Flaw in profile attachment with ** ?

John Johansen john.johansen at canonical.com
Tue Jun 22 16:59:13 BST 2010


On 06/22/2010 04:46 AM, Seth Arnold wrote:
> I'm trying to track down:
> https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/581525
> 
> Short version: /usr/bin/grotty was attached to the profile
> /home/sarnold/Local/Io/**.
> 
 << snip >>

> 
> 
> So my hunch is that ** in profile names is flaky.
> 
That is possible, though it does seem to work in general testing,
and I have not been able to reproduce this bug. :(

There is certainly something strange going on and it seems to be
related to regexs in the profile name and attachment.
> 
> [1] Funny story: I got no video from grub or anything past grub for
> the first five or six reboots, and the machine rebooted on its own
> several times. Oof. (I _really_ should have wondered before why I
> never see grub. That'll be a fun todo item for tomorrow. Sigh.) But at
> some point I finally got a getty that I could use to remove the
> /etc/apparmor.d/etc.init.d.origami file, and after removing _that_,
> then I was finally able to reboot back into X.
> 
On Ubuntu grub is hidden by default.  Hold down the left shift key on boot
to have grub show up.



More information about the AppArmor mailing list