Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- sudo snappy-debug
- INFO: Following '/var/log/syslog'. If have dropped messages, use:
- INFO: $ sudo journalctl --output=short --follow --all | sudo snappy-debug
- kernel.printk_ratelimit = 0
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap" name="/sys/kernel/mm/transparent_hugepage/hpage_pmd_size" pid=39687 comm="jami" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /sys/kernel/mm/transparent_hugepage/hpage_pmd_size (read)
- Suggestion:
- * adjust program to not access '/sys/kernel/mm/transparent_hugepage/hpage_pmd_size'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap" name="/proc/version" pid=39687 comm="jami" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /proc/version (read)
- Suggestion:
- * adjust program to not access '@{PROC}/version'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap" name="/proc/cmdline" pid=39687 comm="jami" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /proc/cmdline (read)
- Suggestion:
- * adjust program to not access '@{PROC}/cmdline'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap" name="/snap/snapd/10707/usr/lib/snapd/info" pid=39687 comm="jami" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /snap/snapd/10707/usr/lib/snapd/info (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap" name="/snap/snapd/10707/usr/bin/snap" pid=39687 comm="jami" requested_mask="x" denied_mask="x" fsuid=1000 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap"
- File: /snap/snapd/10707/usr/bin/snap (exec)
- Suggestions:
- * adjust snap to ship 'snap'
- * adjust program to use relative paths if the snap already ships 'snap'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/snap/snapd/10707/usr/bin/snap" pid=39687 comm="snap" requested_mask="rm" denied_mask="rm" fsuid=1000 ouid=0
- File: /snap/snapd/10707/usr/bin/snap (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/etc/ld.so.cache" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/usr/lib/x86_64-linux-gnu/libpthread-2.31.so" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libpthread-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/usr/lib/x86_64-linux-gnu/libpthread-2.31.so" pid=39687 comm="snap" requested_mask="rm" denied_mask="rm" fsuid=1000 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libpthread-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39687 comm="snap" requested_mask="rm" denied_mask="rm" fsuid=1000 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/usr/lib/os-release" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /usr/lib/os-release (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/proc/version" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /proc/version (read)
- Suggestion:
- * adjust program to not access '@{PROC}/version'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/proc/sys/net/core/somaxconn" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /proc/sys/net/core/somaxconn (read)
- Suggestions:
- * adjust program to not access '@{PROC}/sys/net/core/somaxconn'
- * add one of 'firewall-control, network-control, network-observe' to 'plugs'
- * add one of 'network, network-bind' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/usr/share/locale-langpack/ru/LC_MESSAGES/snappy.mo" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /usr/share/locale-langpack/ru/LC_MESSAGES/snappy.mo (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/proc/cmdline" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /proc/cmdline (read)
- Suggestion:
- * adjust program to not access '@{PROC}/cmdline'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/snap/snapd/10707/usr/lib/snapd/snapd" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /snap/snapd/10707/usr/lib/snapd/snapd (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/sys/kernel/security/apparmor/features/" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /sys/kernel/security/apparmor/features/ (read)
- Suggestion:
- * adjust program to not access '/sys/kernel/security/apparmor/features/'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/proc/39687/mountinfo" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000
- File: /proc/39687/mountinfo (read)
- Suggestions:
- * adjust program to not access '@{PROC}/@{pid}/mountinfo'
- * add 'mount-observe' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/etc/fstab" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /etc/fstab (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'mount-observe' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/proc/39687/mountinfo" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000
- File: /proc/39687/mountinfo (read)
- Suggestions:
- * adjust program to not access '@{PROC}/@{pid}/mountinfo'
- * add 'mount-observe' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/proc/sys/kernel/seccomp/actions_avail" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /proc/sys/kernel/seccomp/actions_avail (read)
- Suggestion:
- * adjust program to not access '@{PROC}/sys/kernel/seccomp/actions_avail'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/dev/null" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /dev/null (read)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/snap/snapd/10707/usr/lib/snapd/snap-seccomp" pid=39699 comm="snap" requested_mask="x" denied_mask="x" fsuid=1000 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-seccomp"
- File: /snap/snapd/10707/usr/lib/snapd/snap-seccomp (exec)
- Suggestions:
- * adjust snap to ship 'snap-seccomp'
- * adjust program to use relative paths if the snap already ships 'snap-seccomp'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_inherit" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-seccomp" name="/dev/null" pid=39699 comm="snap-seccomp" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /dev/null (read)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-seccomp" name="/snap/snapd/10707/usr/lib/snapd/snap-seccomp" pid=39699 comm="snap-seccomp" requested_mask="rm" denied_mask="rm" fsuid=1000 ouid=0
- File: /snap/snapd/10707/usr/lib/snapd/snap-seccomp (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-seccomp" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39699 comm="snap-seccomp" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-seccomp" name="/etc/ld.so.cache" pid=39699 comm="snap-seccomp" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-seccomp" name="/usr/lib/x86_64-linux-gnu/libpthread-2.31.so" pid=39699 comm="snap-seccomp" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libpthread-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-seccomp" name="/usr/lib/x86_64-linux-gnu/libpthread-2.31.so" pid=39699 comm="snap-seccomp" requested_mask="rm" denied_mask="rm" fsuid=1000 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libpthread-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-seccomp" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39699 comm="snap-seccomp" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-seccomp" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39699 comm="snap-seccomp" requested_mask="rm" denied_mask="rm" fsuid=1000 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-seccomp" name="/proc/sys/net/core/somaxconn" pid=39699 comm="snap-seccomp" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /proc/sys/net/core/somaxconn (read)
