Comments (6)
I will answer while Alex is busy.
Your options are:
aa-log
(comes with this package)
tail /var/log/audit/audit.log
(requires auditd
package)
tail /var/log/syslog
(requires rsyslog
package)
tail /var/log/messages
dmesg
from apparmor.d.
That's quite extensive. @roddhjav, I could do this.
firefox
[/etc/timezone r,] operation=open comm=firefox-esr
[/tmp/00UAI2.tmp r,] operation=open,rename_src comm=firefox-esr
[@{bin}/speech-dispatcher rx,] path_diffs=/usr/bin operation=exec comm='speechd init'
firefox▶speech-dispatcher
[/etc/speech-dispatcher/clients/ r,] operation=open comm=speech-dispatch
[/etc/speech-dispatcher/clients/emacs.conf r,] operation=open comm=speech-dispatch
[/etc/speech-dispatcher/modules/ r,] operation=open comm=speech-dispatch
[/etc/speech-dispatcher/modules/dtk-generic.conf r,] operation=open comm=speech-dispatch
[/etc/speech-dispatcher/modules/epos-generic.conf r,] operation=open comm=speech-dispatch
[/etc/speech-dispatcher/modules/espeak-mbrola-generic.conf r,] operation=open comm=speech-dispatch
[/etc/speech-dispatcher/modules/espeak-ng-mbrola-generic.conf r,] operation=open comm=speech-dispatch
[/etc/speech-dispatcher/modules/llia_phon-generic.conf r,] operation=open comm=speech-dispatch
[/etc/speech-dispatcher/modules/mary-generic.conf r,] operation=open comm=speech-dispatch
[/etc/speech-dispatcher/modules/mimic3-generic.conf r,] operation=open comm=speech-dispatch
[/etc/speech-dispatcher/modules/swift-generic.conf r,] operation=open comm=speech-dispatch
[/etc/speech-dispatcher/speechd.conf r,] operation=open comm=speech-dispatch
[@{bin}/dash rx,] path_diffs=/usr/bin operation=exec comm=speech-dispatch
[@{bin}/speech-dispatcher r,] path_diffs=/usr/bin operation=file_mmap comm=speech-dispatch
[@{lib}/speech-dispatcher-modules/sd_dummy rx,] path_diffs=/usr/lib operation=exec comm=speech-dispatch
[@{lib}/speech-dispatcher-modules/sd_espeak-ng rx,] path_diffs=/usr/lib operation=exec comm=speech-dispatch
[owner @{run}/user/@{uid}/speech-dispatcher/ c,] path_diffs=/run,1000 operation=mkdir comm=speech-dispatch
[owner @{run}/user/@{uid}/speech-dispatcher/log/ c,] path_diffs=/run,1000 operation=mkdir comm=speech-dispatch
[owner @{run}/user/@{uid}/speech-dispatcher/log/debug/ c,] path_diffs=/run,1000 operation=mkdir comm=speech-dispatch
[owner @{run}/user/@{uid}/speech-dispatcher/log/dummy.log wc,] path_diffs=/run,1000 operation=mknod,open comm=speech-dispatch
[owner @{run}/user/@{uid}/speech-dispatcher/log/espeak-ng-mbrola.log wc,] path_diffs=/run,1000 operation=mknod,open comm=speech-dispatch
[owner @{run}/user/@{uid}/speech-dispatcher/log/espeak-ng.log wc,] path_diffs=/run,1000 operation=mknod,open comm=speech-dispatch
[owner @{run}/user/@{uid}/speech-dispatcher/log/speech-dispatcher.log wc,] path_diffs=/run,1000 operation=file_perm,mknod,open comm=speech-dispatch
[owner @{run}/user/@{uid}/speech-dispatcher/pid/ c,] path_diffs=/run,1000 operation=mkdir comm=speech-dispatch
[owner @{run}/user/@{uid}/speech-dispatcher/pid/speech-dispatcher.pid wdck,] path_diffs=/run,1000 operation=file_lock,mknod,open,unlink comm=speech-dispatch
[owner @{run}/user/@{uid}/speech-dispatcher/speechd.sock c,] path_diffs=/run,1000 operation=mknod comm=speech-dispatch
firefox▶speech-dispatcher▶/usr/lib/speech-dispatcher-modules/sd_dummy
[/dev/shm/ r,] operation=open comm=sd_dummy
[/etc/machine-id r,] operation=open comm=threaded-ml
[/etc/pulse/client.conf r,] operation=open comm=sd_dummy
[/etc/pulse/client.conf.d/ r,] operation=open comm=sd_dummy
[owner @{run}/user/@{uid}/pulse/ r,] path_diffs=/run,1000 operation=open comm=sd_dummy
[owner @{run}/user/@{uid}/speech-dispatcher/log/dummy.log w,] path_diffs=/run,1000 operation=file_inherit comm=sd_dummy
[owner @{run}/user/@{uid}/speech-dispatcher/log/espeak-ng.log w,] path_diffs=/run,1000 operation=file_inherit comm=sd_dummy
[owner @{run}/user/@{uid}/speech-dispatcher/log/speech-dispatcher.log a,] path_diffs=/run,1000 operation=file_inherit comm=sd_dummy
[owner @{run}/user/@{uid}/speech-dispatcher/pid/speech-dispatcher.pid w,] path_diffs=/run,1000 operation=file_inherit comm=sd_dummy
[owner @{user_config_dirs}/pulse/cookie rk,] path_diffs=/home/user/.config operation=file_lock,open comm=threaded-ml
firefox▶speech-dispatcher▶/usr/lib/speech-dispatcher-modules/sd_espeak-ng
[/dev/shm/ r,] operation=open comm=sd_espeak-ng,sd_espeak-ng-mb
