= AppArmor =
Time: Jun 23 17:45:44
Log: apparmor="DENIED" operation="open" profile="snap.qtox.qtox" name="/sys/devices/system/node/node0/meminfo" pid=12718 comm="qtox" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
File: /sys/devices/system/node/node0/meminfo (read)
Suggestion:
* use gadget hardware assign to access '/sys/devices/system/node/node0/meminfo'
= AppArmor =
Time: Jun 23 17:45:44
Log: apparmor="DENIED" operation="open" profile="snap.qtox.qtox" name="/run/udev/data/+pci:0000:00:02.0" pid=12718 comm="qtox" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
File: /run/udev/data/+pci:0000:00:02.0 (read)
Suggestions:
* adjust program to use $SNAP_DATA
* adjust program to use /run/shm/snaps/$SNAP_NAME/$SNAP_REVISION
= Seccomp =
Time: Jun 23 17:46:01
Log: auid=4294967295 uid=1000 gid=1000 ses=4294967295 pid=12732 comm=71546F7820436F7265 exe="/snap/qtox/x2/usr/bin/qtox" sig=31 arch=c000003e 49(bind) compat=0 ip=0x7fbc61215837 code=0x0
Syscall: bind
Suggestion:
* add one of 'firewall-control, network-bind' to 'plugs'
= AppArmor =
Time: Jun 23 17:46:01
Log: apparmor="ALLOWED" operation="exec" profile="snap.snappy-debug.security" name="/usr/bin/scmp_sys_resolver" pid=12733 comm="snappy-security" requested_mask="x" denied_mask="x" fsuid=1000 ouid=0 target="snap.snappy-debug.security//null-/usr/bin/scmp_sys_resolver"
Suggestions:
* adjust snap to ship 'scmp_sys_resolver'
* adjust program to use relative paths if the snap already ships 'scmp_sys_resolver'
= AppArmor =
Time: Jun 23 17:46:01
Log: apparmor="ALLOWED" operation="open" profile="snap.snappy-debug.security//null-/usr/bin/scmp_sys_resolver" name="/etc/ld.so.cache" pid=12733 comm="scmp_sys_resolv" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
File: /etc/ld.so.cache (read)
Suggestion:
* adjust program to read necessary files from $SNAP, $SNAP_DATA or $SNAP_USER_DATA
= AppArmor =
Time: Jun 23 17:46:01
Log: apparmor="ALLOWED" operation="open" profile="snap.snappy-debug.security//null-/usr/bin/scmp_sys_resolver" name="/lib/x86_64-linux-gnu/libc-2.23.so" pid=12733 comm="scmp_sys_resolv" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
File: /lib/x86_64-linux-gnu/libc-2.23.so (read)
Suggestion:
* adjust program to read necessary files from $SNAP, $SNAP_DATA or $SNAP_USER_DATA
= AppArmor =
Time: Jun 23 17:46:01
Log: apparmor="ALLOWED" operation="file_mprotect" profile="snap.snappy-debug.security//null-/usr/bin/scmp_sys_resolver" name="/usr/bin/scmp_sys_resolver" pid=12733 comm="scmp_sys_resolv" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
File: /usr/bin/scmp_sys_resolver (read)
Suggestions:
* adjust snap to ship 'scmp_sys_resolver'
* adjust program to use relative paths if the snap already ships 'scmp_sys_resolver'
= AppArmor =
Time: Jun 23 17:46:01
Log: apparmor="ALLOWED" operation="file_mprotect" profile="snap.snappy-debug.security//null-/usr/bin/scmp_sys_resolver" name="/lib/x86_64-linux-gnu/ld-2.23.so" pid=12733 comm="scmp_sys_resolv" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
File: /lib/x86_64-linux-gnu/ld-2.23.so (read)
Suggestion:
* adjust program to read necessary files from $SNAP, $SNAP_DATA or $SNAP_USER_DATA
= AppArmor =
Time: Jun 23 17:46:02
Log: apparmor="DENIED" operation="ptrace" profile="snap.qtox.qtox" pid=12718 comm="qtox" requested_mask="trace" denied_mask="trace" peer="unconfined"