Bug#1060378: cups-daemon: apparmor denies net_admin capability
Package: cups-daemon
Version: 2.4.7-1
Severity: normal
Hello,
I see a lot of denials from apparmor regarding net_admin capability:
type=AVC msg=audit(1704872737.703:1422): apparmor="DENIED" operation="capable" class="cap" profile="/usr/sbin/cupsd" pid=149384 comm="cupsd" capability=12 capname="net_admin"
Not too sure what part requires it, but I guess it should be either
allowed or the audit trail should be suppressed
Kind regards,
Laurent Bigonville
-- System Information:
Debian Release: trixie/sid
APT prefers unstable-debug
APT policy: (500, 'unstable-debug'), (500, 'unstable'), (1, 'experimental-debug'), (1, 'experimental')
Architecture: amd64 (x86_64)
Kernel: Linux 6.6.9-amd64 (SMP w/12 CPU threads; PREEMPT)
Kernel taint flags: TAINT_WARN
Locale: LANG=fr_BE.UTF-8, LC_CTYPE=fr_BE.UTF-8 (charmap=UTF-8), LANGUAGE=fr_BE:fr
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages cups-daemon depends on:
ii adduser 3.137
ii bc 1.07.1-3+b1
ii init-system-helpers 1.66
ii libavahi-client3 0.8-13+b1
ii libavahi-common3 0.8-13+b1
ii libc6 2.37-13
ii libcups2 2.4.7-1+b1
ii libdbus-1-3 1.14.10-4
ii libgssapi-krb5-2 1.20.1-5
ii libpam0g 1.5.2-9.1+b1
ii libpaper1 1.1.29
ii libsystemd0 255.2-4
ii procps 2:4.0.4-2+b1
ii ssl-cert 1.1.2
ii sysvinit-utils [lsb-base] 3.08-5
Versions of packages cups-daemon recommends:
ii avahi-daemon 0.8-13+b1
ii colord 1.4.6-5
ii cups-browsed 1.28.17-3+b1
ii ipp-usb 0.9.23-1+b7
Versions of packages cups-daemon suggests:
ii cups 2.4.7-1+b1
pn cups-bsd <none>
ii cups-client 2.4.7-1+b1
ii cups-common 2.4.7-1
ii cups-filters 1.28.17-3+b1
pn cups-pdf <none>
ii cups-ppdc 2.4.7-1+b1
ii cups-server-common 2.4.7-1
pn foomatic-db-compressed-ppds | foomatic-db <none>
ii ghostscript 10.02.1~dfsg-2
ii poppler-utils 22.12.0-2+b1
pn smbclient <none>
ii udev 255.2-4
-- no debconf information
Reply to: