apparmor

  1. I

    Tor inside LXC blocked by AppArmor

    Hey fellas, this is what dmesg gives: [153434.316515] audit: type=1400 audit(1566380002.099:292): apparmor="STATUS" operation="profile_replace" info="same as current profile, skipping" label="lxc-110_</var/lib/lxc>//&:lxc-110_<-var-lib-lxc>:unconfined" name="system_tor" pid=24893...
  2. mattlach

    DMESG Inundated with Apparmor errors

    Hey all, I'm not very good with how Apparmor works, so I was hoping someone might help me solve this one. Two of my many LXC containers, ID 110 and ID 170 are resulting in an absolute spamming of DMESG as follows: Please see this pastebin. It was too much to post in a message here. Two...
  3. S

    nfs-kernel-server in LXC, Dienst startet nicht mehr nach PVE-Update

    Hallo, ich nutze seit über einem Jahr Proxmox VE. Bisher ohne Probleme. Zwischenzeitlich habe ich meine gesamte virtuelle Umgebung dorthin umgezogen. Nun habe ich letze Woche eine Subscription erstanden und heute morgen den Updateprozess von PVE gestartet. Das lief auch alles ohne...
  4. M

    Unprivileged LXC CentOS 7 NFS server woes with AppArmor and D-Bus

    I'm trying to set up a file server (NFS now, Samba after) in a CentOS 7 container, without making it privileged. The NFS service won't start because of dependency issues with RPC Pipe which will not mount (says permission denied). I've found some seemingly relevant information...
  5. F

    Container with mount point randomly not starting at boot

    Hi, I have a poc proxmox server embedded on a train and running some containers and virtual machines. One of this containers have huge data that I don't want to backup, so I put it on a separate mount point marked to not beeing backed up. The proxmox server is setup to start when ups gets...
  6. L

    apparmor error every few seconds

    Testing an upgraded host and container to Debian 9 we keep getting an apparmor error on syslog. I've read other threads about this being a "warning" of some process trying to remount something not allowed on the container but can't figure out what it is. prox-test kernel: [1893537.445678]...
  7. D

    oom-killer activity on debian stretch LXC

    Hello, since the last update I have strange activity in dmesg related to oom-killer with some processes in Debian LXC images and the problem doesn't really seem to be due to lack of memory, because the system has 70G of memory and 15G available. I guess many users would confirm the issue and it...
  8. T

    Apparmor denies LXC startup operations from only certain containers.

    I have been using the supplied templates (pveam downloads) for all of my containers and they are mostly built from the Ubuntu 17.10 template, though I have 2 that are built from the Ubuntu 16.04 template. The LXC containers built from the 16.04 template start just fine and have no issues with...
  9. L

    NFS-Server in LXC

    Hallo zusammen, von Turnkey habe ich mir den Mediaserver geholt und damit einen Container erstellt. In diesem habe ich noch eine komplette Partition gemountet, die die ganzen Multimediadaten beherbergt. lxc.mount.entry: /media/sdb1 /var/lib/lxc/303/rootfs/media/multimedia none bind 0 0 Diese...
  10. B

    [SOLVED] Apparmor preventing LXCs starting after update

    I ran an apt update && apt dist-upgrade on my home server after a few weeks of uptime as part of its routine maintenance but its LXCs are failing to start after the reboot. All the VMs are still working. journalctl -xe output: -- Unit pve-container@200.service has begun starting up. Mar 10...
  11. E

    [SOLVED] Bind mount mounting but subdirectories are empty

    So I have on my Host machine: /storage/HDD2 /storage/Internal And I am planning to mount these on my Guest machine which is a container: /srv/samba So in my Guest machine I can see that under /srv/samba I see HDD2 and Internal respectively, but not their contents, so I am asking the wizards in...
  12. U

    Ubuntu Snaps inside LXC container on Proxmox

    Hi, I am trying to test Snap applications inside an Ubuntu 16.04 LXC container in Proxmox, and I am running into problems. I found this link: https://stgraber.org/2017/01/31/ubuntu-core-in-lxd-containers/ And it seems snapd needs "unprivileged FUSE mounts and AppArmor namespacing and stacking"'...
  13. D

    Few questions

    Hello, I recently installed and configured a fully working 3 nodes cluster HA with CEPH and all works fine. Up to the point when in SYSLOG of each nodes, I get this, repetitively each day: APPARMOR Related: Jul 21 03:40:06 node01-sxb-pve01 kernel: audit_printk_skb: 384 callbacks suppressed...
  14. A

    [SOLVED] apparmor="DENIED" operation="mount"

    The output of dmesg: How to fix it?
  15. T

    KVM and apparmor

    Hi, Proxmox uses apparmor to confine its LXC containers, but it doesn't do so for KVM virtual machines. Libvirt (Proxmox's open source competitor, kind-of) does do so. Would this be worth adding to a new Proxmox release, for additional security? I wanted to post here about it before adding...
  16. P

    Mount SCSI device in LXC container - Apparmor denied

    Hi, I'm trying to mount scsi tape drive into lxc containter and it I cannot figure out how to do it... My UDEV config looks like this: #/etc/udev/rules.d/70-persistent-iscsi.rules SUBSYSTEM=="scsi_generic",ATTRS{vendor}=="IBM",ATTRS{model}=="ULTRIUM-HH4", SYMLINK="ultrium", MODE="0660"...
  17. N

    [SOLVED] PVE v4.4 OpenVPN apparmor DENIED

    PVE: 4.4 Image: Ubuntu 16.10 I'm following the tutorial for setting up OpenVPN, here: https://hungred.com/how-to/setup-openvpn-on-proxmox-lxc/. This worked just fine in PVE 4.2, and have set up 3 OpenVPN servers this way, but it no loger seems to work in PVE 4.4 I've added to...
  18. J

    Problem AppArmor reboot system

    Sorry for my bad english, I have a problem with apparmor in proxmox v4.4 which does not get to mount units and I am the machine the previous registration to the fall is next. Feb 16 17:40:01 nodo1 kernel: [76282.010836] audit: type=1400 audit(1487263201.515:455): apparmor="DENIED"...
  19. T

    [SOLVED] Apparmor lxc config file overwritted when rebooting CT

    Hi there, i'm trying to install Sandstorm on a debian 8 CT. According to my search (and this post ) i need to to edit the apparmor container's config in /var/lib/lxc/103/conf and reboot the CT but any line i add to this file get suppressed as son as i reboot the CT .... (i precise that i edit...
  20. D

    Can't launch Proxmox : apparmor="DENIED"

    Hello, I own a dedicated server (Dedibox Online.net) with Proxmox installed on it. Everything was OK until yesterday, now I can't start the server. Here is the error I got : apparmor="DENIED" operation="sendmsg" profile="/usr/sbin/named" name="/run/systemd/journal/dev-log Could you please help ?

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!