Your message dated Mon, 20 Nov 2023 22:19:16 +0000
with message-id <[email protected]>
and subject line Bug#1056313: fixed in network-manager 1.44.2-5
has caused the Debian Bug report #1056313,
regarding isc-dhcp-client causes AppArmor denials for  
/usr/libexec/nm-dhcp-helper
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1056313: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1056313
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: network-manager
Version: 1.44.2-4
Severity: grave
Justification: renders package unusable

Just after the upgrade of network-manager from 1.44.2-1 to 1.44.2-4,
my network is down.

In the journalctl logs, I can see

[...]
Nov 20 12:08:58 cventin NetworkManager[286424]: <info>  [1700478538.0092] 
policy: auto-activating connection 'Wired connection 1' 
(c89d3bc3-8d9e-44f8-ac86-7e6884d08219)
Nov 20 12:08:58 cventin NetworkManager[286424]: <info>  [1700478538.0098] 
device (enp0s25): Activation: starting connection 'Wired connection 1' 
(c89d3bc3-8d9e-44f8-ac86-7e6884d08219)
Nov 20 12:08:58 cventin NetworkManager[286424]: <info>  [1700478538.0099] 
device (enp0s25): state change: disconnected -> prepare (reason 'none', 
sys-iface-state: 'managed')
Nov 20 12:08:58 cventin NetworkManager[286424]: <info>  [1700478538.0103] 
manager: NetworkManager state is now CONNECTING
Nov 20 12:08:58 cventin NetworkManager[286424]: <info>  [1700478538.0106] 
device (enp0s25): state change: prepare -> config (reason 'none', 
sys-iface-state: 'managed')
Nov 20 12:08:58 cventin NetworkManager[286424]: <info>  [1700478538.0116] 
device (enp0s25): state change: config -> ip-config (reason 'none', 
sys-iface-state: 'managed')
Nov 20 12:08:58 cventin NetworkManager[286424]: <info>  [1700478538.0122] dhcp4 
(enp0s25): activation: beginning transaction (timeout in 45 seconds)
Nov 20 12:08:58 cventin NetworkManager[286424]: <info>  [1700478538.0158] dhcp4 
(enp0s25): dhclient started with pid 294230
Nov 20 12:08:58 cventin avahi-daemon[758]: Joining mDNS multicast group on 
interface enp0s25.IPv6 with address fe80::9a90:96ff:febd:7ff7.
Nov 20 12:08:58 cventin avahi-daemon[758]: New relevant interface enp0s25.IPv6 
for mDNS.
Nov 20 12:08:58 cventin avahi-daemon[758]: Registering new address record for 
fe80::9a90:96ff:febd:7ff7 on enp0s25.*.
Nov 20 12:08:58 cventin dhclient[294231]: execve (/usr/libexec/nm-dhcp-helper, 
...): Permission denied
Nov 20 12:08:58 cventin kernel: audit: type=1400 audit(1700478538.018:40): 
apparmor="DENIED" operation="exec" class="file" profile="/{,usr/}sbin/dhclient" 
name="/usr/libexec/nm-dhcp-helper" pid=294231 comm="dhclient" 
requested_mask="x" denied_mask="x" fsuid=0 ouid=0
Nov 20 12:08:58 cventin dhclient[294230]: DHCPREQUEST for 140.77.13.17 on 
enp0s25 to 255.255.255.255 port 67
Nov 20 12:08:58 cventin dhclient[294230]: DHCPACK of 140.77.13.17 from 
140.77.1.11
Nov 20 12:08:58 cventin dhclient[294233]: execve (/usr/libexec/nm-dhcp-helper, 
...): Permission denied
Nov 20 12:08:58 cventin kernel: audit: type=1400 audit(1700478538.042:41): 
apparmor="DENIED" operation="exec" class="file" profile="/{,usr/}sbin/dhclient" 
name="/usr/libexec/nm-dhcp-helper" pid=294233 comm="dhclient" 
requested_mask="x" denied_mask="x" fsuid=0 ouid=0
Nov 20 12:08:58 cventin dhclient[294230]: bound to 140.77.13.17 -- renewal in 
36738 seconds.
[...]

The issue disappeared after downgrading back to 1.44.2-1.

Note: the errors about /usr/libexec/nm-dhcp-helper changed to

Nov 20 12:17:42 cventin dhclient[295468]: execve (/usr/libexec/nm-dhcp-helper, 
...): No such file or directory

but the network is working. I don't whether this is related, though.

-- System Information:
Debian Release: trixie/sid
  APT prefers unstable-debug
  APT policy: (500, 'unstable-debug'), (500, 'stable-updates'), (500, 
'stable-security'), (500, 'stable-debug'), (500, 'proposed-updates-debug'), 
(500, 'unstable'), (500, 'testing'), (500, 'stable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.5.0-4-amd64 (SMP w/12 CPU threads; PREEMPT)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE, 
TAINT_UNSIGNED_MODULE
Locale: LANG=POSIX, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages network-manager depends on:
ii  adduser                         3.137
ii  dbus [default-dbus-system-bus]  1.14.10-3
ii  libaudit1                       1:3.1.1-1
ii  libbluetooth3                   5.70-1
ii  libc6                           2.37-12
ii  libcurl3-gnutls                 8.4.0-2
ii  libglib2.0-0                    2.78.1-4
ii  libgnutls30                     3.8.1-4+b1
ii  libjansson4                     2.14-2
ii  libmm-glib0                     1.22.0-1
ii  libndp0                         1.8-1
ii  libnewt0.52                     0.52.24-1
ii  libnm0                          1.44.2-4
ii  libpsl5                         0.21.2-1+b1
ii  libreadline8                    8.2-1.3
ii  libselinux1                     3.5-1
ii  libsystemd0                     254.5-1
ii  libteamdctl0                    1.31-1
ii  libudev1                        254.5-1
ii  polkitd                         123-3
ii  udev                            254.5-1

