Yeah I checked before, this is all it dumps: Oct 22 15:23:09 newnyx kernel: [20117.151219] type=1503 audit(1287775389.320:44): operation="capable" pid=28057 parent=28042 profile="/usr/sbin/named" name="dac_read_search"
If it's set to 'complain' it doesn't dump anything. > -----Original Message----- > From: [email protected] [mailto:[email protected]] On Behalf > Of Serge Hallyn > Sent: Friday, October 22, 2010 3:11 PM > To: Aaron Bennett > Subject: [Bug 665264] Re: bind chroot not allowed > > Can you see if there is anything in /var/log/kern.log? > > ** Tags added: apparmor > > -- > bind chroot not allowed > https://bugs.launchpad.net/bugs/665264 > You received this bug notification because you are a direct subscriber of the > bug. > > Status in “apparmor” package in Ubuntu: New > > Bug description: > Binary package hint: apparmor > > I have a custom apparmor profile for /usr/sbin/named which allows chroot. > It's attached. With that profile, bind9 fails as follows: > > named: chroot(): Permission denied > > the reason I suspect an apparmor bug is that if I switch to complain mode and > then directly back to enforce mode, it works as follows: > > r...@newnyx:~# complain /usr/sbin/named ; enforce /usr/sbin/named ; > service bind9 start Setting /usr/sbin/named to complain mode. > Setting /usr/sbin/named to enforce mode. > * Starting domain name service... bind9 > [ OK ] > r...@newnyx:~# > > however, any time I restart apparmor it goes right back to not allowing the > chroot. > > I have attached both my apparmor conf for named and a strace -f output. > > To unsubscribe from this bug, go to: > https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/665264/+subs > cribe -- bind chroot not allowed https://bugs.launchpad.net/bugs/665264 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
