Join GitHub today
GitHub is home to over 20 million developers working together to host and review code, manage projects, and build software together.
Anbox 46 snap-confine has elevated permissions and is not confined but should be #386
Comments
zyga
commented
Jul 28, 2017
•
|
Hey, snap-confine author here. That message means that you have apparmor built into your kernel and enabled but for whatever reason snap-confine is running without confinement. This is a security measure to ensure that nobody can attack the confinement and somehow unconfine snap-confine by running it with the path from the core snap (where it is setuid-root). Can you tell me more about your system please? Start with |
grandtoubab
commented
Jul 28, 2017
•
|
I am running on Debian 10 Buster with apparmor activated
|
lal12
commented
Jul 31, 2017
|
I had the same issue. It seems that no app armor profile for snap is created. I made it work by I guess in terms of security not the optimal solution, ... |
zyga
commented
Aug 1, 2017
|
@lal12 the profile should not apply to |
zyga
commented
Aug 1, 2017
•
|
@grandtoubab This explains everything, thank you! The crux of the issue is disconnect between snap-confine and snapd. Snapd doesn't generate the apparmor profile for snap-confine but snap-confine is compiled with apparmor enabled and expects to be confined since apparmor is also enabled on boot. Unfortunately this situation is unsupported until Linux 4.14 is released. Right now there is no easy way. |
grandtoubab
commented
Aug 1, 2017
|
Hello
and it seems it is not true as the profile is not found in unconfined
so maybe this line is wrong /usr/lib/snapd/snap-exec uxr ? |
grandtoubab
commented
Aug 1, 2017
|
I modify /etc/apparmor.d/usr.lib.snapd.snap-confine this way
and now I get
|
|
I am closing this one as it's not an issue with anbox but with snapd. |
morphis
closed this
Aug 2, 2017
david2896482
commented
Aug 4, 2017
|
@grandtoubab hi I encountered the same problem on my odroid C1 board (armhf). |
grandtoubab
commented
Aug 5, 2017
|
As expalin above snapd is dependant on the kernel version. and Anbox is not a mature project. Not functionnal everywhere so I gave up. |
david2896482
commented
Aug 5, 2017
|
@grandtoubab Okay thanks for your help. Sorry for my English.. |
grandtoubab commentedJul 28, 2017
Problem : nothing starts