[apparmor] [profile] /etc/cron.daily/logrotate: updated version - new DENIED access.

daniel curtis sidetripping at gmail.com
Mon Jan 30 11:36:01 UTC 2017


Hi Christian

Thank You very much for an answer and looking at this issue. So, everything
is okay and you'll update the logrotate profile, right? Of course, I also
have to add these two rules (instead my proposition with five new rules):

/etc/rc?.d/ r,
/usr/bin/xargs mrix,

Christian, if You would like to "allow the directory listing for all
runlevels, not only S and 2" by using "/etc/rc?.d/" - I would kie to ask if
is it correct? I'm asking just out of curiosity. Should not be there
something like:

/etc/rc*.d/ r,

I'm thinking about using "*", because there are plenty of such folders etc.
For example: "rc0.d", "rc1.d", "rc2.d" and so on. But maybe I'm wrong, and
in this case it's better to use "?", especially if:

? -- can substitute for any single character excepting '/'
* -- can substitute for any number of characters, excepting '/'

Thanks, best regards.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.ubuntu.com/archives/apparmor/attachments/20170130/df4a3382/attachment.html>


More information about the AppArmor mailing list