Yeah I checked before, this is all it dumps:

Oct 22 15:23:09 newnyx kernel: [20117.151219] type=1503
audit(1287775389.320:44):  operation="capable" pid=28057 parent=28042
profile="/usr/sbin/named" name="dac_read_search"

If it's set to 'complain' it doesn't dump anything.


> -----Original Message-----
> From: [email protected] [mailto:[email protected]] On Behalf
> Of Serge Hallyn
> Sent: Friday, October 22, 2010 3:11 PM
> To: Aaron Bennett
> Subject: [Bug 665264] Re: bind chroot not allowed
> 
> Can you see if there is anything in /var/log/kern.log?
> 
> ** Tags added: apparmor
> 
> --
> bind chroot not allowed
> https://bugs.launchpad.net/bugs/665264
> You received this bug notification because you are a direct subscriber of the
> bug.
> 
> Status in “apparmor” package in Ubuntu: New
> 
> Bug description:
> Binary package hint: apparmor
> 
> I have a custom apparmor profile for /usr/sbin/named which allows chroot.
> It's attached.  With that profile, bind9 fails as follows:
> 
> named: chroot(): Permission denied
> 
> the reason I suspect an apparmor bug is that if I switch to complain mode and
> then directly back to enforce mode, it works as follows:
> 
> r...@newnyx:~# complain /usr/sbin/named ; enforce /usr/sbin/named ;
> service bind9 start Setting /usr/sbin/named to complain mode.
> Setting /usr/sbin/named to enforce mode.
>  * Starting domain name service... bind9
> [ OK ]
> r...@newnyx:~#
> 
> however, any time I restart apparmor it goes right back to not allowing the
> chroot.
> 
> I have attached both my apparmor conf for named and a strace -f output.
> 
> To unsubscribe from this bug, go to:
> https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/665264/+subs
> cribe

-- 
bind chroot not allowed
https://bugs.launchpad.net/bugs/665264
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to