Did you by chance change anything related to dnsmasq's startup? This
looks like dnsmasq is now starting in a private filesystem namespace
without access to the dbus sockets. It's possible to adapt the AppArmor
profile for this (by adding the attach_disconnected flag to the profile)
but the downside is that AppArmor will then attach all paths not in the
namespace to / which might allow e.g. a chroot etc/shadow to also allow
access to non-chroot /etc/shadow.

Thanks

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1703520

Title:
  DNS resolving doesn't work in complain mode with dnsmasq and apparmor

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1703520/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to