- Suggestions:
- * adjust program to not access '@{PROC}/sys/net/core/somaxconn'
- * add one of 'firewall-control, network-control, network-observe' to 'plugs'
- * add one of 'network, network-bind' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-seccomp" name="/snap/snapd/10707/usr/lib/snapd/snap-seccomp" pid=39699 comm="snap-seccomp" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /snap/snapd/10707/usr/lib/snapd/snap-seccomp (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/var/lib/snapd/system-key" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /var/lib/snapd/system-key (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/snap/jami/112/meta/snap.yaml" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /snap/jami/112/meta/snap.yaml (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/etc/nsswitch.conf" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /etc/nsswitch.conf (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * add one of 'firewall-control, fwupd, network, network-bind, network-control, network-observe' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/etc/ld.so.cache" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/usr/lib/x86_64-linux-gnu/libnss_files-2.31.so" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libnss_files-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/usr/lib/x86_64-linux-gnu/libnss_files-2.31.so" pid=39687 comm="snap" requested_mask="rm" denied_mask="rm" fsuid=1000 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libnss_files-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/etc/passwd" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /etc/passwd (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * add one of 'firewall-control, fwupd, network, network-bind, network-control, network-observe' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/proc/39687/mountinfo" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000
- File: /proc/39687/mountinfo (read)
- Suggestions:
- * adjust program to not access '@{PROC}/@{pid}/mountinfo'
- * add 'mount-observe' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/run/user/1000/gdm/Xauthority" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000
- File: /run/user/1000/gdm/Xauthority (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/proc/39687/mountinfo" pid=39687 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000
- File: /proc/39687/mountinfo (read)
- Suggestions:
- * adjust program to not access '@{PROC}/@{pid}/mountinfo'
- * add 'mount-observe' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap" name="/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39687 comm="snap" requested_mask="x" denied_mask="x" fsuid=1000 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine"
- File: /snap/snapd/10707/usr/lib/snapd/snap-confine (exec)
- Suggestions:
- * adjust snap to ship 'snap-confine'
- * adjust program to use relative paths if the snap already ships 'snap-confine'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39687 comm="snap-confine" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /snap/snapd/10707/usr/lib/snapd/snap-confine (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/etc/ld.so.cache" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/x86_64-linux-gnu/libudev.so.1.6.17" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libudev.so.1.6.17 (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/x86_64-linux-gnu/libudev.so.1.6.17" pid=39687 comm="snap-confine" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libudev.so.1.6.17 (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/x86_64-linux-gnu/libpthread-2.31.so" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libpthread-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/x86_64-linux-gnu/libpthread-2.31.so" pid=39687 comm="snap-confine" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libpthread-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39687 comm="snap-confine" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/var/lib/snapd/cookie/snap.jami" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /var/lib/snapd/cookie/snap.jami (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/proc/39687/mounts" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /proc/39687/mounts (read)
- Suggestions:
- * adjust program to not access '@{PROC}/@{pid}/mounts'
- * add one of 'mount-observe, network-control' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/proc/39687/attr/current" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /proc/39687/attr/current (read)
- Suggestion:
- * adjust program to not access '@{PROC}/@{pid}/attr/current'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39687 comm="snap-confine" capability=19 capname="sys_ptrace"
- Capability: sys_ptrace
- Suggestions:
- * adjust program to not require 'CAP_SYS_PTRACE' (see 'man 7 capabilities')
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: / (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * add 'network-control' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add one of 'network-setup-control, removable-media' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/snapd/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/snapd/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/snapd/lock/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/snapd/lock/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/snapd/lock/.lock" pid=39687 comm="snap-confine" requested_mask="wrc" denied_mask="wrc" fsuid=0 ouid=0
- File: /run/snapd/lock/.lock (write)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_lock" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/snapd/lock/.lock" pid=39687 comm="snap-confine" requested_mask="wk" denied_mask="wk" fsuid=0 ouid=0
- File: /run/snapd/lock/.lock (write)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/proc/39687/mountinfo" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /proc/39687/mountinfo (read)
- Suggestions:
- * adjust program to not access '@{PROC}/@{pid}/mountinfo'
