[apparmor] debugging aa_change_profile

Steve Beattie steve at nxnw.org
Fri Apr 27 06:14:26 UTC 2012


On Thu, Apr 26, 2012 at 04:31:03PM -0700, John Johansen wrote:
> it only needs to be the same value. If you are being killed apparmor
> should be logging what value it sees as being used.

Hrm, with linux-image-3.2.0-21-generic (yes, I need to reboot into the
released 12.04 kernel), I don't see the attempted value being reported
when a process gets killed:

  type=AVC msg=audit(1335506883.709:10343): apparmor="KILLEDAUTO" operation="change_hat" parent=19778 profile="myprofile//myhat" pid=26623 comm="R" target="myprofile"

I suspect I need to file a bug report.

-- 
Steve Beattie
<sbeattie at ubuntu.com>
http://NxNW.org/~steve/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: Digital signature
URL: <https://lists.ubuntu.com/archives/apparmor/attachments/20120426/60429488/attachment.pgp>


More information about the AppArmor mailing list