[/etc/machine-id r,] operation=open comm=threaded-ml
[/etc/pulse/client.conf r,] operation=open comm=sd_espeak-ng,sd_espeak-ng-mb
[/etc/pulse/client.conf.d/ r,] operation=open comm=sd_espeak-ng,sd_espeak-ng-mb
[/etc/speech-dispatcher/modules/espeak-ng-mbrola.conf r,] operation=open comm=sd_espeak-ng-mb
[/etc/speech-dispatcher/modules/espeak-ng.conf r,] operation=open comm=sd_espeak-ng
["@{lib}/x86_64-linux-gnu/espeak-ng-data/voices/!v/Mr serious" r,] path_diffs=/usr/lib operation=open comm=sd_espeak-ng,sd_espeak-ng-mb
[owner @{run}/user/@{uid}/pulse/ r,] path_diffs=/run,1000 operation=open comm=sd_espeak-ng,sd_espeak-ng-mb
[owner @{run}/user/@{uid}/speech-dispatcher/log/espeak-ng-mbrola.log w,] path_diffs=/run,1000 operation=file_inherit comm=sd_espeak-ng-mb
[owner @{run}/user/@{uid}/speech-dispatcher/log/espeak-ng.log w,] path_diffs=/run,1000 operation=file_inherit comm=sd_espeak-ng
[owner @{run}/user/@{uid}/speech-dispatcher/log/speech-dispatcher.log a,] path_diffs=/run,1000 operation=file_inherit comm=sd_espeak-ng-mb
[owner @{run}/user/@{uid}/speech-dispatcher/pid/speech-dispatcher.pid w,] path_diffs=/run,1000 operation=file_inherit comm=sd_espeak-ng-mb
[owner @{user_config_dirs}/pulse/cookie rk,] path_diffs=/home/user/.config operation=file_lock,open comm=threaded-ml
firefox▶speech-dispatcher▶dash
[/dev/null wc,] operation=open comm=sh
[/etc/speech-dispatcher/modules/dtk-generic.conf r,] operation=file_inherit comm=sh
[/etc/speech-dispatcher/modules/epos-generic.conf r,] operation=file_inherit comm=sh
[/etc/speech-dispatcher/modules/espeak-mbrola-generic.conf r,] operation=file_inherit comm=sh
[/etc/speech-dispatcher/modules/espeak-ng-mbrola-generic.conf r,] operation=file_inherit comm=sh
[/etc/speech-dispatcher/modules/llia_phon-generic.conf r,] operation=file_inherit comm=sh
[/etc/speech-dispatcher/modules/mary-generic.conf r,] operation=file_inherit comm=sh
[/etc/speech-dispatcher/modules/mimic3-generic.conf r,] operation=file_inherit comm=sh
[/etc/speech-dispatcher/modules/swift-generic.conf r,] operation=file_inherit comm=sh
[@{bin}/dash r,] path_diffs=/usr/bin operation=file_mmap comm=sh
[owner @{run}/user/@{uid}/speech-dispatcher/log/speech-dispatcher.log a,] path_diffs=/run,1000 operation=file_inherit comm=sh
[owner @{run}/user/@{uid}/speech-dispatcher/pid/speech-dispatcher.pid w,] path_diffs=/run,1000 operation=file_inherit comm=sh
from apparmor.d.
Thanks, should be fixed now.
from apparmor.d.
owner /tmp/@{rand6}.tmp rw,
seems to be the only culprit. Probably a side effect from #275
But I cant reproduce speech-dispatcher
call anymore!
from apparmor.d.
Thanks, should be fixed now.
Thank you.
May I ask how you found the issue? I could not locate anything in my logs about it
from apparmor.d.
owner /tmp/@{rand6}.tmp rw, seems to be the only culprit. Probably a side effect from #275
But I cant reproduce speech-dispatcher call anymore!
That is a side effect from #275. speech-dispatcher is not really an issue (it is explicitly denied in the firefox from apparmor-profiles-extra
)
To work aa-log
, requires either auditd
or rsyslog
to be installed and enabled.
from apparmor.d.
Related Issues (20)
- aalog -r and -R do not honor the owner qualifier HOT 2
- EndeavourOS does not boot after installing apparmor.d-git HOT 5
- Firefox profile capabilities HOT 3
- Question: No New Privs HOT 1
- Flatpak aa-log HOT 2
- build process should not require a network connection HOT 2
- build security of dependencies? HOT 2
- Found reference to variable gdm_local_dirs, but is never declared (gnome-keyring-daemon) HOT 1
- aa-log reports from EndeavourOS (Arch, KDE) HOT 2
- Mutt child-pager HOT 1
- Visual Studio Code C# intellisense/debugger does not work with AppArmor enabled HOT 11
- torbrowser-start regex parser error HOT 8
- Pacman prints 'error: could not get current working directory' HOT 1
- Flatpak stops working normally when apparmor.d is installed HOT 14
- Problems with libpam-tmpdir and GDM HOT 1
- PAM auth doesn't work for systemd-homed users HOT 1
- Unable to build on Ubuntu 24.04 HOT 3
- Cannot build on debian bookworm: missing slices package HOT 1
- Firefox doesn't open after installing and enabling apparmor. d, Xfce. "Failed to execute default web browser. input/output error" HOT 3
- apparmor service does not load HOT 8
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from apparmor.d.