[lxc-users] Apparmor profile boken

Serge Hallyn serge.hallyn at ubuntu.com
Fri Mar 21 20:11:53 UTC 2014


If this is a stock ubuntu 14.04 system, please do file a bug asap
against apparmor.  If possible, using 'ubuntu-bug apparmor' from one
of the failing hosts (maybe global04).  I haven't seen this myself,
but it sure looks bad.

Quoting Flo (florian.engelmann at gmail.com):
> Hi,
> 
> after patching 6 Ubuntu 14.04 servers today (all 6 are same HW, same
> installation) two got problems with apparmor and the lxc-container-default
> profile?
> 
> root at xxxxxxxxxxxxxxxx:/etc# service apparmor restart
>  * Reloading AppArmor profiles
>                                                            Enocoding of
> mount rule failed
> ERROR processing policydb rules for profile lxc-container-default, failed
> to load
> 
> 
> I tried purging and resinstalling apparmor lxc and lxc-templates but this
> did not fix the problem?!
> It looks like something failed during the apparmor upgrade?
> 
> for i in 1 2 3 4 5 6; do ssh root at 192.168.xxx.1$i "hostname;
> apparmor_parser /etc/apparmor.d/lxc-containers"; done
> global01
> Enocoding of mount rule failed
> ERROR processing policydb rules for profile lxc-container-default, failed
> to load
> global02
> global03
> global04
> Enocoding of mount rule failed
> ERROR processing policydb rules for profile lxc-container-default, failed
> to load
> global05
> global06
> 
> Any idea how whats broken? I also tried to copy /etc/apparmor.d from a
> healthy server to the broken once but this did not help... and is not a
> good thing to do anyway...
> 
> Regards,
> Flo

> _______________________________________________
> lxc-users mailing list
> lxc-users at lists.linuxcontainers.org
> http://lists.linuxcontainers.org/listinfo/lxc-users



More information about the lxc-users mailing list