<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=4139&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / [SOLVED] Heads up: haveged denied starting by apparmor in Beowulf]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=4139</link>
		<description><![CDATA[The most recent posts in [SOLVED] Heads up: haveged denied starting by apparmor in Beowulf.]]></description>
		<lastBuildDate>Sun, 11 Apr 2021 09:22:11 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: [SOLVED] Heads up: haveged denied starting by apparmor in Beowulf]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=29017#p29017</link>
			<description><![CDATA[<div class="quotebox"><cite>Altoid wrote:</cite><blockquote><div><p>everything is apparently <span class="bbc">unconfined</span>, so what does it actually do? Am I missing some configuration file/s?</p></div></blockquote></div><p>The default configuration supplies a mandatory access control framework to confine some but not all programs. This confinement prevents compromised software from altering your system even if it has root privileges. It is actually very useful, which is why it is enabled by default. There are extra profiles available if you want to extend the protection and you can also write your own profiles to specify the exact level of confinement.</p><p>See also <a href="https://wiki.debian.org/AppArmor/HowToUse" rel="nofollow">https://wiki.debian.org/AppArmor/HowToUse</a> &amp; <a href="https://debian-handbook.info/browse/stable/sect.apparmor.html" rel="nofollow">https://debian-handbook.info/browse/sta … armor.html</a></p>]]></description>
			<author><![CDATA[dummy@example.com (Head_on_a_Stick)]]></author>
			<pubDate>Sun, 11 Apr 2021 09:22:11 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=29017#p29017</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Heads up: haveged denied starting by apparmor in Beowulf]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=29015#p29015</link>
			<description><![CDATA[<p>Hello:</p><div class="quotebox"><cite>dice wrote:</cite><blockquote><div><p>uninstalling apparmor ...</p></div></blockquote></div><p>Indeed.<br />Got rid of it.<br />Saw no use for it and people who know more than i do about all this have uninstalled it.</p><p><a href="https://dev1galaxy.org/viewtopic.php?pid=28640#p28640" rel="nofollow">https://dev1galaxy.org/viewtopic.php?pid=28640#p28640</a></p><p>And that was the end of it.</p><p>Cheers,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Sat, 10 Apr 2021 21:04:04 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=29015#p29015</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Heads up: haveged denied starting by apparmor in Beowulf]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=27605#p27605</link>
			<description><![CDATA[<p>Hello:</p><div class="quotebox"><cite>dice wrote:</cite><blockquote><div><p>uninstalling apparmor also solves this issue.</p></div></blockquote></div><p>Quite so ...<br />Something I&#039;m considering as I&#039;m <em>not certain</em> it is of any use to me.</p><p>ie: everything is apparently <span class="bbc">unconfined</span>, so what does it actually do? Am I missing some configuration file/s?</p><div class="codebox"><pre><code>groucho@devuan:~$  sudo dmesg | grep apparmor
[   25.423650] audit: type=1400 --- snip --- apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;libreoffice-senddoc&quot; pid=1409 comm=&quot;apparmor_parser&quot;
[   25.448662] audit: type=1400 --- snip --- apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;libreoffice-oopslash&quot; pid=1412 comm=&quot;apparmor_parser&quot;
[   25.474000] audit: type=1400 --- snip --- apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;nvidia_modprobe&quot; pid=1411 comm=&quot;apparmor_parser&quot;
[   25.500604] audit: type=1400 --- snip --- apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;nvidia_modprobe//kmod&quot; pid=1411 comm=&quot;apparmor_parser&quot;
[   25.500605] audit: type=1400 --- snip --- apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;/usr/bin/man&quot; pid=1410 comm=&quot;apparmor_parser&quot;
[   25.500607] audit: type=1400 --- snip --- apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;man_filter&quot; pid=1410 comm=&quot;apparmor_parser&quot;
