I also cannot get any kind of audit from apparmor. I first enabled the profile since I had disabled it:
sudo aa-enforce /etc/apparmor.d/usr.bin.firefox-3.5
Now Firefox freezes when loading Java, but the only output on kern.log is the following:
Dec 27 11:55:53 al-desktop kernel: [226309.268382] type=1505 audit(1261914953.903:24): operation="profile_load" pid=6147 name=/usr/lib/firefox-3.5.*/firefox
Then I tried putting apparmor into complain mode:
sudo aa-complain /usr/bin/firefox-3.5 sudo aa-complain /usr/lib/firefox-3.5.*/firefox sudo aa-complain Please enter the program to switch to complain mode: firefox Setting /etc/apparmor.d/usr.bin.firefox-3.5 to complain mode.
After the third attempt I saw this on kern.log:
Dec 27 12:18:27 al-desktop kernel: [227662.623186] type=1505 audit(1261916307.256:25): operation="profile_replace" pid=7541 name=/usr/lib/firefox-3.5.*/firefox
However, Firefox still freezes with no audit log, even though in complain mode, nothing is supposed to be enforced.
Setting this bug back to "new" because we cannot get the requested information with the supplied instructions.
I also cannot get any kind of audit from apparmor. I first enabled the profile since I had disabled it:
sudo aa-enforce /etc/apparmor. d/usr.bin. firefox- 3.5
Now Firefox freezes when loading Java, but the only output on kern.log is the following:
Dec 27 11:55:53 al-desktop kernel: [226309.268382] type=1505 audit(126191495 3.903:24) : operation= "profile_ load" pid=6147 name=/usr/ lib/firefox- 3.5.*/firefox
Then I tried putting apparmor into complain mode:
sudo aa-complain /usr/bin/ firefox- 3.5 firefox- 3.5.*/firefox
Please enter the program to switch to complain mode: firefox d/usr.bin. firefox- 3.5 to complain mode.
sudo aa-complain /usr/lib/
sudo aa-complain
Setting /etc/apparmor.
After the third attempt I saw this on kern.log:
Dec 27 12:18:27 al-desktop kernel: [227662.623186] type=1505 audit(126191630 7.256:25) : operation= "profile_ replace" pid=7541 name=/usr/ lib/firefox- 3.5.*/firefox
However, Firefox still freezes with no audit log, even though in complain mode, nothing is supposed to be enforced.
Setting this bug back to "new" because we cannot get the requested information with the supplied instructions.