[apparmor] question about "no new privs"

Mikhail Morfikov mmorfikov at gmail.com
Sat Nov 3 15:08:00 UTC 2018


I can't really figure out what apparmor wants from me in the following message:

kernel: [61380.312237] audit: type=1400 audit(1541256918.026:2604):
apparmor="DENIED" operation="exec" info="no new privs" error=-1
profile="opt-google-chrome-chrome" name="/usr/bin/xdg-desktop-menu" pid=115118
comm="TaskSchedulerFo" requested_mask="x" denied_mask="x" fsuid=1000 ouid=0
target="xdg-desktop-menu"

I have an external profile for /usr/bin/xdg-desktop-menu and also I use the
following rule in the opt-google-chrome-chrome profile:

  /usr/bin/xdg-desktop-menu rPUx,

So what apparmor rule is able to fix that message?



More information about the AppArmor mailing list