[Bug 1413410] Re: Unable to match unix bind rule

2015-01-22 Thread Jamie Strandboge
** Also affects: snappy-ubuntu Importance: Undecided Status: New ** Summary changed: - Unable to match unix bind rule + Unable to match embedded NULLs in unix bind rule for abstract sockets ** Changed in: apparmor Assignee: (unassigned) => John Johansen (jjohansen) ** Changed in:

[Bug 1413410] Re: Unable to match unix bind rule

2015-01-22 Thread John Johansen
So first off something is wrong with the decode google-nacl-o1d12356-391 does not contain any characters that would cause encoding to happen. Doing a manual decode verifies that the issue is the trailing 0s. The question still remains if this is a bug in apparmor grabbing the abstract names le

[Bug 1413410] Re: Unable to match unix bind rule

2015-01-21 Thread Jamie Strandboge
** Description changed: On Ubuntu 14.10, I had this in my logs: Jan 21 16:32:30 localhost kernel: [24900.927939] audit: type=1400 audit(1421879550.441:534): apparmor="DENIED" operation="bind" profile="/usr/lib/firefox/firefox{,*[^s][^h]}" pid=12356 comm="plugin-containe" family="unix" sock_

[Bug 1413410] Re: Unable to match unix bind rule

2015-01-21 Thread Jamie Strandboge
** Description changed: On Ubuntu 14.10, I had this in my logs: Jan 21 16:32:30 localhost kernel: [24900.927939] audit: type=1400 audit(1421879550.441:534): apparmor="DENIED" operation="bind" profile="/usr/lib/firefox/firefox{,*[^s][^h]}" pid=12356 comm="plugin-containe" family="unix" sock_