF_UNSPEC in a number of places. I tried the 
following rules:
  # ntp uses AF_INET, AF_INET6 and AF_UNSPEC
  network dgram,
  network stream,

which should fix it, but still get denials. I then tried all of the following:
  network udp,
  network tcp,
  network dgram,
  network stream,
  network inet,
  network inet6,
  network,

and the kernel is still denying.

-- 
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to ntp in Ubuntu.
https://bugs.launchpad.net/bugs/1546455

Title:
  Many instances of 'apparmor="DENIED" operation="create"
  profile="/usr/sbin/ntpd" pid=15139 comm="ntpd" family="unspec"
  sock_type="dgram" protocol=0' in syslog

Status in apparmor package in Ubuntu:
  Confirmed
Status in ntp package in Ubuntu:
  In Progress

Bug description:
  I just dist-upgraded to this version of ntp which arrived in xenial
  very recently. Since then I'm being constantly spammed with libnotify
  notifications about the following

  Feb 17 09:59:55 raleigh.local kernel: audit: type=1400 
audit(1455703195.606:429): apparmor="DENIED" operation="create" 
profile="/usr/sbin/ntpd" pid=15139 comm="ntpd" family="unspec" 
sock_type="dgram" protocol=0
  Feb 17 09:59:55 raleigh.local kernel: audit: type=1400 
audit(1455703195.606:430): apparmor="DENIED" operation="create" 
profile="/usr/sbin/ntpd" pid=15139 comm="ntpd" family="unspec" 
sock_type="dgram" protocol=0
  Feb 17 09:59:55 raleigh.local kernel: audit: type=1400 
audit(1455703195.606:431): apparmor="DENIED" operation="create" 
profile="/usr/sbin/ntpd" pid=15139 comm="ntpd" family="unspec" 
sock_type="dgram" protocol=0
  Feb 17 09:59:55 raleigh.local kernel: audit: type=1400 
audit(1455703195.606:432): apparmor="DENIED" operation="create" 
profile="/usr/sbin/ntpd" pid=15139 comm="ntpd" family="unspec" 
sock_type="dgram" protocol=0
  Feb 17 09:59:55 raleigh.local kernel: audit: type=1400 
audit(1455703195.606:433): apparmor="DENIED" operation="create" 
profile="/usr/sbin/ntpd" pid=15139 comm="ntpd" family="unspec" 
sock_type="dgram" protocol=0
  […]
  Feb 17 09:59:59 raleigh.local kernel: audit: type=1400 
audit(1455703199.526:434): apparmor="DENIED" operation="create" 
profile="/usr/sbin/ntpd" pid=15139 comm="ntpd" family="unspec" 
sock_type="dgram" protocol=0
  Feb 17 09:59:59 raleigh.local kernel: audit: type=1400 
audit(1455703199.526:435): apparmor="DENIED" operation="create" 
profile="/usr/sbin/ntpd" pid=15139 comm="ntpd" family="unspec" 
sock_type="dgram" protocol=0
  Feb 17 09:59:59 raleigh.local kernel: audit: type=1400 
audit(1455703199.526:436): apparmor="DENIED" operation="create" 
profile="/usr/sbin/ntpd" pid=15139 comm="ntpd" family="unspec" 
sock_type="dgram" protocol=0
  Feb 17 09:59:59 raleigh.local kernel: audit: type=1400 
audit(1455703199.526:437): apparmor="DENIED" operation="create" 
profile="/usr/sbin/ntpd" pid=15139 comm="ntpd" family="unspec" 
sock_type="dgram" protocol=0
  Feb 17 09:59:59 raleigh.local kernel: audit: type=1400 
audit(1455703199.526:438): apparmor="DENIED" operation="create" 
profile="/usr/sbin/ntpd" pid=15139 comm="ntpd" family="unspec" 
sock_type="dgram" protocol=0

  argh!

  ProblemType: Bug
  DistroRelease: Ubuntu 16.04
  Package: ntp 1:4.2.8p4+dfsg-3ubuntu1
  ProcVersionSignature: Ubuntu 4.4.0-2.16-generic 4.4.0
  Uname: Linux 4.4.0-2-generic x86_64
  NonfreeKernelModules: nvidia_uvm nvidia
  ApportVersion: 2.20-0ubuntu3
  Architecture: amd64
  CurrentDesktop: Unity
  Date: Wed Feb 17 09:57:02 2016
  InstallationDate: Installed on 2012-10-07 (1227 days ago)
  InstallationMedia: Ubuntu 12.10 "Quantal Quetzal" - Beta amd64 (20121007)
  SourcePackage: ntp
  UpgradeStatus: Upgraded to xenial on 2013-05-07 (1016 days ago)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1546455/+subscriptions

-- 
Mailing list: https://launchpad.net/~touch-packages
Post to     : touch-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~touch-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to