[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-31 Thread Launchpad Bug Tracker
This bug was fixed in the package chrony - 3.2-4ubuntu4.1 --- chrony (3.2-4ubuntu4.1) bionic; urgency=medium * debian/usr.sbin.chronyd: - Support all paths suggested in the man page. (LP: #1771028, Closes: #898614) -- Christian Ehrhardt Wed, 23 May 2018 16:22:13 +0200

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-24 Thread  Christian Ehrhardt 
root@b:~# echo "refclock SOCK /var/run/chrony.ttyS0.sock" >> /etc/chrony/chrony.conf root@b:~# systemctl restart chrony Job for chrony.service failed because the control process exited with error code. See "systemctl status chrony.service" and "journalctl -xe" for details. Hitting denies like:

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-23 Thread Robie Basak
Hello Mark, or anyone else affected, Accepted chrony into bionic-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/chrony/3.2-4ubuntu4.1 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-23 Thread  Christian Ehrhardt 
Added a SRU Template and an MP [1] for the SRU changes. [1]: https://code.launchpad.net/~paelzer/ubuntu/+source/chrony/+git/chrony/+merge/346740 ** Description changed: + [Impact] + + * Configurations that are not the default, but suggeste din the man page +hit apparmor denies. Super

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-23 Thread Launchpad Bug Tracker
** Merge proposal linked: https://code.launchpad.net/~paelzer/ubuntu/+source/chrony/+git/chrony/+merge/346740 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1771028 Title: Apparmor profile for

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-23 Thread  Christian Ehrhardt 
With Bionic being an LTS and rather new, even this being "just" a config file entry I think we should provide that to Bionic. I'm prepping an SRU upload ... ** Also affects: chrony (Ubuntu Bionic) Importance: Undecided Status: New ** Changed in: chrony (Ubuntu Bionic) Status:

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-22 Thread Launchpad Bug Tracker
This bug was fixed in the package chrony - 3.3-2ubuntu1 --- chrony (3.3-2ubuntu1) cosmic; urgency=medium * Merge with Debian unstable (LP: #1771061). Remaining changes: - d/chrony.conf: use ubuntu ntp pool and server (LP 1744664) - Set -x as default if unable to set time

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-16 Thread Bug Watch Updater
** Changed in: chrony (Debian) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1771028 Title: Apparmor profile for chronyd needs to allow creation of

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-16 Thread  Christian Ehrhardt 
** Merge proposal linked: https://code.launchpad.net/~paelzer/ubuntu/+source/chrony/+git/chrony/+merge/345498 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1771028 Title: Apparmor profile for

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-16 Thread Launchpad Bug Tracker
** Merge proposal unlinked: https://code.launchpad.net/~paelzer/ubuntu/+source/chrony/+git/chrony/+merge/345498 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1771028 Title: Apparmor profile for

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-15 Thread Bug Watch Updater
** Changed in: chrony (Debian) Status: New => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1771028 Title: Apparmor profile for chronyd needs to allow creation of

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-14 Thread Bug Watch Updater
** Changed in: chrony (Debian) Status: Unknown => New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1771028 Title: Apparmor profile for chronyd needs to allow creation of

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-14 Thread  Christian Ehrhardt 
The Debian maintainer works closely with us on chrony, so I suggested the change I came up with to him as well - linked up as Debian bug tasks. ** Bug watch added: Debian Bug tracker #898614 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=898614 ** Also affects: chrony (Debian) via

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-14 Thread Mark Shuttleworth
Thanks Christian. The SOCK method is a much more accurate (apparently) way for chrony and gpsd to communicate. I do think we need to lock gpsd down as well but that's a separate issue. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-14 Thread Launchpad Bug Tracker
** Merge proposal linked: https://code.launchpad.net/~paelzer/ubuntu/+source/chrony/+git/chrony/+merge/345498 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1771028 Title: Apparmor profile for

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-14 Thread  Christian Ehrhardt 
For SRU later note steps to reproduce: Trigger #1 - add to chrony conf a line like: refclock SOCK /var/run/chrony.ttyS0.sock (does not need gpsd to really attach, so no special HW needed) See Deny in dmesg: [929890.257312] audit: type=1400 audit(1526282225.749:636): apparmor="DENIED"

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-14 Thread  Christian Ehrhardt 
Hi Mark, thanks for the report - we only discussed with peers about gpsd via shm so far. The rule for that would be too open which is why it is disabled with a comment in the apparmor profile atm. For gpsd via tty I'd have expected all chrony files in /var/run/chrony/... as most of them are in

[Bug 1771028] Re: Apparmor profile for chronyd needs to allow creation of /var/run/chrony.tty*.sock

2018-05-14 Thread  Christian Ehrhardt 
FYI (as I wondered if we had GPSD rules already) we adressed some of the HW-access issues already in bug 1751241 , but those are not the same, so no conflict going forward with this bug. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.