- * add 'mount-observe' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: / (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * add 'network-control' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add one of 'network-setup-control, removable-media' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/snapd/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/snapd/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/snapd/ns/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/snapd/ns/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/proc/39687/mountinfo" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /proc/39687/mountinfo (read)
- Suggestions:
- * adjust program to not access '@{PROC}/@{pid}/mountinfo'
- * add 'mount-observe' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: / (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * add 'network-control' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add one of 'network-setup-control, removable-media' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/snapd/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/snapd/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/snapd/lock/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/snapd/lock/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/snapd/lock/jami.lock" pid=39687 comm="snap-confine" requested_mask="wrc" denied_mask="wrc" fsuid=0 ouid=0
- File: /run/snapd/lock/jami.lock (write)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_lock" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/snapd/lock/jami.lock" pid=39687 comm="snap-confine" requested_mask="wk" denied_mask="wk" fsuid=0 ouid=0
- File: /run/snapd/lock/jami.lock (write)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/udev/tags/snap_jami_jami/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/udev/tags/snap_jami_jami/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/fs/cgroup/devices/snap.jami.jami/cgroup.procs" pid=39687 comm="snap-confine" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/cgroup.procs (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/cgroup.procs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/fs/cgroup/devices/snap.jami.jami/cgroup.procs" pid=39687 comm="snap-confine" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/cgroup.procs (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/cgroup.procs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.deny" pid=39687 comm="snap-confine" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.deny (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.deny'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.deny" pid=39687 comm="snap-confine" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.deny (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.deny'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39705 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39705 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39705 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39705 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39705 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39705 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39705 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39705 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39705 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39705 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39706 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39706 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39706 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39706 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39706 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39706 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39706 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39706 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39706 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39706 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39707 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39707 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39707 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39707 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39707 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39707 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39707 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39707 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39707 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39707 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39707 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39708 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39708 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39708 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39708 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39708 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39708 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39708 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39708 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39708 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39708 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39708 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39709 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39709 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39709 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39709 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39709 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39709 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39709 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39709 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39709 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39709 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39709 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39710 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39710 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39710 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39710 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39710 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39710 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39710 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39710 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39710 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39710 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39710 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39711 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39711 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39711 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39711 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39711 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39711 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39711 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39711 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39711 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39711 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39711 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39712 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39712 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39712 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39712 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39712 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39712 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39712 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39712 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39712 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39712 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39712 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39713 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39713 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39713 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39713 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39713 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39713 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39713 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39713 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39713 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39713 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39713 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39714 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39714 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39714 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39714 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39714 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39714 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39714 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39714 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39714 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39714 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39714 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39715 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39715 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39715 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39715 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39715 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39715 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39715 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39715 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39715 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39715 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39715 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39716 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39716 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39716 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39716 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39716 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39716 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39716 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39716 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39716 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39716 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39716 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39717 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39717 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39717 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39717 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39717 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39717 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39717 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39717 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39717 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39717 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39717 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39718 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39718 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39718 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39718 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39718 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39718 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39718 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39718 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39718 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39718 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39718 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39719 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39719 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39719 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39719 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39719 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39719 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39719 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39719 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39719 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39719 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39719 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39720 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39720 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39720 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39720 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39720 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39720 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39720 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39720 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39720 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39720 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39720 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39721 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39721 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39721 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39721 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39721 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39721 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39721 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39721 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39721 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39721 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39721 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39722 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39722 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39722 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39722 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39722 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39722 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39722 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39722 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39722 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39722 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39722 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/devices/pci0000:00/0000:00:02.0/drm/card0/uevent" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /sys/devices/pci0000:00/0000:00:02.0/drm/card0/uevent (read)