Versions of packages network-manager recommends:
ii  dnsmasq-base [dnsmasq-base]  2.89-1
ii  libpam-systemd               254.5-1
ii  modemmanager                 1.22.0-1
pn  ppp                          <none>
ii  wireless-regdb               2022.06.06-1
ii  wpasupplicant                2:2.10-15

Versions of packages network-manager suggests:
ii  iptables       1.8.9-2
pn  libteam-utils  <none>

Versions of packages network-manager is related to:
ii  isc-dhcp-client  4.4.3-P1-4

-- no debconf information

-- 
Vincent Lefèvre <[email protected]> - Web: <https://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)

--- End Message ---
--- Begin Message ---
Source: network-manager
Source-Version: 1.44.2-5
Done: Michael Biebl <[email protected]>

We believe that the bug you reported is fixed in the latest version of
network-manager, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Biebl <[email protected]> (supplier of updated network-manager package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Mon, 20 Nov 2023 23:02:41 +0100
Source: network-manager
Architecture: source
Version: 1.44.2-5
Distribution: unstable
Urgency: medium
Maintainer: Utopia Maintenance Team 
<[email protected]>
Changed-By: Michael Biebl <[email protected]>
Closes: 1056313
Changes:
 network-manager (1.44.2-5) unstable; urgency=medium
 .
   * Replace systemd Build-Depends with systemd-dev.
     Only systemd.pc is required during build which is now shipped in
     systemd-dev.
   * Add versioned Breaks against isc-dhcp-client.
     The AppArmor policy in isc-dhcp-client needs to be updated to account
     for the move of the nm-dhcp-helper binary to /usr/libexec.
     (Closes: #1056313)
Checksums-Sha1:
 e08c59efdd987e31e4d6cd666228f553adecc419 3084 network-manager_1.44.2-5.dsc
 216d1e92ec673c3b4796c0813fd90bfb580bb66a 49720 
network-manager_1.44.2-5.debian.tar.xz
 390f16dd11ac25b991e7f30c2ff684f2cd0d1bd5 10180 
network-manager_1.44.2-5_source.buildinfo
Checksums-Sha256:
 a980b4fa3088860deb3203d733aaa8d3ddbf2178ee1e909ae87a46f40f44c5eb 3084 
network-manager_1.44.2-5.dsc
 814b3a5db75ab117aa94ff00ce6be93a69f272886e59be0d2195e30cf3ff1d9f 49720 
network-manager_1.44.2-5.debian.tar.xz
 56fe254433e4152ee5f3f6d1b3a9a617f0286c3ebff0896076c3a8a239a7d4d5 10180 
network-manager_1.44.2-5_source.buildinfo
Files:
 7a7064e8aa79db271e637e02df420495 3084 net optional network-manager_1.44.2-5.dsc
 7bac95d6ce5bfea14c9a6a63552c86d2 49720 net optional 
network-manager_1.44.2-5.debian.tar.xz
 a25e3847b6ae0f1b0d51fcdf9cd70264 10180 net optional 
network-manager_1.44.2-5_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEECbOsLssWnJBDRcxUauHfDWCPItwFAmVb2FsACgkQauHfDWCP
ItzMEg//QgzHMKDg5fHItgDoCfeufIe+YnAtuwGmNe4joecpfY+RLakVhqFfmsKM
L9JrXO/gzNNWHnekzzEGpudNNmilQA4enCvdkvV/UVLrd9SDNNeATgsJrd/OknlZ
aXFaMZ6xj3iCPWDtYBs5Z77Fr32f9G4VDI5LpI5zRK3CYTPIrmaHXElQfzcfwjMY
bfMMkQn7Ex2Mw3a2KxIEYjMP6/aubbpiVwg89oovCd3Gb75sv4ppuFYiPWNSxWoL
f0cdt2Rj03gkrzBl1pvVXKUiJuBnsih2i6S0ysm+omU3UM5LlgSmaHvi2gx8+vlO
2Mnnb/bvJQ09OXgt3gRpR6ai8TZbTpyXY5Dpo2c/kYjMEE0r0FrxCIn+hnNtGjOI
EKgQShuOolBO2qAhZhj02AhRw5ZKXd8ZPk3NUojThuBkWG9i1MhyOz9XIlXyhhNq
bs30NUUJl6mC5mJjftBmVFsPwvNWnjv8hZDRdZ0+QCsQt24gXm1hoGecnbr+fN1P
haLfpK4GKrsmQ2c1KGY353JSzar6VDO1o4Ak6o+lNGoQfuz60jWLnFfRMLnj9PH+
zhfmsHUqIQtPdai5osZ+5lBdwrgmcjUxMoH2gJitICvuyd42OSYFGvzq91eULDTh
x4HlaKVlHjkBGEYAFHcpQQq/f2U91q4Rx0omhcnCfdTz8OLCDqc=
=e5XI
-----END PGP SIGNATURE-----

--- End Message ---
_______________________________________________
Pkg-utopia-maintainers mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-utopia-maintainers

Reply via email to