AppArmor WARN aa_audit_file: ((!(&sa)->apparmor_audit_data->request))
I found a stack trace that was generated by the AppArmor kernel module in my dmesg/syslog.
Looking at the debug info and cross referencing master, it appears to be generated by a check on line 138 in security/apparmor/file.c
I'll investigate if this is reproducible and add additional details if it is.
The confined process was Hasicorp Vault
which vault
/usr/local/bin/vault
vault --version
Vault v1.0.2 ('37a1dc9c477c1c68c022d2084550f25bf20cac33')
sudo aa-status
apparmor module is loaded.
16 profiles are loaded.
11 profiles are in enforce mode.
...
5 profiles are in complain mode.
...
/usr/local/bin/vault///bin/uname
4 processes have profiles defined.
2 processes are in enforce mode.
...
/usr/local/bin/vault (9102)
uname -a
Linux hostname 4.4.0-142-generic #168-Ubuntu SMP Wed Jan 16 21:00:45 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
cat /etc/issue
Ubuntu 16.04.5 LTS \n \l
apt-cache policy apparmor
apparmor:
Installed: 2.10.95-0ubuntu2.10
Candidate: 2.10.95-0ubuntu2.10
Version table:
*** 2.10.95-0ubuntu2.10 500
500 http://us.archive.ubuntu.com/ubuntu xenial-updates/main amd64 Packages
500 http://security.ubuntu.com/ubuntu xenial-security/main amd64 Packages
100 /var/lib/dpkg/status
2.10.95-0ubuntu2 500
500 http://us.archive.ubuntu.com/ubuntu xenial/main amd64 Packages
dmesg
[555555.729558] ------------[ cut here ]------------
[555555.729576] WARNING: CPU: 0 PID: 9028 at /build/linux-2I72tK/linux-4.4.0/security/apparmor/file.c:136 aa_audit_file+0x16e/0x180()
[555555.729580] AppArmor WARN aa_audit_file: ((!(&sa)->apparmor_audit_data->request)):
[555555.729582] Modules linked in:
[555555.729585] xt_recent vmw_vsock_vmci_transport vsock joydev input_leds serio_raw coretemp vmw_balloon i2c_piix4 shpchp vmw_vmci mac_hid ip6t_REJECT nf_reject_ipv6 nf_log_ipv6 xt_hl ip6t_rt nf_conntrack_ipv6 nf_defrag_ipv6 ipt_REJECT nf_reject_ipv4 nf_log_ipv4 nf_log_common xt_LOG xt_limit xt_tcpudp xt_addrtype nf_conntrack_ipv4 nf_defrag_ipv4 xt_conntrack ip6table_filter ip6_tables nf_conntrack_netbios_ns nf_conntrack_broadcast nf_nat_ftp nf_nat nf_conntrack_ftp nf_conntrack iptable_filter ip_tables x_tables autofs4 btrfs xor raid6_pq crct10dif_pclmul crc32_pclmul ghash_clmulni_intel aesni_intel aes_x86_64 lrw gf128mul glue_helper ablk_helper cryptd vmwgfx ttm drm_kms_helper psmouse syscopyarea sysfillrect sysimgblt fb_sys_fops drm ahci libahci e1000 mptspi mptscsih mptbase scsi_transport_spi pata_acpi
[555555.729662] fjes
[555555.729668] CPU: 0 PID: 9028 Comm: vault Not tainted 4.4.0-142-generic #168-Ubuntu
[555555.729671] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 04/05/2016
[555555.729675] 0000000000000286 06521264101c938e ffff880014423ae8 ffffffff8140a2e1
[555555.729679] ffff880014423b30 ffffffff81cfd1e8 ffff880014423b20 ffffffff81085372
[555555.729683] ffff880016e5d800 ffff880014423c9c ffff88001f347600 ffff880014423c9c
[555555.729699] Call Trace:
[555555.729712] [<ffffffff8140a2e1>] dump_stack+0x63/0x82
[555555.729721] [<ffffffff81085372>] warn_slowpath_common+0x82/0xc0
