Verify on noble: PASS
=====================

#### 2.76.3+ubuntu24.04

```
snap version --verbose
snap            2.76.3+ubuntu24.04
snapd           2.76.3+ubuntu24.04
series          16
ubuntu          24.04
kernel          6.8.0-142-generic
architecture    amd64
snapd-bin-from  native-package
snap-bin-from   native-package

snap run test-snapd-sh-core26.sh -c 'cat /proc/self/smaps_rollup'
cat: /proc/self/smaps_rollup: Permission denied

grep -n smaps_rollup 
/var/lib/snapd/apparmor/profiles/snap.test-snapd-sh-core26.sh
(no rule)

journalctl -b | grep smaps_rollup
Oct 08 17:27:38 sru-2160691-noble audit[500940]: AVC apparmor="DENIED" 
operation="open" class="file" profile="snap.test-snapd-sh-core26.sh" 
name="/proc/500940/smaps_rollup" pid=500940 comm="cat" requested_mask="r" 
denied_mask="r" fsuid=0 ouid=0
```

#### 2.77.1+ubuntu24.04 from noble-proposed

```
snap version --verbose
snap            2.77.1+ubuntu24.04
snapd           2.77.1+ubuntu24.04
series          16
ubuntu          24.04
kernel          6.8.0-142-generic
architecture    amd64
snapd-bin-from  native-package
snap-bin-from   native-package

grep -n smaps_rollup 
/var/lib/snapd/apparmor/profiles/snap.test-snapd-sh-core26.sh
221:  @{PROC}/@{pid}/smaps_rollup r,

snap run test-snapd-sh-core26.sh -c 'cat /proc/self/smaps_rollup'
5c333c2cb000-7fffd9799000 ---p 00000000 00:00 0                          
[rollup]
Rss:                6968 kB
Pss:                6200 kB
...
```

No smaps_rollup denials after the upgrade. The allow rule is the snap's
own pid only.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2110510

Title:
  New AppArmor logspam under snap v136.0.7103.92

To manage notifications about this bug go to:
https://bugs.launchpad.net/snapd/+bug/2110510/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to