[   25.500608] audit: type=1400 --- snip --- apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;man_groff&quot; pid=1410 comm=&quot;apparmor_parser&quot;
[   25.500609] audit: type=1400 --- snip --- apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;libreoffice-soffice&quot; pid=1414 comm=&quot;apparmor_parser&quot;
[   25.500611] audit: type=1400 --- snip --- apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;libreoffice-soffice//gpg&quot; pid=1414 comm=&quot;apparmor_parser&quot;
[   25.500612] audit: type=1400 --- snip --- apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;libreoffice-xpdfimport&quot; pid=1416 comm=&quot;apparmor_parser&quot;
groucho@devuan:~$ </code></pre></div><div class="quotebox"><cite>dice wrote:</cite><blockquote><div><p>... being obnoxious sorry...</p></div></blockquote></div><p>Nah!</p><p>It&#039;s quite alright, been there/done that.</p><p>After all, it <em>is</em> monday.</p><p>Cheers,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Mon, 22 Feb 2021 14:52:31 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=27605#p27605</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Heads up: haveged denied starting by apparmor in Beowulf]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=27604#p27604</link>
			<description><![CDATA[<p>uninstalling apparmor also solves this issue. But im being obnoxious sorry...</p>]]></description>
			<author><![CDATA[dummy@example.com (dice)]]></author>
			<pubDate>Mon, 22 Feb 2021 13:53:54 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=27604#p27604</guid>
		</item>
		<item>
			<title><![CDATA[[SOLVED] Heads up: haveged denied starting by apparmor in Beowulf]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=27601#p27601</link>
			<description><![CDATA[<p>Hello:</p><p>As I do every so often, I was trawling through my <span class="bbc">dmesg</span> output to see if everything was running kosher and came across a few lines involving apparmor. </p><div class="codebox"><pre><code>groucho@devuan:~$ uname -a
Linux devuan 4.19.0-14-amd64 #1 SMP Debian 4.19.171-2 (2021-01-30) x86_64 GNU/Linux
groucho@devuan:~$ </code></pre></div><div class="codebox"><pre><code>groucho@devuan:~$ apt list | grep installed | grep apparmor
--- snip ---
apparmor/stable,now 2.13.2-10 amd64 [installed,automatic]
libapparmor1/stable,now 2.13.2-10 amd64 [installed]
groucho@devuan:~$ </code></pre></div><div class="codebox"><pre><code>groucho@devuan:~$ sudo dmesg | grep apparmor
[   25.573821] audit: type=1400 audit(1613992734.879:2): apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;libreoffice-senddoc&quot; pid=1413 comm=&quot;apparmor_parser&quot;
[   25.602109] audit: type=1400 audit(1613992734.879:3): apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;libreoffice-oopslash&quot; pid=1416 comm=&quot;apparmor_parser&quot;
[   25.630152] audit: type=1400 audit(1613992734.879:4): apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;/usr/bin/man&quot; pid=1414 comm=&quot;apparmor_parser&quot;
[   25.656608] audit: type=1400 audit(1613992734.879:5): apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;man_filter&quot; pid=1414 comm=&quot;apparmor_parser&quot;
[   25.656609] audit: type=1400 audit(1613992734.879:6): apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;man_groff&quot; pid=1414 comm=&quot;apparmor_parser&quot;
[   25.656611] audit: type=1400 audit(1613992734.879:7): apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;/usr/sbin/haveged&quot; pid=1419 comm=&quot;apparmor_parser&quot;
[   25.656612] audit: type=1400 audit(1613992734.879:8): apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;libreoffice-xpdfimport&quot; pid=1420 comm=&quot;apparmor_parser&quot;
[   25.656613] audit: type=1400 audit(1613992734.879:9): apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;/usr/lib/cups/backend/cups-pdf&quot; pid=1417 comm=&quot;apparmor_parser&quot;
[   25.656616] audit: type=1400 audit(1613992734.879:10): apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;/usr/sbin/cupsd&quot; pid=1417 comm=&quot;apparmor_parser&quot;
