I am a colleague of Renier Posts's (reinpost) above, and we have since traced the error messages to the following six rules. That is, at least one of them is the culprit - I have not delved into which ones specifically are the cause.
I would like to note bug #2077416 which is a bug pointing out that this message does not provide much detail. In the upstream kernel source code, where this functionality has since been merged, the error message is a bit different because the function has a different name, but it still is the case that pretty much no information is present in the message, forcing folks to go spelunking in their rules to figure out which of them are the cause. I hope that can be fixed, because that would be convenient. Thanks! -a exit,always -F arch=b64 -S kill -k sigkill -a exit,always -F arch=b32 -S kill -k sigkill -a exit,always -F arch=b64 -S tkill -k sigkill -a exit,always -F arch=b32 -S tkill -k sigkill -a exit,always -F arch=b64 -S tgkill -k sigkill -a exit,always -F arch=b32 -S tgkill -k sigkill -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2069464 Title: On Ubuntu 24.04 installed auditd=1:3.1.2-2.1build1, The audit log starts printing on the console the error of audit: error in audit_log_object_context when deactivate apparmor and activate selinux To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/audit/+bug/2069464/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
