Flaw in profile attachment with ** ?

John Johansen john.johansen at canonical.com
Tue Jun 22 16:59:13 BST 2010

On 06/22/2010 04:46 AM, Seth Arnold wrote:
> I'm trying to track down:
> https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/581525
> Short version: /usr/bin/grotty was attached to the profile
> /home/sarnold/Local/Io/**.
 << snip >>

> So my hunch is that ** in profile names is flaky.
That is possible, though it does seem to work in general testing,
and I have not been able to reproduce this bug. :(

There is certainly something strange going on and it seems to be
related to regexs in the profile name and attachment.
> [1] Funny story: I got no video from grub or anything past grub for
> the first five or six reboots, and the machine rebooted on its own
> several times. Oof. (I _really_ should have wondered before why I
> never see grub. That'll be a fun todo item for tomorrow. Sigh.) But at
> some point I finally got a getty that I could use to remove the
> /etc/apparmor.d/etc.init.d.origami file, and after removing _that_,
> then I was finally able to reboot back into X.
On Ubuntu grub is hidden by default.  Hold down the left shift key on boot
to have grub show up.

More information about the AppArmor mailing list