[Apparmor-general] permission denied at boot, but is fine later on?

Per Jessen per at computer.org
Thu Oct 23 07:19:00 MDT 2008


John Johansen wrote:

>> what does the full expanded profile look like?
>> apparmor_parser -p /etc/apparmod.d/sbin.syslog-ng
> 

Have attached it to the bugreport.

>> It looks like the permissions for /var/log should be rw, but why
>> isn't this corrected by aa-genprof, and why isn't it a problem when I
>> restart syslog-ng?
>> 
> There are a few possibilities.  While I haven't tested this with
> syslog-ng,  it is not unheard of that restart does something slightly
> different than start.  Also start and restart may do slightly
> different things depending on what services are up or what files
> exist.
> 
> Some questions
> - do you get the message when you boot your machine

Yep. 

> - do you get the message if you run rcsyslog stop, rcsyslog start
> instead of rcsyslog restart?

I haven't tried it, but the init-script makes restart = stop + start, so
there shouldn't be much difference. 


/Per Jessen, Zürich



More information about the Apparmor-general mailing list