Verify on jammy: PASS
=====================

#### 2.76.3+ubuntu22.04.1

```
snap version --verbose
snap            2.76.3+ubuntu22.04.1
snapd           2.76.3+ubuntu22.04.1
series          16
ubuntu          22.04
kernel          5.15.0-198-generic
architecture    amd64
snapd-bin-from  native-package
snap-bin-from   native-package

snap run test-snapd-sh-core26.sh -c 'cat /proc/self/smaps_rollup'
cat: /proc/self/smaps_rollup: Permission denied

grep -n smaps_rollup 
/var/lib/snapd/apparmor/profiles/snap.test-snapd-sh-core26.sh
(no rule)

journalctl -b | grep smaps_rollup
Oct 08 17:27:38 sru-2160691-jammy audit[498547]: AVC apparmor="DENIED" 
operation="open" profile="snap.test-snapd-sh-core26.sh" 
name="/proc/498547/smaps_rollup" pid=498547 comm="cat" requested_mask="r" 
denied_mask="r" fsuid=0 ouid=0
```

#### 2.77.1+ubuntu22.04 from jammy-proposed

```
snap version --verbose
snap            2.77.1+ubuntu22.04
snapd           2.77.1+ubuntu22.04
series          16
ubuntu          22.04
kernel          5.15.0-198-generic
architecture    amd64
snapd-bin-from  native-package
snap-bin-from   native-package

grep -n smaps_rollup 
/var/lib/snapd/apparmor/profiles/snap.test-snapd-sh-core26.sh
221:  @{PROC}/@{pid}/smaps_rollup r,

snap run test-snapd-sh-core26.sh -c 'cat /proc/self/smaps_rollup'
555e33806000-7fffc4fa3000 ---p 00000000 00:00 0                          
[rollup]
Rss:                7248 kB
Pss:                6514 kB
...
```

No further smaps_rollup denials after the upgrade. The allow rule is the
snap's own pid only.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2110510

Title:
  New AppArmor logspam under snap v136.0.7103.92

To manage notifications about this bug go to:
https://bugs.launchpad.net/snapd/+bug/2110510/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to