Package: unbound
Version: 1.15.0-8
Severity: normal

When enabling apparmor, unbound fails to start.  From the dmesg:

 audit: type=1400 audit(1651577812.219:369): apparmor="DENIED" \
  operation="mknod" profile="/usr/sbin/unbound" \
  name="/etc/unbound/var/lib/unbound/root.key.68281-0-55cf18ed18a0" \
  pid=68281 comm="unbound" requested_mask="c" denied_mask="c" \
  fsuid=930 ouid=930

from the unbound log:

 unbound: [68281:0] fatal error: could not open autotrust file for writing, \
   /var/lib/unbound/root.key.68281-0-55cf18ed18a0: Permission denied

There are 2 issues there: the wrong apparmor profile and the behavour
of unbound which makes this error to be fatal.

/mjt

Reply via email to