Discussion:
Bug#1082190: /usr/bin/ping: iputils-ping: Apparmor denial
Add Reply
Laurent Bigonville
2024-09-19 09:10:01 UTC
Reply
Permalink
Package: iputils-ping
Version: 3:20240117-1
Severity: important
File: /usr/bin/ping

Hello,

When running ping, I get the following apparmor denial (well it's in
complain, so nothing is really denied ATM)

type=AVC msg=audit(1726736548.607:760): apparmor="ALLOWED" operation="open" class="file" profile="ping" name="/proc/sys/net/ipv6/conf/all/disable_ipv6" pid=22129 comm="ping" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0FSUID="bigon" OUID="root"
type=SYSCALL msg=audit(1726736548.607:760): arch=c000003e syscall=257 success=yes exit=5 a0=ffffff9c a1=7ffd75b7a670 a2=80100 a3=0 items=0 ppid=22072 pid=22129 auid=1000 uid=1000 gid=1000 euid=1000 suid=1000 fsuid=1000 egid=1000 sgid=1000 fsgid=1000 tty=pts2 ses=3 comm="ping" exe="/usr/bin/ping" subj=ping key=(null)ARCH=x86_64 SYSCALL=openat AUID="bigon" UID="bigon" GID="bigon" EUID="bigon" SUID="bigon" FSUID="bigon" EGID="bigon" SGID="bigon" FSGID="bigon"
type=PROCTITLE msg=audit(1726736548.607:760): proctitle=70696E67007777772E70657264752E636F6D

That still should be fixed I guess

Kind regards,
Laurent Bigonville

-- System Information:
Debian Release: trixie/sid
APT prefers unstable-debug
APT policy: (500, 'unstable-debug'), (500, 'unstable'), (1, 'experimental-debug'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 6.10.9-amd64 (SMP w/12 CPU threads; PREEMPT)
Locale: LANG=fr_BE.UTF-8, LC_CTYPE=fr_BE.UTF-8 (charmap=UTF-8), LANGUAGE=fr_BE:fr
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages iputils-ping depends on:
ii libc6 2.40-2
ii libcap2 1:2.66-5
ii libcap2-bin 1:2.66-5
ii libidn2-0 2.3.7-2

iputils-ping recommends no packages.

iputils-ping suggests no packages.

-- no debconf information
Christian Boltz
2024-09-26 22:10:01 UTC
Reply
Permalink
Hello,

Am Donnerstag, 19. September 2024, 15:15:02 MESZ schrieb Debian Bug
Bug #1082190 [apparmor-profiles] /usr/bin/ping: iputils-ping: Apparmor
denial Added indication that 1082190 affects iputils-ping
I submitted the profile update upstream at
https://gitlab.com/apparmor/apparmor/-/merge_requests/1340


Regards,

Christian Boltz
--
We need to make sure that the direction we're going and the decisions
we're taking are made by people who will suffer the consequences of
them. [Henne Vogelsang in opensuse-project]
Loading...