[Bug 1227937] [NEW] lxc-start is unconfined but has a profile defined

Jamie Strandboge jamie at ubuntu.com
Fri Sep 20 01:15:54 UTC 2013


Public bug reported:

On today's ubuntu-system image (grouper) I noticed that lxc-start has a
profile defined, but the process is not confined. Eg:

$ sudo aa-status
apparmor module is loaded.
20 profiles are loaded.
20 profiles are in enforce mode.
...
   /usr/bin/lxc-start
...
   lxc-container-default
   lxc-container-default-with-nesting
...
0 profiles are in complain mode.
4 processes have profiles defined.
3 processes are in enforce mode.
   /sbin/dhclient (1316) 
   /usr/lib/telepathy/mission-control-5 (1541) 
   /usr/lib/telepathy/telepathy-ofono (1614) 
0 processes are in complain mode.
1 processes are unconfined but have a profile defined.
   /usr/bin/lxc-start (471) 
$

I don't think this is a new bug-- seems like I've noticed it before.

** Affects: lxc (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to lxc in Ubuntu.
https://bugs.launchpad.net/bugs/1227937

Title:
  lxc-start is unconfined but has a profile defined

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1227937/+subscriptions



More information about the Ubuntu-server-bugs mailing list