userID mapping issue?

xokia

Member
Apr 8, 2023
96
9
8
Is this a userid mapping issue with the LXC? Hard to understand what its doing in this audit. I get this error fairly consistently

Jun 01 11:58:30 HOME-SERVER audit[1380]: AVC apparmor="DENIED" operation="mount" class="mount" info="failed perms check" error=-13 profile="lxc-100_</var/lib/lxc>" name="/run/systemd/unit-root/" pid=1380 comm="(nft)" srcname="/" flags="rw, rbind"
Jun 01 11:58:30 HOME-SERVER kernel: audit: type=1400 audit(1685645910.805:22): apparmor="DENIED" operation="mount" class="mount" info="failed perms check" error=-13 profile="lxc-100_</var/lib/lxc>" name="/run/systemd/unit-root/" pid=1380 comm="(nft)">
Jun 01 11:58:30 HOME-SERVER audit[1391]: AVC apparmor="DENIED" operation="mount" class="mount" info="failed perms check" error=-13 profile="lxc-100_</var/lib/lxc>" name="/dev/" pid=1391 comm="(sd-mkdcreds)" flags="rw, rslave"
Jun 01 11:58:30 HOME-SERVER kernel: audit: type=1400 audit(1685645910.809:23): apparmor="DENIED" operation="mount" class="mount" info="failed perms check" error=-13 profile="lxc-100_</var/lib/lxc>" name="/dev/" pid=1391 comm="(sd-mkdcreds)" flags="rw>
Jun 01 11:58:30 HOME-SERVER audit[1414]: AVC apparmor="DENIED" operation="mount" class="mount" info="failed perms check" error=-13 profile="lxc-100_</var/lib/lxc>" name="/run/systemd/unit-root/" pid=1414 comm="(networkd)" srcname="/" flags="rw, rbind"
Jun 01 11:58:30 HOME-SERVER kernel: audit: type=1400 audit(1685645910.821:24): apparmor="DENIED" operation="mount" class="mount" info="failed perms check" error=-13 profile="lxc-100_</var/lib/lxc>" name="/run/systemd/unit-root/" pid=1414 comm="(netwo>
Jun 01 11:58:30 HOME-SERVER audit[1426]: AVC apparmor="DENIED" operation="mount" class="mount" info="failed perms check" error=-13 profile="lxc-100_</var/lib/lxc>" name="/run/systemd/unit-root/" pid=1426 comm="(resolved)" srcname="/" flags="rw, rbind"


Jun 01 11:58:30 HOME-SERVER audit[1417]: AVC apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1417 comm="apparmor_parser"
Jun 01 11:58:30 HOME-SERVER audit[1418]: AVC apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1418 comm="apparmor_parser"
Jun 01 11:58:30 HOME-SERVER audit[1418]: AVC apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1418 comm="apparmor_parser"
Jun 01 11:58:30 HOME-SERVER kernel: IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready
Jun 01 11:58:30 HOME-SERVER kernel: fwbr100i0: port 2(veth100i0) entered blocking state
Jun 01 11:58:30 HOME-SERVER kernel: fwbr100i0: port 2(veth100i0) entered forwarding state
Jun 01 11:58:30 HOME-SERVER kernel: audit: type=1400 audit(1685645910.845:26): apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1417 comm="apparmor>
Jun 01 11:58:30 HOME-SERVER kernel: audit: type=1400 audit(1685645910.845:27): apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1418 comm="apparmor>
Jun 01 11:58:30 HOME-SERVER kernel: audit: type=1400 audit(1685645910.845:28): apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1418 comm="apparmor>
Jun 01 11:58:30 HOME-SERVER audit[1420]: AVC apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1420 comm="apparmor_parser"
Jun 01 11:58:30 HOME-SERVER kernel: audit: type=1400 audit(1685645910.857:29): apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1420 comm="apparmor>
Jun 01 11:58:30 HOME-SERVER audit[1421]: AVC apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1421 comm="apparmor_parser"
Jun 01 11:58:30 HOME-SERVER kernel: audit: type=1400 audit(1685645910.877:30): apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1421 comm="apparmor>
Jun 01 11:58:30 HOME-SERVER audit[1419]: AVC apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1419 comm="apparmor_parser"
Jun 01 11:58:30 HOME-SERVER audit[1452]: AVC apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1452 comm="apparmor_parser"
Jun 01 11:58:30 HOME-SERVER audit[1455]: AVC apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1455 comm="apparmor_parser"
Jun 01 11:58:30 HOME-SERVER audit[1455]: AVC apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1455 comm="apparmor_parser"
Jun 01 11:58:30 HOME-SERVER audit[1468]: AVC apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1468 comm="apparmor_parser"
Jun 01 11:58:30 HOME-SERVER audit[1471]: AVC apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1471 comm="apparmor_parser"
Jun 01 11:58:30 HOME-SERVER audit[1461]: AVC apparmor="STATUS" operation="profile_replace" info="not policy admin" error=-13 label="lxc-100_</var/lib/lxc>//&:lxc-100_<-var-lib-lxc>:unconfined" pid=1461 comm="apparmor_parser"
Jun 01 11:58:30 HOME-SERVER audit[1479]: AVC apparmor="DENIED" operation="mount" class="mount" info="failed perms check" error=-13 profile="lxc-100_</var/lib/lxc>" name="/run/systemd/unit-root/" pid=1479 comm="(d-logind)" srcname="/" flags="rw, rbind"
 
Last edited:
  • Like
Reactions: jasonsansone

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!