[   25.857783] audit: type=1400 audit(1613992734.879:11): apparmor=&quot;STATUS&quot; operation=&quot;profile_load&quot; profile=&quot;unconfined&quot; name=&quot;/usr/sbin/cupsd//third_party&quot; pid=1417 comm=&quot;apparmor_parser&quot;
[   38.103239] audit: type=1400 audit(1613992747.407:16): apparmor=&quot;DENIED&quot; operation=&quot;mknod&quot; profile=&quot;/usr/sbin/haveged&quot; name=&quot;/run/haveged.pid&quot; pid=2516 comm=&quot;haveged&quot; requested_mask=&quot;c&quot; denied_mask=&quot;c&quot; fsuid=0 ouid=0
[ 2040.598275] audit: type=1400 audit(1613994749.903:17): apparmor=&quot;ALLOWED&quot; operation=&quot;file_mmap&quot; profile=&quot;libreoffice-soffice&quot; name=&quot;/tmp/.glRDlerP&quot; pid=8590 comm=&quot;soffice.bin&quot; requested_mask=&quot;m&quot; denied_mask=&quot;m&quot; fsuid=1000 ouid=1000
[ 2040.905923] audit: type=1400 audit(1613994750.211:18): apparmor=&quot;ALLOWED&quot; operation=&quot;open&quot; profile=&quot;libreoffice-soffice&quot; name=&quot;/home/groucho/.icons/default/index.theme&quot; pid=8589 comm=&quot;soffice.bin&quot; requested_mask=&quot;r&quot; denied_mask=&quot;r&quot; fsuid=1000 ouid=1000
[ 2040.906026] audit: type=1400 audit(1613994750.211:19): apparmor=&quot;ALLOWED&quot; operation=&quot;open&quot; profile=&quot;libreoffice-soffice&quot; name=&quot;/home/groucho/.icons/default/index.theme&quot; pid=8589 comm=&quot;soffice.bin&quot; requested_mask=&quot;r&quot; denied_mask=&quot;r&quot; fsuid=1000 ouid=1000
[ 2040.906121] audit: type=1400 audit(1613994750.211:20): apparmor=&quot;ALLOWED&quot; operation=&quot;open&quot; profile=&quot;libreoffice-soffice&quot; name=&quot;/home/groucho/.icons/default/index.theme&quot; pid=8589 comm=&quot;soffice.bin&quot; requested_mask=&quot;r&quot; denied_mask=&quot;r&quot; fsuid=1000 ouid=1000
[ 2040.906212] audit: type=1400 audit(1613994750.211:21): apparmor=&quot;ALLOWED&quot; operation=&quot;open&quot; profile=&quot;libreoffice-soffice&quot; name=&quot;/home/groucho/.icons/default/index.theme&quot; pid=8589 comm=&quot;soffice.bin&quot; requested_mask=&quot;r&quot; denied_mask=&quot;r&quot; fsuid=1000 ouid=1000
groucho@devuan:~$ </code></pre></div><p>The one that caught my eye was this one:</p><div class="codebox"><pre><code>[   38.103239] audit: type=1400 audit(1613992747.407:16): apparmor=&quot;DENIED&quot; operation=&quot;mknod&quot; profile=&quot;/usr/sbin/haveged&quot; name=&quot;/run/haveged.pid&quot; pid=2516 comm=&quot;haveged&quot; requested_mask=&quot;c&quot; denied_mask=&quot;c&quot; fsuid=0 ouid=0</code></pre></div><div class="codebox"><pre><code>groucho@devuan:~$ apt list | grep installed | grep haveged
--- snip ---
haveged/stable,now 1.9.1-7 amd64 [installed]
groucho@devuan:~$ </code></pre></div><p>I looked it up and found a Debian bug report from late 2018:&#160; <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=911604" rel="nofollow">https://bugs.debian.org/cgi-bin/bugrepo … bug=911604</a></p><p>Basically, what I understand is happening is that <span class="bbc">apparmor</span> does not allow <span class="bbc">haveged</span> to start, failing silently.</p><p>From what I can make out of the text in the bug report, it seems that this does not happen if your installation uses <span class="bbc">systemd</span>, but it does if you use <span class="bbc">openrc-init</span>,&#160; <span class="bbc">sysvinit</span> and probaby the rest, apparently generating first-boot delays.</p><p>A workaround to the problem was posted by the bug&#039;s OP and confirmed to work in a later post.</p><div class="quotebox"><blockquote><div><p>What helped was adding the line</p><p>&#160; /run/haveged.pid w,</p><p>to /etc/apparmor.d/local/usr.sbin.haveged, so you should probably add that line to /etc/apparmor.d/usr.sbin.haveged.</p></div></blockquote></div><p>This was apparently fixed in <span class="bbc">haveged 1.9.1-8</span> but the latest version in <span class="bbc"><a href="http://deb.devuan.org/merged" rel="nofollow">http://deb.devuan.org/merged</a> beowulf/main amd64</span> is 1.9.1-7.</p><p>I&#039;ll try the fix and report back later.</p><p><span class="bbu">Edit:</span> the fix works.</p><p>Cheers,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Mon, 22 Feb 2021 13:34:52 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=27601#p27601</guid>
		</item>
	</channel>
</rss>
