Hmm, one more this morning but its on the clamd executable
Oct 6 08:10:51 lenovo2 kernel: [160702.723615]
audit(1286349051.332:38): type=1502 operation=inode_permission
requested_mask=r:: denied_mask=r:: name=/proc/28617/status
pid=28617 profile=/usr/sbin/clamd namespace=default
but its
The maverick package has:
./clamav-daemon.postinst.in:apparmor_parser -r -T -W $APP_PROFILE
|| true
./clamav-freshclam.postinst.in:apparmor_parser -r -T -W
$APP_PROFILE || true
Both -T and -W will need to be stripped for hardy and jaunty when doing
the backport. Karmic
@jdstrand: I'm mostly offline the next few days, so please take this as
whatever blessing you need from ubuntu-backporters to upload a fix for
this to hardy and jaunty backports.
--
freshclam apparmor error : type=1502 operation=inode_permission
requested_mask=r:: denied_mask=r::
@jdstrand: would you please have a look at this? This is from hardy-
backports.
--
freshclam apparmour error : type=1502 operation=inode_permission
requested_mask=r:: denied_mask=r:: name=/proc/28071/status
https://bugs.launchpad.net/bugs/655058
You received this bug notification because you
Can you please attach /etc/apparmor.d/usr.bin.freshclam?
** Changed in: clamav (Ubuntu)
Status: New = Incomplete
** Changed in: clamav (Ubuntu)
Assignee: (unassigned) = Jamie Strandboge (jdstrand)
--
freshclam apparmour error : type=1502 operation=inode_permission
cut and paste of the above file
# vim:syntax=apparmor
# Author: Jamie Strandboge ja...@ubuntu.com
# Last Modified: Sun Aug 3 09:39:03 2008
#include tunables/global
/usr/bin/freshclam {
#include abstractions/base
#include abstractions/nameservice
#include abstractions/user-tmp
owner @{PROC}/[0-9]*/status r, is present so this suggests the profile did
not get reloaded on upgrade. What is the output of the following:
$ sudo apparmor_parser -r -T -W /etc/apparmor.d/usr.bin.freshclam
--
freshclam apparmour error : type=1502 operation=inode_permission
requested_mask=r::
Did you see the error in the apt log for the clamav update on the -W
flag, similar with the above command ...
apparmor_parser -r -T -W /etc/apparmor.d/usr.bin.freshclam
apparmor_parser: invalid option -- T
Novell/SUSE AppArmor parser version 2.1
Copyright (C) 1999, 2000, 2003, 2004, 2005, 2006
This worked ( minus -T -W )
apparmor_parser -r /etc/apparmor.d/usr.bin.freshclam
Replacement succeeded for /usr/bin/freshclam.
--
freshclam apparmour error : type=1502 operation=inode_permission
requested_mask=r:: denied_mask=r:: name=/proc/28071/status
dpkg -l apparmor
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Installed/Config-f/Unpacked/Failed-cfg/Half-inst/t-aWait/T-pend
|/ Err?=(none)/Hold/Reinst-required/X=both-problems (Status,Err: uppercase=bad)
||/ Name Version Description
I'm sorry, I forgot that Hardy does not support the -T and -W flags.
After performing this:
$ sudo apparmor_parser -r /etc/apparmor.d/usr.bin.freshclam
do you still see the errors in kern.log? Note you may have to do:
$ sudo sysctl -w kernel.printk_ratelimit=0
to turn off kernel rate limiting.
I caught the lack of -T on Hardy and dropped it. I didn't catch the lack
of -W. Is that in the current package?
--
freshclam apparmour error : type=1502 operation=inode_permission
requested_mask=r:: denied_mask=r:: name=/proc/28071/status
https://bugs.launchpad.net/bugs/655058
You received
Havent seen any errors since the apparmor_parser -r
/etc/apparmor.d/usr.bin.freshclam
-W is not in the help displayed above.
Thanks
--
freshclam apparmour error : type=1502 operation=inode_permission
requested_mask=r:: denied_mask=r:: name=/proc/28071/status
13 matches
Mail list logo