Apparmor denies access to /var/lib/openntpd/db/ntpd.drift

msi1

New Member
Jan 30, 2020
4
0
1
37
audit: type=1400 audit(1580378188.850:39): apparmor="DENIED" operation="truncate" profile="/usr/sbin/ntpd" name="/var/lib/openntpd/db/ntpd.drift" pid=251684 comm="ntpd" requested_mask="w" denied_mask="w" fsuid=0 ouid=0

root@pve01:/etc/apparmor.d# grep drift /etc/apparmor.d/usr.sbin.ntpd
/etc/ntp.drift rwl,
/etc/ntp.drift.TEMP rwl,
/etc/ntp/drift* rwl,
/var/lib/ntp/*drift rw,
/var/lib/ntp/*drift.TEMP rw,
 
Is it enough that it is the same package name in the bug report ?

This is the attached diff:
--- usr.sbin.ntpd 2014-10-19 03:36:28.000000000 -0500
+++ /tmp/usr.sbin.ntpd 2015-09-15 12:51:07.502640134 -0500
@@ -45,6 +45,7 @@
/etc/ntpd.conf r,
/etc/ntpd.conf.tmp r,
/var/lib/ntp/ntp.conf.dhcp r,
+ /etc/openntpd/ntpd.conf r,

/etc/ntp.keys r,
/etc/ntp/** r,

I mean... reallly ?
 
For the record, as it is present again in Debian12/Proxmox 8, i just created another bug:
https://bugs.debian.org/cgi-bin/pkgreport.cgi?pkg=ntpsec

Code:
2023-12-22T10:46:28.551247+01:00 srv42 kernel: [1569581.071493] audit: type=1400 audit(1703238388.546:160): apparmor="DENIED" operation="mknod" class="file" profile="/usr/sbin/ntpd" name="/var/lib/ntp/drift-tmp" pid=782130 comm="ntpd" requested_mask="c" denied_mask="c" fsuid=115 ouid=115
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!