[pkg-apparmor] Bug#819501: apparmor abstraction nameservice should include /run/NetworkManager/resolv.conf

Julian Andres Klode jak at debian.org
Tue Mar 29 18:43:53 UTC 2016


Package: apparmor-profiles
Version: 2.10-3
Severity: normal

On systems where NetworkManager automatically starts dnsmasq, it also controls
resolv.conf itself, and the resolv.conf file is linked to /run/NetworkManager/resolv.conf

ls -l /etc/resolv.conf 
lrwxrwxrwx 1 root root 35 Mar 29 20:36 /etc/resolv.conf -> /var/run/NetworkManager/resolv.conf

So:
	/{,var/}run/NetworkManager/resolv.conf r,

should be added to the nameservices abstraction.

-- System Information:
Debian Release: stretch/sid
  APT prefers unstable
  APT policy: (900, 'unstable'), (500, 'unstable-debug'), (500, 'testing'), (100, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.5.0-trunk-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_IE.UTF-8, LC_CTYPE=en_IE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages apparmor-profiles depends on:
ii  apparmor  2.10-3+b1

apparmor-profiles recommends no packages.

apparmor-profiles suggests no packages.

-- Configuration Files:
/etc/apparmor.d/bin.ping changed [not included]
/etc/apparmor.d/usr.sbin.avahi-daemon changed [not included]
/etc/apparmor.d/usr.sbin.dnsmasq changed [not included]
/etc/apparmor.d/usr.sbin.smbd changed [not included]

-- no debconf information

-- 
Debian Developer - deb.li/jak | jak-linux.org - free software dev

When replying, only quote what is necessary, and write each reply
directly below the part(s) it pertains to (`inline'). Thank you.



More information about the pkg-apparmor-team mailing list