The verification of the Stable Release Update for apparmor has completed successfully and the package has now been released to -updates. Subsequently, the Ubuntu Stable Release Updates Team is being unsubscribed and will not receive messages about this bug report. In the event that you encounter a regression using the package from -updates please report a new bug using ubuntu-bug and tag the bug report regression-update so we can easily find any regressions.
-- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1403468 Title: dnsmasq profile incomplete for lxc usage Status in AppArmor Linux application security framework: Fix Released Status in apparmor package in Ubuntu: Fix Released Bug description: [impact] This bug prevents the proper functioning of dnsmasq under lxc [steps to reproduce] 1) install lxc 2) start container, do dns lookups within it 3) with the fix applied, dnsmasq in the host os should not generate apparmor rejections in syslog [regression potential] The change in the patch for this bug is a slight loosening of the apparmor policy for dnsmasq. The risk of an introduced regression is small. [original description] Hi, I am using the dnsmasq profile with lxc, and I am getting DENIED messages like: Dec 16 22:26:58 superstar kernel: [226445.568383] type=1400 audit(1418768818.310:865): apparmor="DENIED" operation="truncate" profile="/usr/sbin/dnsmasq" name="/var/lib/misc/dnsmasq.lxcbr0.leases" pid=1472 comm="dnsmasq" requested_mask="w" denied_mask="w" fsuid=118 ouid=0 Adding rw for that path obviously makes it go away, and seems like a reasonable change. Thanks, James ProblemType: Bug DistroRelease: Ubuntu 14.04 Package: apparmor-profiles 2.8.95~2430-0ubuntu5.1 ProcVersionSignature: Ubuntu 3.13.0-43.72-generic 3.13.11.11 Uname: Linux 3.13.0-43-generic x86_64 ApportVersion: 2.14.1-0ubuntu3.6 Architecture: amd64 CurrentDesktop: Unity Date: Wed Dec 17 11:27:18 2014 PackageArchitecture: all ProcKernelCmdline: BOOT_IMAGE=/vmlinuz-3.13.0-43-generic root=/dev/mapper/hostname--vg-root ro quiet splash vt.handoff=7 SourcePackage: apparmor Syslog: UpgradeStatus: No upgrade log present (probably fresh install) modified.conffile..etc.apparmor.d.usr.sbin.avahi.daemon: [modified] mtime.conffile..etc.apparmor.d.usr.sbin.avahi.daemon: 2014-12-16T20:38:31.370339 mtime.conffile..etc.apparmor.d.usr.sbin.dnsmasq: 2014-12-17T11:21:47.159017 To manage notifications about this bug go to: https://bugs.launchpad.net/apparmor/+bug/1403468/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp