Ubuntu Bionic AWS EC2实例中AppArmor全系统实现的问题求助
Hi there, let's work through your AppArmor full system setup issues on Ubuntu Bionic EC2 instances together. I'll break down practical solutions for both of your questions:
1. 解决udevd和timesyncd导致的启动失败问题
The core issue here is that systemd-udevd and systemd-timesyncd run extremely early in the boot process (even before the root filesystem is fully mounted in some cases) and rely on specific permissions to function properly. Empty complain-mode profiles might still block critical operations, so here's how to fix this:
Add minimal complain-mode profiles for these services to your initramfs script
Update your/etc/initramfs-tools/scripts/init-bottom/apparmorfile to include entries for both services alongside your existing ones:echo "profile init-systemd /lib/systemd/systemd-udevd flags=(complain) {}" | /sbin/apparmor_parser -a echo "profile init-systemd /lib/systemd/systemd-timesyncd flags=(complain) {}" | /sbin/apparmor_parser -a # Keep your existing profiles echo "profile init-systemd /lib/systemd/systemd-logind flags=(complain) {}" | /sbin/apparmor_parser -a echo "profile lib-systemd-systemd-journald /lib/systemd/systemd-journald flags=(complain) {}" | /sbin/apparmor_parser -a echo "profile init-systemd /lib/systemd/systemd flags=(complain) {}" | /sbin/apparmor_parser -aRegenerate initramfs and reboot
Apply the changes to your initramfs with this command:update-initramfs -uReboot your EC2 instance next. Complain mode will let the services run while logging all permission denials, so your system should boot successfully now.
Capture required permissions from logs
After rebooting, collect AppArmor denial logs to identify what permissions these services need:- Check kernel logs for quick insights:
dmesg | grep -i apparmor - Use systemd journal for more detailed entries:
journalctl -t apparmor | grep DENIED
For
systemd-udevd, you'll likely see requests for access to/devnodes,/sysfilesystem paths, and proc entries. Forsystemd-timesyncd, expect network access, read access to time-related config files (like/etc/systemd/timesyncd.conf), and write access to its state directory (/var/lib/systemd/timesync/).- Check kernel logs for quick insights:
Refine the profiles
Add the required permissions to each profile in your initramfs script. For example, a basicsystemd-udevdprofile might look like:echo "profile init-systemd /lib/systemd/systemd-udevd flags=(complain) { /dev/** rw, /sys/** rw, /proc/** r, /lib/systemd/systemd-udevd mr, # Add other specific paths pulled from logs here }" | /sbin/apparmor_parser -aRegenerate the initramfs again after updating profiles, and repeat until no more critical denials appear.
2. 如何确定空配置文件中应添加的权限
Building a deny-all, permit-by-exception policy relies on systematically capturing and whitelisting only the permissions your processes actually need. Here's the most effective approach:
Stay in complain mode initially
Complain mode is your safest starting point—it logs all denied operations without blocking them, letting you build profiles incrementally without breaking the system.Use AppArmor's built-in log tools
Manual log checking works, but these tools streamline the process:aa-logprof: Scans denial logs and walks you through adding rules to your profiles. Note that for initramfs profiles, you'll need to copy generated rules into your init-bottom script instead of using default profile paths.aa-genprof: If starting with an empty profile, this tool launches a process and captures its permissions in real-time. For initramfs services, run this after boot by reloading the profile in complain mode and triggering the service's operations.
Follow the principle of least privilege
Only add the specific permissions you see in denial logs—avoid broad rules like/** rwunless absolutely necessary. For example, ifsystemd-timesyncdonly needs to read/etc/systemd/timesyncd.conf, add/etc/systemd/timesyncd.conf r,instead of/etc/** r,.Test in enforce mode gradually
Once you've captured all necessary permissions in complain mode, switch profile flags from(complain)to(enforce)one at a time. Reboot and check logs to ensure no critical operations are blocked. If something breaks, switch back to complain mode and adjust the profile.
Feel free to reach out if you hit specific snags while collecting logs or refining your profiles—I can help troubleshoot further!
备注:内容来源于stack exchange,提问作者user596374