[555555.729726] [<ffffffff8108540c>] warn_slowpath_fmt+0x5c/0x80
[555555.729732] [<ffffffff813a580e>] aa_audit_file+0x16e/0x180
[555555.729738] [<ffffffff8139885e>] profile_transition+0x3de/0xc80
[555555.729743] [<ffffffff8139ab23>] apparmor_bprm_set_creds+0x953/0xa60
[555555.729752] [<ffffffff812f761c>] ? ext4_xattr_security_get+0x1c/0x30
[555555.729758] [<ffffffff81241ad1>] ? generic_getxattr+0x51/0x70
[555555.729766] [<ffffffff8135757e>] ? security_capable+0x4e/0x70
[555555.729773] [<ffffffff8108f138>] ? ns_capable_common+0x68/0x80
[555555.729777] [<ffffffff8108f18c>] ? capable+0x1c/0x20
[555555.729782] [<ffffffff8135559b>] ? cap_bprm_set_creds+0x3eb/0x5f0
[555555.729787] [<ffffffff81357819>] security_bprm_set_creds+0x39/0x50
[555555.729795] [<ffffffff81221f65>] prepare_binprm+0x85/0x190
[555555.729800] [<ffffffff81223684>] do_execveat_common.isra.31+0x4b4/0x770
[555555.729806] [<ffffffff81223b9a>] SyS_execve+0x3a/0x50
[555555.729815] [<ffffffff818617d5>] stub_execve+0x5/0x5
[555555.729820] [<ffffffff8186145b>] ? entry_SYSCALL_64_fastpath+0x22/0xcb
[555555.729823] ---[ end trace 3ef751ede96d944f ]---
[555555.730500] ------------[ cut here ]------------
[555555.730510] WARNING: CPU: 0 PID: 9029 at /build/linux-2I72tK/linux-4.4.0/security/apparmor/file.c:136 aa_audit_file+0x16e/0x180()
[555555.730513] AppArmor WARN aa_audit_file: ((!(&sa)->apparmor_audit_data->request)):
[555555.730515] Modules linked in:
[555555.730517] xt_recent vmw_vsock_vmci_transport vsock joydev input_leds serio_raw coretemp vmw_balloon i2c_piix4 shpchp vmw_vmci mac_hid ip6t_REJECT nf_reject_ipv6 nf_log_ipv6 xt_hl ip6t_rt nf_conntrack_ipv6 nf_defrag_ipv6 ipt_REJECT nf_reject_ipv4 nf_log_ipv4 nf_log_common xt_LOG xt_limit xt_tcpudp xt_addrtype nf_conntrack_ipv4 nf_defrag_ipv4 xt_conntrack ip6table_filter ip6_tables nf_conntrack_netbios_ns nf_conntrack_broadcast nf_nat_ftp nf_nat nf_conntrack_ftp nf_conntrack iptable_filter ip_tables x_tables autofs4 btrfs xor raid6_pq crct10dif_pclmul crc32_pclmul ghash_clmulni_intel aesni_intel aes_x86_64 lrw gf128mul glue_helper ablk_helper cryptd vmwgfx ttm drm_kms_helper psmouse syscopyarea sysfillrect sysimgblt fb_sys_fops drm ahci libahci e1000 mptspi mptscsih mptbase scsi_transport_spi pata_acpi
[555555.730570] fjes
[555555.730575] CPU: 0 PID: 9029 Comm: vault Tainted: G W 4.4.0-142-generic #168-Ubuntu
[555555.730577] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 04/05/2016
[555555.730580] 0000000000000286 035d4c7a8328a392 ffff880014417ae8 ffffffff8140a2e1
[555555.730584] ffff880014417b30 ffffffff81cfd1e8 ffff880014417b20 ffffffff81085372
[555555.730588] ffff880016e5d800 ffff880014417c9c ffff88001f345200 ffff880014417c9c
[555555.730592] Call Trace:
[555555.730598] [<ffffffff8140a2e1>] dump_stack+0x63/0x82
[555555.730604] [<ffffffff81085372>] warn_slowpath_common+0x82/0xc0
[555555.730609] [<ffffffff8108540c>] warn_slowpath_fmt+0x5c/0x80
[555555.730615] [<ffffffff813a580e>] aa_audit_file+0x16e/0x180
[555555.730620] [<ffffffff8139885e>] profile_transition+0x3de/0xc80
[555555.730625] [<ffffffff8139ab23>] apparmor_bprm_set_creds+0x953/0xa60
[555555.730631] [<ffffffff812f761c>] ? ext4_xattr_security_get+0x1c/0x30
[555555.730635] [<ffffffff81241ad1>] ? generic_getxattr+0x51/0x70
[555555.730641] [<ffffffff8135757e>] ? security_capable+0x4e/0x70
[555555.730646] [<ffffffff8108f138>] ? ns_capable_common+0x68/0x80
[555555.730650] [<ffffffff8108f18c>] ? capable+0x1c/0x20
[555555.730654] [<ffffffff8135559b>] ? cap_bprm_set_creds+0x3eb/0x5f0
[555555.730659] [<ffffffff81357819>] security_bprm_set_creds+0x39/0x50
[555555.730665] [<ffffffff81221f65>] prepare_binprm+0x85/0x190
[555555.730670] [<ffffffff81223684>] do_execveat_common.isra.31+0x4b4/0x770
[555555.730676] [<ffffffff81223b9a>] SyS_execve+0x3a/0x50
[555555.730681] [<ffffffff818617d5>] stub_execve+0x5/0x5
[555555.730686] [<ffffffff8186145b>] ? entry_SYSCALL_64_fastpath+0x22/0xcb
[555555.730689] ---[ end trace 3ef751ede96d9450 ]---
[555555.730955] ------------[ cut here ]------------
[555555.730964] WARNING: CPU: 0 PID: 9030 at /build/linux-2I72tK/linux-4.4.0/security/apparmor/file.c:136 aa_audit_file+0x16e/0x180()
[555555.730967] AppArmor WARN aa_audit_file: ((!(&sa)->apparmor_audit_data->request)):
[555555.730968] Modules linked in:
[555555.730971] xt_recent vmw_vsock_vmci_transport vsock joydev input_leds serio_raw coretemp vmw_balloon i2c_piix4 shpchp vmw_vmci mac_hid ip6t_REJECT nf_reject_ipv6 nf_log_ipv6 xt_hl ip6t_rt nf_conntrack_ipv6 nf_defrag_ipv6 ipt_REJECT nf_reject_ipv4 nf_log_ipv4 nf_log_common xt_LOG xt_limit xt_tcpudp xt_addrtype nf_conntrack_ipv4 nf_defrag_ipv4 xt_conntrack ip6table_filter ip6_tables nf_conntrack_netbios_ns nf_conntrack_broadcast nf_nat_ftp nf_nat nf_conntrack_ftp nf_conntrack iptable_filter ip_tables x_tables autofs4 btrfs xor raid6_pq crct10dif_pclmul crc32_pclmul ghash_clmulni_intel aesni_intel aes_x86_64 lrw gf128mul glue_helper ablk_helper cryptd vmwgfx ttm drm_kms_helper psmouse syscopyarea sysfillrect sysimgblt fb_sys_fops drm ahci libahci e1000 mptspi mptscsih mptbase scsi_transport_spi pata_acpi
[555555.731022] fjes
[555555.731026] CPU: 0 PID: 9030 Comm: vault Tainted: G W 4.4.0-142-generic #168-Ubuntu
[555555.731029] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 04/05/2016
[555555.731031] 0000000000000286 31cac79825f30458 ffff8800170b3ae8 ffffffff8140a2e1
[555555.731035] ffff8800170b3b30 ffffffff81cfd1e8 ffff8800170b3b20 ffffffff81085372
[555555.731039] ffff880016e5d800 ffff8800170b3c9c ffff88001f360700 ffff8800170b3c9c
[555555.731043] Call Trace:
[555555.731049] [<ffffffff8140a2e1>] dump_stack+0x63/0x82
[555555.731054] [<ffffffff81085372>] warn_slowpath_common+0x82/0xc0
[555555.731059] [<ffffffff8108540c>] warn_slowpath_fmt+0x5c/0x80
[555555.731065] [<ffffffff813a580e>] aa_audit_file+0x16e/0x180
[555555.731070] [<ffffffff8139885e>] profile_transition+0x3de/0xc80
[555555.731075] [<ffffffff8139ab23>] apparmor_bprm_set_creds+0x953/0xa60
[555555.731081] [<ffffffff812f761c>] ? ext4_xattr_security_get+0x1c/0x30
[555555.731085] [<ffffffff81241ad1>] ? generic_getxattr+0x51/0x70
[555555.731090] [<ffffffff8135757e>] ? security_capable+0x4e/0x70
[555555.731095] [<ffffffff8108f138>] ? ns_capable_common+0x68/0x80
