/srv/irclogs.ubuntu.com/2024/04/12/#ubuntu-security.txt

=== chris14_ is now known as chris14
=== guiverc2 is now known as guvierc
stigoJust wanted to say that I enjoy the format of the Ubuntu Security Podcast, it gives a nice overview of the latest issues12:08
ahasenackgeorgiag: hi, morning14:50
ahasenackI'm getting this apparmor denied log, and am wondering how to best address it14:50
ahasenack[ter abr 16 17:25:04 2024] audit: type=1400 audit(1712933337.687:2890): apparmor="DENIED" operation="bind" class="net" namespace="root//lxd-n-pro_<var-snap-lxd-common-lxd>" profile="ubuntu_pro_esm_cache_systemctl" pid=348274 comm="systemctl" family="unix" sock_type="stream" protocol=0 requested_mask="bind" denied_mask="bind" addr="@d08132a6b99ec357/bus/systemctl/system"14:50
ahasenack"network unix," sorts it out14:50
ahasenackbut is there something I can do about the "address" perhaps, to limit it to that */bus/systemctl/system" address?14:51
georgiagyep, there are specific unix rules that one would look like: unix bind addr=@*/bus/systemctl/system,14:54
ahasenackso "network unix" plus that?14:54
ahasenackor just that?14:54
georgiagjust that works14:54
ahasenackthanks, trying14:54
ahasenackcan I use unix bind addr=@*/bus/systemctl/*, ? I see two addresses:14:55
ahasenackaddr="@5a483abfca663cfc/bus/systemctl/system"14:55
ahasenackand also14:55
ahasenackaddr="@e85173dd91675953/bus/systemctl/"14:56
ahasenackor just list both?14:56
ahasenacktwo "unix bind" lines14:56
georgiagaddr=@*/bus/systemctl/{,system} seems more strict 14:56
ahasenackdoes this use the normal path globbing rules?14:56
georgiagit does14:56
ahasenackawesome14:57
=== cpaelzer_ is now known as cpaelzer

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!