- Suggestions:
- * adjust program to not access '/sys/devices/pci0000:00/0000:00:02.0/drm/card0/uevent'
- * adjust program to not access '/sys/devices/pci[0-9]*:[0-9]*/[0-9]*:[0-9]*:[0-9]*.[0-9]*/drm/card[0-9]*/uevent'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39723 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39723 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39723 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39723 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39723 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39723 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39723 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39723 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39723 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39723 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39723 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-DP-1/uevent" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-DP-1/uevent (read)
- Suggestions:
- * adjust program to not access '/sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-DP-1/uevent'
- * adjust program to not access '/sys/devices/pci[0-9]*:[0-9]*/[0-9]*:[0-9]*:[0-9]*.[0-9]*/drm/card[0-9]*/card[0-9]*-DP-[0-9]*/uevent'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-DP-2/uevent" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-DP-2/uevent (read)
- Suggestions:
- * adjust program to not access '/sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-DP-2/uevent'
- * adjust program to not access '/sys/devices/pci[0-9]*:[0-9]*/[0-9]*:[0-9]*:[0-9]*.[0-9]*/drm/card[0-9]*/card[0-9]*-DP-[0-9]*/uevent'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-DP-3/uevent" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-DP-3/uevent (read)
- Suggestions:
- * adjust program to not access '/sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-DP-3/uevent'
- * adjust program to not access '/sys/devices/pci[0-9]*:[0-9]*/[0-9]*:[0-9]*:[0-9]*.[0-9]*/drm/card[0-9]*/card[0-9]*-DP-[0-9]*/uevent'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-HDMI-A-1/uevent" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-HDMI-A-1/uevent (read)
- Suggestions:
- * adjust program to not access '/sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-HDMI-A-1/uevent'
- * adjust program to not access '/sys/devices/pci[0-9]*:[0-9]*/[0-9]*:[0-9]*:[0-9]*.[0-9]*/drm/card[0-9]*/card[0-9]*-HDMI-A-[0-9]*/uevent'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-HDMI-A-2/uevent" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-HDMI-A-2/uevent (read)
- Suggestions:
- * adjust program to not access '/sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-HDMI-A-2/uevent'
- * adjust program to not access '/sys/devices/pci[0-9]*:[0-9]*/[0-9]*:[0-9]*:[0-9]*.[0-9]*/drm/card[0-9]*/card[0-9]*-HDMI-A-[0-9]*/uevent'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-HDMI-A-3/uevent" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-HDMI-A-3/uevent (read)
- Suggestions:
- * adjust program to not access '/sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-HDMI-A-3/uevent'
- * adjust program to not access '/sys/devices/pci[0-9]*:[0-9]*/[0-9]*:[0-9]*:[0-9]*.[0-9]*/drm/card[0-9]*/card[0-9]*-HDMI-A-[0-9]*/uevent'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-LVDS-1/uevent" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-LVDS-1/uevent (read)
- Suggestions:
- * adjust program to not access '/sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-LVDS-1/uevent'
- * adjust program to not access '/sys/devices/pci[0-9]*:[0-9]*/[0-9]*:[0-9]*:[0-9]*.[0-9]*/drm/card[0-9]*/card[0-9]*-LVDS-[0-9]*/uevent'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-VGA-1/uevent" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-VGA-1/uevent (read)
- Suggestions:
- * adjust program to not access '/sys/devices/pci0000:00/0000:00:02.0/drm/card0/card0-VGA-1/uevent'
- * adjust program to not access '/sys/devices/pci[0-9]*:[0-9]*/[0-9]*:[0-9]*:[0-9]*.[0-9]*/drm/card[0-9]*/card[0-9]*-VGA-[0-9]*/uevent'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/devices/pci0000:00/0000:00:02.0/drm/renderD128/uevent" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /sys/devices/pci0000:00/0000:00:02.0/drm/renderD128/uevent (read)
- Suggestions:
- * adjust program to not access '/sys/devices/pci0000:00/0000:00:02.0/drm/renderD128/uevent'
- * adjust program to not access '/sys/devices/pci[0-9]*:[0-9]*/[0-9]*:[0-9]*:[0-9]*.[0-9]*/drm/renderD[0-9]*/uevent'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39724 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39724 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39724 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39724 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39724 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39724 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39724 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39724 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39724 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39724 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39724 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/devices/pci0000:00/0000:00:1a.0/usb1/1-1/1-1.6/1-1.6:1.0/video4linux/video0/uevent" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /sys/devices/pci0000:00/0000:00:1a.0/usb1/1-1/1-1.6/1-1.6:1.0/video4linux/video0/uevent (read)
- Suggestions:
- * adjust program to not access '/sys/devices/pci0000:00/0000:00:1a.0/usb1/1-1/1-1.6/1-1.6:1.0/video4linux/video0/uevent'
- * adjust program to not access '/sys/devices/pci[0-9]*:[0-9]*/[0-9]*:[0-9]*:[0-9]*a.[0-9]*/usb[0-9]*/[0-9]*-[0-9]*/[0-9]*-[0-9]*.[0-9]*/[0-9]*-[0-9]*.[0-9]*:[0-9]*.[0-9]*/video[0-9]*linux/video[0-9]*/uevent'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39725 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39725 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39725 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39725 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39725 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39725 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39725 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39725 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39725 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39725 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39725 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/devices/pci0000:00/0000:00:1a.0/usb1/1-1/1-1.6/1-1.6:1.0/video4linux/video1/uevent" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /sys/devices/pci0000:00/0000:00:1a.0/usb1/1-1/1-1.6/1-1.6:1.0/video4linux/video1/uevent (read)
