Ubuntu Pastebin

Paste from popey at Thu, 23 Jun 2016 16:46:19 +0000

Download as text
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
= AppArmor =
Time: Jun 23 17:45:44
Log: apparmor="DENIED" operation="open" profile="snap.qtox.qtox" name="/sys/devices/system/node/node0/meminfo" pid=12718 comm="qtox" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
File: /sys/devices/system/node/node0/meminfo (read)
Suggestion:
* use gadget hardware assign to access '/sys/devices/system/node/node0/meminfo'

= AppArmor =
Time: Jun 23 17:45:44
Log: apparmor="DENIED" operation="open" profile="snap.qtox.qtox" name="/run/udev/data/+pci:0000:00:02.0" pid=12718 comm="qtox" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
File: /run/udev/data/+pci:0000:00:02.0 (read)
Suggestions:
* adjust program to use $SNAP_DATA
* adjust program to use /run/shm/snaps/$SNAP_NAME/$SNAP_REVISION

= Seccomp =
Time: Jun 23 17:46:01
Log: auid=4294967295 uid=1000 gid=1000 ses=4294967295 pid=12732 comm=71546F7820436F7265 exe="/snap/qtox/x2/usr/bin/qtox" sig=31 arch=c000003e 49(bind) compat=0 ip=0x7fbc61215837 code=0x0
Syscall: bind
Suggestion:
* add one of 'firewall-control, network-bind' to 'plugs'

= AppArmor =
Time: Jun 23 17:46:01
Log: apparmor="ALLOWED" operation="exec" profile="snap.snappy-debug.security" name="/usr/bin/scmp_sys_resolver" pid=12733 comm="snappy-security" requested_mask="x" denied_mask="x" fsuid=1000 ouid=0 target="snap.snappy-debug.security//null-/usr/bin/scmp_sys_resolver"
Suggestions:
* adjust snap to ship 'scmp_sys_resolver'
* adjust program to use relative paths if the snap already ships 'scmp_sys_resolver'

= AppArmor =
Time: Jun 23 17:46:01
Log: apparmor="ALLOWED" operation="open" profile="snap.snappy-debug.security//null-/usr/bin/scmp_sys_resolver" name="/etc/ld.so.cache" pid=12733 comm="scmp_sys_resolv" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
File: /etc/ld.so.cache (read)
Suggestion:
* adjust program to read necessary files from $SNAP, $SNAP_DATA or $SNAP_USER_DATA

= AppArmor =
Time: Jun 23 17:46:01
Log: apparmor="ALLOWED" operation="open" profile="snap.snappy-debug.security//null-/usr/bin/scmp_sys_resolver" name="/lib/x86_64-linux-gnu/libc-2.23.so" pid=12733 comm="scmp_sys_resolv" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
File: /lib/x86_64-linux-gnu/libc-2.23.so (read)
Suggestion:
* adjust program to read necessary files from $SNAP, $SNAP_DATA or $SNAP_USER_DATA

= AppArmor =
Time: Jun 23 17:46:01
Log: apparmor="ALLOWED" operation="file_mprotect" profile="snap.snappy-debug.security//null-/usr/bin/scmp_sys_resolver" name="/usr/bin/scmp_sys_resolver" pid=12733 comm="scmp_sys_resolv" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
File: /usr/bin/scmp_sys_resolver (read)
Suggestions:
* adjust snap to ship 'scmp_sys_resolver'
* adjust program to use relative paths if the snap already ships 'scmp_sys_resolver'

= AppArmor =
Time: Jun 23 17:46:01
Log: apparmor="ALLOWED" operation="file_mprotect" profile="snap.snappy-debug.security//null-/usr/bin/scmp_sys_resolver" name="/lib/x86_64-linux-gnu/ld-2.23.so" pid=12733 comm="scmp_sys_resolv" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
File: /lib/x86_64-linux-gnu/ld-2.23.so (read)
Suggestion:
* adjust program to read necessary files from $SNAP, $SNAP_DATA or $SNAP_USER_DATA

= AppArmor =
Time: Jun 23 17:46:02
Log: apparmor="DENIED" operation="ptrace" profile="snap.qtox.qtox" pid=12718 comm="qtox" requested_mask="trace" denied_mask="trace" peer="unconfined"
Download as text