[555555.731100] [<ffffffff8108f18c>] ? capable+0x1c/0x20
[555555.731104] [<ffffffff8135559b>] ? cap_bprm_set_creds+0x3eb/0x5f0
[555555.731109] [<ffffffff81357819>] security_bprm_set_creds+0x39/0x50
[555555.731114] [<ffffffff81221f65>] prepare_binprm+0x85/0x190
[555555.731120] [<ffffffff81223684>] do_execveat_common.isra.31+0x4b4/0x770
[555555.731125] [<ffffffff81223b9a>] SyS_execve+0x3a/0x50
[555555.731131] [<ffffffff818617d5>] stub_execve+0x5/0x5
[555555.731135] [<ffffffff8186145b>] ? entry_SYSCALL_64_fastpath+0x22/0xcb
[555555.731138] ---[ end trace 3ef751ede96d9451 ]---
[557304.436776] ------------[ cut here ]------------
[557304.436793] WARNING: CPU: 0 PID: 9109 at /build/linux-2I72tK/linux-4.4.0/security/apparmor/file.c:136 aa_audit_file+0x16e/0x180()
[557304.436797] AppArmor WARN aa_audit_file: ((!(&sa)->apparmor_audit_data->request)):
[557304.436799] Modules linked in:
[557304.436803] xt_recent vmw_vsock_vmci_transport vsock joydev input_leds serio_raw coretemp vmw_balloon i2c_piix4 shpchp vmw_vmci mac_hid ip6t_REJECT nf_reject_ipv6 nf_log_ipv6 xt_hl ip6t_rt nf_conntrack_ipv6 nf_defrag_ipv6 ipt_REJECT nf_reject_ipv4 nf_log_ipv4 nf_log_common xt_LOG xt_limit xt_tcpudp xt_addrtype nf_conntrack_ipv4 nf_defrag_ipv4 xt_conntrack ip6table_filter ip6_tables nf_conntrack_netbios_ns nf_conntrack_broadcast nf_nat_ftp nf_nat nf_conntrack_ftp nf_conntrack iptable_filter ip_tables x_tables autofs4 btrfs xor raid6_pq crct10dif_pclmul crc32_pclmul ghash_clmulni_intel aesni_intel aes_x86_64 lrw gf128mul glue_helper ablk_helper cryptd vmwgfx ttm drm_kms_helper psmouse syscopyarea sysfillrect sysimgblt fb_sys_fops drm ahci libahci e1000 mptspi mptscsih mptbase scsi_transport_spi pata_acpi
[557304.436880] fjes
[557304.436886] CPU: 0 PID: 9109 Comm: vault Tainted: G W 4.4.0-142-generic #168-Ubuntu
[557304.436889] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 04/05/2016
[557304.436893] 0000000000000286 368d9cf0b8dc44c2 ffff880019193ae8 ffffffff8140a2e1
[557304.436897] ffff880019193b30 ffffffff81cfd1e8 ffff880019193b20 ffffffff81085372
[557304.436901] ffff880016e5d800 ffff880019193c9c ffff88001937eb00 ffff880019193c9c
[557304.436905] Call Trace:
[557304.436918] [<ffffffff8140a2e1>] dump_stack+0x63/0x82
[557304.436927] [<ffffffff81085372>] warn_slowpath_common+0x82/0xc0
[557304.436932] [<ffffffff8108540c>] warn_slowpath_fmt+0x5c/0x80
[557304.436938] [<ffffffff813a580e>] aa_audit_file+0x16e/0x180
[557304.436943] [<ffffffff8139885e>] profile_transition+0x3de/0xc80
[557304.436948] [<ffffffff8139ab23>] apparmor_bprm_set_creds+0x953/0xa60
[557304.436957] [<ffffffff812f761c>] ? ext4_xattr_security_get+0x1c/0x30
[557304.436964] [<ffffffff81241ad1>] ? generic_getxattr+0x51/0x70
[557304.436971] [<ffffffff8135757e>] ? security_capable+0x4e/0x70
[557304.436978] [<ffffffff8108f138>] ? ns_capable_common+0x68/0x80
[557304.436983] [<ffffffff8108f18c>] ? capable+0x1c/0x20
[557304.436987] [<ffffffff8135559b>] ? cap_bprm_set_creds+0x3eb/0x5f0
[557304.436992] [<ffffffff81357819>] security_bprm_set_creds+0x39/0x50
[557304.437000] [<ffffffff81221f65>] prepare_binprm+0x85/0x190
[557304.437006] [<ffffffff81223684>] do_execveat_common.isra.31+0x4b4/0x770
[557304.437012] [<ffffffff81223b9a>] SyS_execve+0x3a/0x50
[557304.437020] [<ffffffff818617d5>] stub_execve+0x5/0x5
[557304.437025] [<ffffffff8186145b>] ? entry_SYSCALL_64_fastpath+0x22/0xcb
[557304.437029] ---[ end trace 3ef751ede96d9452 ]---
[557304.437287] ------------[ cut here ]------------
[557304.437296] WARNING: CPU: 0 PID: 9110 at /build/linux-2I72tK/linux-4.4.0/security/apparmor/file.c:136 aa_audit_file+0x16e/0x180()
[557304.437299] AppArmor WARN aa_audit_file: ((!(&sa)->apparmor_audit_data->request)):
[557304.437300] Modules linked in:
[557304.437303] xt_recent vmw_vsock_vmci_transport vsock joydev input_leds serio_raw coretemp vmw_balloon i2c_piix4 shpchp vmw_vmci mac_hid ip6t_REJECT nf_reject_ipv6 nf_log_ipv6 xt_hl ip6t_rt nf_conntrack_ipv6 nf_defrag_ipv6 ipt_REJECT nf_reject_ipv4 nf_log_ipv4 nf_log_common xt_LOG xt_limit xt_tcpudp xt_addrtype nf_conntrack_ipv4 nf_defrag_ipv4 xt_conntrack ip6table_filter ip6_tables nf_conntrack_netbios_ns nf_conntrack_broadcast nf_nat_ftp nf_nat nf_conntrack_ftp nf_conntrack iptable_filter ip_tables x_tables autofs4 btrfs xor raid6_pq crct10dif_pclmul crc32_pclmul ghash_clmulni_intel aesni_intel aes_x86_64 lrw gf128mul glue_helper ablk_helper cryptd vmwgfx ttm drm_kms_helper psmouse syscopyarea sysfillrect sysimgblt fb_sys_fops drm ahci libahci e1000 mptspi mptscsih mptbase scsi_transport_spi pata_acpi
[557304.437354] fjes
[557304.437358] CPU: 0 PID: 9110 Comm: vault Tainted: G W 4.4.0-142-generic #168-Ubuntu
[557304.437361] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 04/05/2016
[557304.437363] 0000000000000286 7e21bd933fcd1136 ffff8800171efae8 ffffffff8140a2e1
[557304.437367] ffff8800171efb30 ffffffff81cfd1e8 ffff8800171efb20 ffffffff81085372
[557304.437371] ffff880016e5d800 ffff8800171efc9c ffff88001937f400 ffff8800171efc9c
[557304.437375] Call Trace:
[557304.437381] [<ffffffff8140a2e1>] dump_stack+0x63/0x82
[557304.437387] [<ffffffff81085372>] warn_slowpath_common+0x82/0xc0
[557304.437391] [<ffffffff8108540c>] warn_slowpath_fmt+0x5c/0x80
[557304.437397] [<ffffffff813a580e>] aa_audit_file+0x16e/0x180
[557304.437402] [<ffffffff8139885e>] profile_transition+0x3de/0xc80
[557304.437407] [<ffffffff8139ab23>] apparmor_bprm_set_creds+0x953/0xa60
[557304.437413] [<ffffffff812f761c>] ? ext4_xattr_security_get+0x1c/0x30
[557304.437417] [<ffffffff81241ad1>] ? generic_getxattr+0x51/0x70
[557304.437422] [<ffffffff8135757e>] ? security_capable+0x4e/0x70
[557304.437427] [<ffffffff8108f138>] ? ns_capable_common+0x68/0x80
[557304.437431] [<ffffffff8108f18c>] ? capable+0x1c/0x20
[557304.437436] [<ffffffff8135559b>] ? cap_bprm_set_creds+0x3eb/0x5f0
[557304.437440] [<ffffffff81357819>] security_bprm_set_creds+0x39/0x50
[557304.437446] [<ffffffff81221f65>] prepare_binprm+0x85/0x190
[557304.437451] [<ffffffff81223684>] do_execveat_common.isra.31+0x4b4/0x770
[557304.437457] [<ffffffff81223b9a>] SyS_execve+0x3a/0x50
[557304.437462] [<ffffffff818617d5>] stub_execve+0x5/0x5
[557304.437467] [<ffffffff8186145b>] ? entry_SYSCALL_64_fastpath+0x22/0xcb
