[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#980974: marked as done (apparmor blocks cups backend outgoing network connections)



Your message dated Sat, 25 Feb 2023 18:24:11 +0000 (UTC)
with message-id <alpine.DEB.2.21.2302251822410.23431@postfach.intern.alteholz.me>
and subject line Closing this bug (BTS maintenance for debian-printing)
has caused the Debian Bug report #977813,
regarding apparmor blocks cups backend outgoing network connections
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
977813: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=977813
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: cups
Version: 2.3.3op1-7

After upgrading to bullseye, TCP connections from cupsd to localhost appeared to be blocked:

Jan 23 23:39:29 debian audit[2172]: AVC apparmor="DENIED" operation="capable" profile="" pid=2172 comm="cupsd" capability=12  capname="net_admin"
Jan 23 23:39:29 debian systemd[1]: Started CUPS Scheduler.
Jan 23 23:39:29 debian kernel: kauditd_printk_skb: 10 callbacks suppressed
Jan 23 23:39:29 debian kernel: audit: type=1400 audit(1611445169.589:22): apparmor="DENIED" operation="capable" profile="" pid=2172 comm="cupsd" capability=12>
Jan 23 23:39:29 debian systemd[1]: Started Make remote CUPS printers available locally.
Jan 23 23:39:29 debian audit[2174]: AVC apparmor="DENIED" operation="capable" profile="" pid=2174 comm="cups-browsed" capability=23  capname="sys_nice"

I worked around this with `aa-complain cupsd`, `aa-complain cups-browsed`, but I would guess that this should work without modifications, unless this (TCP connections from cupsd to backend driver) is considered non-standard usage?

--- End Message ---
--- Begin Message ---
Hi,

it looks like this bug has been "fixed", at least the last entry says so.

Thus I am manually closing this bug.

Best regards,
Thorsten

--- End Message ---

Reply to: