** Description changed: + [ Impact ] + + AppArmor generates noisy denial logs in CPC's Resolute and Noble testing + pipelines. The profile ubuntu_pro_esm_cache_systemd_detect_virt lacks + permission for capability perfmon, resulting in audit denials in system + logs whenever systemd-detect-virt attempts to check process capability. + + The fix is to add capability perfmon to the + ubuntu_pro_esm_cache_systemd_detect_virt AppArmor sub-profile. + + [ Test Plan ] + + On a system running Noble (24.04) or Resolute (26.04) without the fix, + trigger esm-cache.service or run systemd-detect-virt under the + ubuntu_pro_esm_cache_systemd_detect_virt AppArmor profile. + + Check dmesg or journalctl -k and observe the AppArmor denial log: + apparmor="DENIED" operation="capable" class="cap" profile="ubuntu_pro_esm_cache_systemd_detect_virt" ... capname="perfmon" + + Install the updated package from -proposed. + + Trigger esm-cache.service or run systemd-detect-virt again. + + Check dmesg or journalctl -k and verify that no perfmon AppArmor denials + are logged. + + [ Where problems could occur ] + + Adding permissions to an AppArmor profile brings the risk of allowing + more access than intended. + + To minimize the concern, capability perfmon is strictly granted to the + ubuntu_pro_esm_cache_systemd_detect_virt sub-profile for capability + checks required by systemd-detect-virt, without granting extra file or + process access. + + [ Other Info ] + + Here is the original description of the bug: + We are seeing an apparmor DENIED audit message in CPC's Resolute and Noble testing pipelines: 'Mar 01 21:52:18 alan-resolute-tpqofsymyu kernel: audit: type=1400 audit(1772401938.245:192): apparmor="DENIED" operation="capable" class="cap" profile="ubuntu_pro_esm_cache_systemd_detect_virt" pid=3768 comm="systemd-detect-" capability=38 capname="perfmon"' - From the apparmor team: That denial is for capabilities (7). It seems that `ubuntu_pro_esm_cache_systemd_detect_virt` needs a rule in the following syntax: - ``` - capability perfmon, - ``` + From the apparmor team: That denial is for capabilities (7). It seems that `ubuntu_pro_esm_cache_systemd_detect_virt` needs a rule in the following syntax: + ``` + capability perfmon, + ``` Locally reproduced with the latest Resolute daily image (https://cloud- images.ubuntu.com/resolute/20260221/): Description: Ubuntu Resolute Raccoon (development branch) Release: 26.04 Package: linux-virtual Version: 6.19.0-6.6 Package: systemd Version: 259-1ubuntu3 Package: apparmor Version: 5.0.0~beta1-0ubuntu2 Logs: ubuntu@ubuntu:~$ journalctl --no-pager | grep DENIED Mar 04 18:03:59 ubuntu kernel: audit: type=1400 audit(1772647439.196:190): apparmor="DENIED" operation="capable" class="cap" profile="ubuntu_pro_esm_cache_systemd_detect_virt" pid=1127 comm="systemd-detect-" capability=38 capname="perfmon" + + [ Changelog ] + + ubuntu-advantage-tools (38ubuntu0) stonking; urgency=medium + + * d/apparmor: add cap perfmon to cloud_id AppArmor profile (LP: #2153472) + * d/apparmor: add perfmon systemctl unix socket in AppArmor profiles + (LP: #2143251) + * d/apparmor: fix denied audit messages when devicetree exists + (LP: #2131292) + * d/apparmor: include PID directory in ubuntu_pro_esm_cache profile (GH: #3555) + * d/apparmor: allow /usr/share/coreutils/locales/** in ubuntu_pro_esm_cache + profile (GH: #3570) + * New upstream release 38: + - security: + + fix CVE-2026-12391 + + fix CVE-2026-11386 + + fix CVE-2026-9494 + - clouds: + + add support for GCE Marketplace Pro licenses (GH: #3573) + + add resolute GCP license IDs (GH: #3532) + + map aws-gov to aws for correct FIPS flavor (LP: #2144693)
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2143251 Title: ubuntu_pro_esm_cache_systemd_detect_virt apparmor DENIED audit messages for perfmon capability To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/2143251/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