[557304.437470] ---[ end trace 3ef751ede96d9453 ]---
[557304.437722] ------------[ cut here ]------------
[557304.437731] WARNING: CPU: 0 PID: 9111 at /build/linux-2I72tK/linux-4.4.0/security/apparmor/file.c:136 aa_audit_file+0x16e/0x180()
[557304.437733] AppArmor WARN aa_audit_file: ((!(&sa)->apparmor_audit_data->request)):
[557304.437735] Modules linked in:
[557304.437737] xt_recent vmw_vsock_vmci_transport vsock joydev input_leds serio_raw coretemp vmw_balloon i2c_piix4 shpchp vmw_vmci mac_hid ip6t_REJECT nf_reject_ipv6 nf_log_ipv6 xt_hl ip6t_rt nf_conntrack_ipv6 nf_defrag_ipv6 ipt_REJECT nf_reject_ipv4 nf_log_ipv4 nf_log_common xt_LOG xt_limit xt_tcpudp xt_addrtype nf_conntrack_ipv4 nf_defrag_ipv4 xt_conntrack ip6table_filter ip6_tables nf_conntrack_netbios_ns nf_conntrack_broadcast nf_nat_ftp nf_nat nf_conntrack_ftp nf_conntrack iptable_filter ip_tables x_tables autofs4 btrfs xor raid6_pq crct10dif_pclmul crc32_pclmul ghash_clmulni_intel aesni_intel aes_x86_64 lrw gf128mul glue_helper ablk_helper cryptd vmwgfx ttm drm_kms_helper psmouse syscopyarea sysfillrect sysimgblt fb_sys_fops drm ahci libahci e1000 mptspi mptscsih mptbase scsi_transport_spi pata_acpi
[557304.437786] fjes
[557304.437790] CPU: 0 PID: 9111 Comm: vault Tainted: G W 4.4.0-142-generic #168-Ubuntu
[557304.437793] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 04/05/2016
[557304.437795] 0000000000000286 721a770cdeca8f15 ffff880014513ae8 ffffffff8140a2e1
[557304.437799] ffff880014513b30 ffffffff81cfd1e8 ffff880014513b20 ffffffff81085372
[557304.437803] ffff880016e5d800 ffff880014513c9c ffff88001937ee00 ffff880014513c9c
[557304.437807] Call Trace:
[557304.437812] [<ffffffff8140a2e1>] dump_stack+0x63/0x82
[557304.437818] [<ffffffff81085372>] warn_slowpath_common+0x82/0xc0
[557304.437823] [<ffffffff8108540c>] warn_slowpath_fmt+0x5c/0x80
[557304.437828] [<ffffffff813a580e>] aa_audit_file+0x16e/0x180
[557304.437833] [<ffffffff8139885e>] profile_transition+0x3de/0xc80
[557304.437838] [<ffffffff8139ab23>] apparmor_bprm_set_creds+0x953/0xa60
[557304.437844] [<ffffffff812f761c>] ? ext4_xattr_security_get+0x1c/0x30
[557304.437848] [<ffffffff81241ad1>] ? generic_getxattr+0x51/0x70
[557304.437853] [<ffffffff8135757e>] ? security_capable+0x4e/0x70
[557304.437858] [<ffffffff8108f138>] ? ns_capable_common+0x68/0x80
[557304.437863] [<ffffffff8108f18c>] ? capable+0x1c/0x20
[557304.437867] [<ffffffff8135559b>] ? cap_bprm_set_creds+0x3eb/0x5f0
[557304.437872] [<ffffffff81357819>] security_bprm_set_creds+0x39/0x50
[557304.437877] [<ffffffff81221f65>] prepare_binprm+0x85/0x190
[557304.437883] [<ffffffff81223684>] do_execveat_common.isra.31+0x4b4/0x770
[557304.437888] [<ffffffff81223b9a>] SyS_execve+0x3a/0x50
[557304.437894] [<ffffffff818617d5>] stub_execve+0x5/0x5
[557304.437898] [<ffffffff8186145b>] ? entry_SYSCALL_64_fastpath+0x22/0xcb
[557304.437901] ---[ end trace 3ef751ede96d9454 ]---
[557229.711189] audit: type=1400 audit(1549403644.331:1202): apparmor="DENIED" operation="open" profile="/usr/local/bin/vault" name="/var/lib/vault/gpg.asc" pid=9138 comm="vault" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0