"aa-genprof /usr/sbin/nginx" crashed upon readling a line from a log
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
AppArmor |
New
|
Undecided
|
Unassigned | ||
apparmor (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned |
Bug Description
So (not knowing much about apparmor), to me it looks like AppArmor changed the word "receive" to "reweive" and thought it was a mode.
The entire automatically generated bug report is attached.
Here's my terminal's output:
[root at localhost]
Writing updated profile for /usr/sbin/nginx.
Setting /usr/sbin/nginx to complain mode.
Before you begin, you may wish to check if a
profile already exists for the application you
wish to confine. See the following wiki page for
more information:
http://
Please start the application to be profiled in
another window and exercise its functionality now.
Once completed, select the "Scan" option below in
order to scan the system logs for AppArmor events.
For each AppArmor event, you will be given the
opportunity to choose whether the access should be
allowed or denied.
Profiling: /usr/sbin/nginx
[(S)can system log for AppArmor events] / (F)inish
Reading log entries from /var/log/syslog.
Updating AppArmor profiles in /etc/apparmor.d.
Traceback (most recent call last):
File "/usr/lib/
self.
File "/usr/lib/
e = self.parse_
File "/usr/lib/
raise AppArmorExcepti
apparmor.
During handling of the above exception, another exception occurred:
Traceback (most recent call last):
File "/usr/sbin/
lp_ret = apparmor.
File "/usr/lib/
log = log_reader.
File "/usr/lib/
raise AppArmorBug(ex_msg) # py3-only: from None
apparmor.
This error was caused by the log line:
May 27 12:51:51 localhost kernel: [1896557.253647] audit: type=1400 audit(146431751
An unexpected error occoured!
For details, see /tmp/apparmor-
Please consider reporting a bug at https:/
and attach this file.
information type: | Public → Private Security |
information type: | Private Security → Private |
description: | updated |
information type: | Private → Public |
Thanks root,
This error was caused by the log line: 1.752:362) : apparmor="ALLOWED" operation= "file_perm" profile= "/usr/sbin/ nginx" pid=13215 comm="nginx" laddr=45.32.188.150 lport=443 faddr=101. 174.56. 194 fport=62972 family="inet" sock_type="stream" protocol=6 requested_ mask="receive" denied_ mask="receive"
May 27 12:51:51 tty0 kernel: [1896557.253647] audit: type=1400 audit(146431751