** Description changed:

+ [ Impact ]
+ 
+ AppArmor generates noisy denial logs in CPC's Resolute and Noble testing
+ pipelines. The profile ubuntu_pro_esm_cache_systemd_detect_virt lacks
+ permission for capability perfmon, resulting in audit denials in system
+ logs whenever systemd-detect-virt attempts to check process capability.
+ 
+ The fix is to add capability perfmon to the
+ ubuntu_pro_esm_cache_systemd_detect_virt AppArmor sub-profile.
+ 
+ [ Test Plan ]
+ 
+ On a system running Noble (24.04) or Resolute (26.04) without the fix,
+ trigger esm-cache.service or run systemd-detect-virt under the
+ ubuntu_pro_esm_cache_systemd_detect_virt AppArmor profile.
+ 
+ Check dmesg or journalctl -k and observe the AppArmor denial log:
+ apparmor="DENIED" operation="capable" class="cap" 
profile="ubuntu_pro_esm_cache_systemd_detect_virt" ... capname="perfmon"
+ 
+ Install the updated package from -proposed.
+ 
+ Trigger esm-cache.service or run systemd-detect-virt again.
+ 
+ Check dmesg or journalctl -k and verify that no perfmon AppArmor denials
+ are logged.
+ 
+ [ Where problems could occur ]
+ 
+ Adding permissions to an AppArmor profile brings the risk of allowing
+ more access than intended.
+ 
+ To minimize the concern, capability perfmon is strictly granted to the
+ ubuntu_pro_esm_cache_systemd_detect_virt sub-profile for capability
+ checks required by systemd-detect-virt, without granting extra file or
+ process access.
+ 
+ [ Other Info ]
+ 
+ Here is the original description of the bug:
+ 
  We are seeing an apparmor DENIED audit message in CPC's Resolute and
  Noble testing pipelines:
  
  'Mar 01 21:52:18 alan-resolute-tpqofsymyu kernel: audit: type=1400
  audit(1772401938.245:192): apparmor="DENIED" operation="capable"
  class="cap" profile="ubuntu_pro_esm_cache_systemd_detect_virt" pid=3768
  comm="systemd-detect-" capability=38  capname="perfmon"'
  
- From the apparmor team: That denial is for capabilities (7). It seems that 
`ubuntu_pro_esm_cache_systemd_detect_virt` needs a rule in the following 
syntax: 
-   ```
-   capability perfmon,
-   ```
+ From the apparmor team: That denial is for capabilities (7). It seems that 
`ubuntu_pro_esm_cache_systemd_detect_virt` needs a rule in the following syntax:
+   ```
+   capability perfmon,
+   ```
  
  Locally reproduced with the latest Resolute daily image (https://cloud-
  images.ubuntu.com/resolute/20260221/):
  
  Description:    Ubuntu Resolute Raccoon (development branch)
  Release:        26.04
  
  Package: linux-virtual
  Version: 6.19.0-6.6
  
  Package: systemd
  Version: 259-1ubuntu3
  
  Package: apparmor
  Version: 5.0.0~beta1-0ubuntu2
  
  Logs:
  ubuntu@ubuntu:~$  journalctl --no-pager | grep DENIED
  Mar 04 18:03:59 ubuntu kernel: audit: type=1400 audit(1772647439.196:190): 
apparmor="DENIED" operation="capable" class="cap" 
profile="ubuntu_pro_esm_cache_systemd_detect_virt" pid=1127 
comm="systemd-detect-" capability=38  capname="perfmon"
+ 
+ [ Changelog ]
+ 
+ ubuntu-advantage-tools (38ubuntu0) stonking; urgency=medium
+ 
+   * d/apparmor: add cap perfmon to cloud_id AppArmor profile (LP: #2153472)
+   * d/apparmor: add perfmon systemctl unix socket in AppArmor profiles
+     (LP: #2143251)
+   * d/apparmor: fix denied audit messages when devicetree exists
+     (LP: #2131292)
+   * d/apparmor: include PID directory in ubuntu_pro_esm_cache profile (GH: 
#3555)
+   * d/apparmor: allow /usr/share/coreutils/locales/** in ubuntu_pro_esm_cache
+     profile (GH: #3570)
+   * New upstream release 38:
+     - security:
+       + fix CVE-2026-12391
+       + fix CVE-2026-11386
+       + fix CVE-2026-9494
+     - clouds:
+       + add support for GCE Marketplace Pro licenses (GH: #3573)
+       + add resolute GCP license IDs (GH: #3532)
+       + map aws-gov to aws for correct FIPS flavor (LP: #2144693)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2143251

Title:
  ubuntu_pro_esm_cache_systemd_detect_virt apparmor DENIED audit
  messages for perfmon capability

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/2143251/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to