/sys/kernel/security/apparmor/profiles 设置为 -r--r--r-- 但非 root 用户无法读取

/sys/kernel/security/apparmor/profiles 设置为 -r--r--r-- 但非 root 用户无法读取

我尝试从 gnome-boxes 3.28 升级到 3.32,但它一直崩溃,因为 libvirtd 无法访问:

/sys/内核/安全/apparmor/profiles

这是终端输出:

user1@pts:~: gnome-boxes 
(gnome-boxes:10186): Boxes-WARNING **: 17:52:06.148: util-app.vala:178: Failed to find OS with id: 'http://redhat.com/rhel/7.6': Unknown OS ID 'http://redhat.com/rhel/7.6'

(gnome-boxes:10186): Boxes-WARNING **: 17:52:06.149: util-app.vala:178: Failed to find OS with id: 'http://redhat.com/rhel/7.6': Unknown OS ID 'http://redhat.com/rhel/7.6'
Segmentation fault

journalctl 给出(最新的一行在最上面,最旧的一行在最下面):

Sep 15 17:52:06 user1-Dell libvirtd[967]: End of file while reading data: Input/output error
Sep 15 17:52:06 user1-Dell libvirtd[10215]: End of file while reading data: Input/output error
Sep 15 17:52:06 user1-Dell kernel: gnome-boxes[10186]: segfault at 0 ip 00007fa5f804aeb1 sp 00007ffc5b9c5a78 error 4 in libosinfo-1.0.so.0.1006.0[7fa5f8047000+1
Sep 15 17:52:06 user1-Dell systemd[1]: Started Hostname Service.
Sep 15 17:52:06 user1-Dell dbus-daemon[818]: [system] Successfully activated service 'org.freedesktop.hostname1'
Sep 15 17:52:05 user1-Dell libvirtd[10215]: Failed to read AppArmor profiles list '/sys/kernel/security/apparmor/profiles': Permission denied
Sep 15 17:52:05 user1-Dell libvirtd[10215]: Failed to open file '/sys/kernel/security/apparmor/profiles': Permission denied
Sep 15 17:52:05 user1-Dell libvirtd[10215]: Failed to read AppArmor profiles list '/sys/kernel/security/apparmor/profiles': Permission denied
Sep 15 17:52:05 user1-Dell libvirtd[10215]: Failed to open file '/sys/kernel/security/apparmor/profiles': Permission denied
Sep 15 17:52:05 user1-Dell libvirtd[10215]: hostname: user1-Dell
Sep 15 17:52:05 user1-Dell libvirtd[10215]: libvirt version: 5.4.0, package: 0ubuntu5 (Matthias Klose <[email protected]> Thu, 05 Sep 2019 11:00:53 +0000)

以 root 身份,我检查了此文件的权限,发现它的权限为 -r--r--r--,其所有父目录的权限也是如此。我能够以 root 身份读取其内容,但非 wheel 用户尝试对该文件使用 cat 时,出现了权限被拒绝的错误。

这是 ubuntu 中的一个错误还是我这里遗漏了什么?

相关内容