the rsyslog apparmor profile has a rule for /dev/log, which is a
symlink:

lrwxrwxrwx 1 root root 28 Sep 15 16:39 /dev/log ->
/run/systemd/journal/dev-log

But the base abstraction allows writing to that symlink's target:
/etc/apparmor.d/abstractions/base:  @{run}/systemd/journal/dev-log w,

And the rsyslog profile includes the base abstraction.

** Changed in: rsyslog (Ubuntu)
       Status: New => Incomplete

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2123821

Title:
  bad restriction: apparmor="DENIED" [...] namespace="root//lxd-n_<var-
  snap-lxd-common-lxd>" profile="rsyslogd"
  name="/run/systemd/journal/dev-log"

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2123821/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to