- Suggestions:
- * adjust program to not access '/sys/devices/pci0000:00/0000:00:1a.0/usb1/1-1/1-1.6/1-1.6:1.0/video4linux/video1/uevent'
- * adjust program to not access '/sys/devices/pci[0-9]*:[0-9]*/[0-9]*:[0-9]*:[0-9]*a.[0-9]*/usb[0-9]*/[0-9]*-[0-9]*/[0-9]*-[0-9]*.[0-9]*/[0-9]*-[0-9]*.[0-9]*:[0-9]*.[0-9]*/video[0-9]*linux/video[0-9]*/uevent'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39726 comm="snap-confine" capability=7 capname="setuid"
- Capability: setuid
- Suggestions:
- * adjust program to not require 'CAP_SETUID' (see 'man 7 capabilities')
- * add one of 'firewall-control, network-control, network-observe, ppp' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/snapd/snap-device-helper" pid=39726 comm="snap-confine" requested_mask="x" denied_mask="x" fsuid=0 ouid=0 target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper"
- File: /usr/lib/snapd/snap-device-helper (exec)
- Suggestions:
- * adjust snap to ship 'snap-device-helper'
- * adjust program to use relative paths if the snap already ships 'snap-device-helper'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/bin/dash" pid=39726 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/bin/dash (read)
- Suggestions:
- * adjust snap to ship 'dash'
- * adjust program to use relative paths if the snap already ships 'dash'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/ld-2.31.so" pid=39726 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/ld-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/etc/ld.so.cache" pid=39726 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /etc/ld.so.cache (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'system-files (see https://forum.snapcraft.io/t/the-system-files-interface for acceptance criteria)' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39726 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="file_mmap" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/x86_64-linux-gnu/libc-2.31.so" pid=39726 comm="snap-device-hel" requested_mask="rm" denied_mask="rm" fsuid=0 ouid=0
- File: /usr/lib/x86_64-linux-gnu/libc-2.31.so (mmap)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/usr/lib/snapd/snap-device-helper" pid=39726 comm="snap-device-hel" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/snapd/snap-device-helper (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39726 comm="snap-device-hel" requested_mask="wc" denied_mask="wc" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="truncate" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" name="/sys/fs/cgroup/devices/snap.jami.jami/devices.allow" pid=39726 comm="snap-device-hel" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/devices/snap.jami.jami/devices.allow (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/devices/snap.jami.jami/devices.allow'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-/usr/lib/snapd/snap-device-helper" pid=39726 comm="snap-device-hel" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/usr/lib/os-release" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /usr/lib/os-release (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/snapd/ns/jami.mnt" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/snapd/ns/jami.mnt (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/proc/39687/mountinfo" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /proc/39687/mountinfo (read)
- Suggestions:
- * adjust program to not access '@{PROC}/@{pid}/mountinfo'
- * add 'mount-observe' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/proc/39727/attr/current" pid=39727 comm="snap-confine" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /proc/39727/attr/current (write)
- Suggestion:
- * adjust program to not access '@{PROC}/@{pid}/attr/current'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="change_hat" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="mount-namespace-capture-helper" pid=39727 comm="snap-confine" target="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine//null-mount-namespace-capture-helper"
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="capable" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" pid=39728 comm="snap-confine" capability=21 capname="sys_admin"
- Capability: sys_admin
- Suggestions:
- * adjust program to not require 'CAP_SYS_ADMIN' (see 'man 7 capabilities')
- * add one of 'cifs-mount, fuse-support, hardware-observe, hostname-control, network-control, system-trace' to 'plugs'
- * do nothing if program otherwise works properly
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/proc/39728/mountinfo" pid=39728 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /proc/39728/mountinfo (read)
- Suggestions:
- * adjust program to not access '@{PROC}/@{pid}/mountinfo'
- * add 'mount-observe' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/snapd/ns/snap.jami.info" pid=39728 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/snapd/ns/snap.jami.info (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/udev/tags/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/udev/tags/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/udev/tags/snap_snap-store_ubuntu-software/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/udev/tags/snap_snap-store_ubuntu-software/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/udev/tags/snap_snap-store_ubuntu-software-local-file/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/udev/tags/snap_snap-store_ubuntu-software-local-file/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/udev/tags/snap_krdc_krdc/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/udev/tags/snap_krdc_krdc/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/udev/tags/snap_snap-store_snap-store/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/udev/tags/snap_snap-store_snap-store/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/udev/tags/snap_jami_jami/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/udev/tags/snap_jami_jami/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/udev/tags/snap_telegram-desktop_telegram-desktop/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/udev/tags/snap_telegram-desktop_telegram-desktop/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/run/udev/tags/snap_discord_discord/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
- File: /run/udev/tags/snap_discord_discord/ (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/proc/39729/attr/exec" pid=39729 comm="snap-confine" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /proc/39729/attr/exec (write)
