[pkg-apparmor] Bug#969267: apparmor: nvidia_modprobe profile does not allow reading /proc/driver/nvidia/params

Vincas Dargis vindrg at gmail.com
Sun Aug 30 13:19:33 BST 2020


Package: apparmor
Version: 2.13.4-3
Severity: minor
Tags: upstream

Dear Maintainer,


Just got this denial (while running some absolutely propiertary application via Steam):
```
type=AVC msg=audit(1598788812.837:495): apparmor="DENIED" operation="open" profile="nvidia_modprobe" name="/proc/driver/nvidia/params" pid=31586 comm="nvidia-modprobe" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
```

Does not seem critical, everything still works, so marked as minor.


-- System Information:
Debian Release: bullseye/sid
  APT prefers unstable-debug
  APT policy: (500, 'unstable-debug'), (500, 'unstable'), (1, 'experimental-debug'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 5.7.0-3-amd64 (SMP w/8 CPU threads)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE
Locale: LANG=lt_LT.UTF-8, LC_CTYPE=lt_LT.UTF-8 (charmap=UTF-8), LANGUAGE=lt
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages apparmor depends on:
ii  debconf [debconf-2.0]  1.5.74
ii  libc6                  2.31-3
ii  lsb-base               11.1.0
ii  python3                3.8.2-3

apparmor recommends no packages.

Versions of packages apparmor suggests:
ii  apparmor-profiles-extra  1.27
ii  apparmor-utils           2.13.4-3

-- Configuration Files:
/etc/apparmor.d/abstractions/vulkan changed [not included]

-- debconf information excluded



More information about the pkg-apparmor-team mailing list