- Suggestion:
- * adjust program to not access '@{PROC}/@{pid}/attr/exec'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="change_onexec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="snap-update-ns.jami" pid=39729 comm="snap-confine" target="snap-update-ns.jami"
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="exec" info="Failed name lookup - disconnected path" error=-13 profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/dev/fd/5" pid=39729 comm="snap-confine" target="snap-update-ns.jami"
- File: /dev/fd/5 (exec)
- Suggestions:
- * adjust snap to ship '5'
- * adjust program to use relative paths if the snap already ships '5'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/sys/fs/cgroup/freezer/snap.jami/cgroup.procs" pid=39687 comm="snap-confine" requested_mask="w" denied_mask="w" fsuid=0 ouid=0
- File: /sys/fs/cgroup/freezer/snap.jami/cgroup.procs (write)
- Suggestion:
- * adjust program to not access '/sys/fs/cgroup/freezer/snap.jami/cgroup.procs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: / (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * add 'network-control' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/home/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /home/ (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/home/artem/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000
- File: /home/artem/ (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * add 'home' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/home/artem/snap/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000
- File: /home/artem/snap/ (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * add 'home' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/home/artem/snap/jami/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000
- File: /home/artem/snap/jami/ (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/home/artem/snap/jami/112/" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000
- File: /home/artem/snap/jami/112/ (read)
- Suggestion:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/proc/39687/attr/exec" pid=39687 comm="snap-confine" requested_mask="w" denied_mask="w" fsuid=1000 ouid=0
- File: /proc/39687/attr/exec (write)
- Suggestion:
- * adjust program to not access '@{PROC}/@{pid}/attr/exec'
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="change_onexec" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="snap.jami.jami" pid=39687 comm="snap-confine" target="snap.jami.jami"
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/var/lib/snapd/seccomp/bpf/snap.jami.jami.bin" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /var/lib/snapd/seccomp/bpf/snap.jami.jami.bin (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:54:58
- Log: apparmor="ALLOWED" operation="open" profile="/usr/bin/snap//null-/snap/snapd/10707/usr/bin/snap//null-/snap/snapd/10707/usr/lib/snapd/snap-confine" name="/var/lib/snapd/seccomp/bpf/global.bin" pid=39687 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /var/lib/snapd/seccomp/bpf/global.bin (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = Seccomp =
- Time: Jan 5 11:54:59
- Log: auid=1000 uid=1000 gid=1000 ses=3 pid=39687 comm="jami-gnome" exe="/snap/jami/112/usr/bin/jami-gnome" sig=0 arch=c000003e 203(sched_setaffinity) compat=0 ip=0x7fa57ebcdc7f code=0x50000
- Syscall: sched_setaffinity
- Suggestion:
- * add 'process-control' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:59
- Log: apparmor="DENIED" operation="open" profile="snap.jami.jami" name="/etc/fstab" pid=39687 comm="jami-gnome" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /etc/fstab (read)
- Suggestions:
- * adjust program to read necessary files from $SNAP, $SNAP_DATA, $SNAP_COMMON, $SNAP_USER_DATA or $SNAP_USER_COMMON
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- * add 'mount-observe' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:54:59
- Log: apparmor="DENIED" operation="open" profile="snap.jami.jami" name="/run/mount/utab" pid=39687 comm="jami-gnome" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /run/mount/utab (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:55:00
- Log: apparmor="DENIED" operation="dbus_method_call" bus="system" path="/org/freedesktop/NetworkManager" interface="org.freedesktop.DBus.Properties" member="GetAll" mask="send" name=":1.12" pid=39849 label="snap.jami.jami" peer_pid=559 peer_label="unconfined"
- DBus access
- Suggestion:
- * try adding one of 'network-manager, network-manager-observe' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:55:00
- Log: apparmor="DENIED" operation="open" profile="snap.jami.jami" name="/run/mount/utab" pid=39687 comm="jami-gnome" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /run/mount/utab (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:55:00
- Log: apparmor="DENIED" operation="dbus_signal" bus="session" path="/StatusNotifierWatcher" interface="org.kde.StatusNotifierWatcher" member="StatusNotifierItemRegistered" name=":1.43" mask="receive" pid=2315 label="snap.telegram-desktop.telegram-desktop" peer_pid=2133 peer_label="unconfined"
- DBus access
- = AppArmor =
- Time: Jan 5 11:55:00
- Log: apparmor="DENIED" operation="dbus_signal" bus="session" path="/StatusNotifierWatcher" interface="org.freedesktop.DBus.Properties" member="PropertiesChanged" name=":1.43" mask="receive" pid=2315 label="snap.telegram-desktop.telegram-desktop" peer_pid=2133 peer_label="unconfined"
- DBus access
- = AppArmor =
- Time: Jan 5 11:55:00
- Log: apparmor="DENIED" operation="open" profile="snap.jami.jami" name="/run/mount/utab" pid=39687 comm="jami-gnome" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
- File: /run/mount/utab (read)
- Suggestions:
- * adjust program to use $SNAP_DATA
- * adjust program to use /run/shm/snap.$SNAP_NAME.*
- * adjust program to use /run/snap.$SNAP_NAME.*
- * adjust snap to use snap layouts (https://forum.snapcraft.io/t/snap-layouts/7207)
- = AppArmor =
- Time: Jan 5 11:55:00
- Log: apparmor="DENIED" operation="dbus_method_call" bus="system" path="/org/freedesktop/hostname1" interface="org.freedesktop.DBus.Properties" member="GetAll" mask="send" name=":1.145" pid=39687 label="snap.jami.jami" peer_pid=39856 peer_label="unconfined"
- DBus access
- Suggestion:
- * try adding 'hostname-control' to 'plugs'
- = AppArmor =
- Time: Jan 5 11:55:00
- Log: apparmor="DENIED" operation="dbus_method_call" bus="system" path="/org/freedesktop/UPower/devices/DisplayDevice" interface="org.freedesktop.DBus.Properties" member="GetAll" mask="send" name=":1.43" pid=39848 label="snap.jami.jami" peer_pid=1331 peer_label="unconfined"
- DBus access
- Suggestion:
- * try adding 'upower-observe' to 'plugs'
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement