You are not logged in.

#1 2020-09-13 08:32:51

3yan
Member
Registered: 2016-10-06
Posts: 8

AppArmor aa-complain startx blocks input devices

I created a blank AppArmor profile for startx. When I set it to aa-complain mode I was not able to type or move/click mouse in the GUI.

no-apparmor: $ startx => works

aa-complain: $ startx => the GUI appears, but the keyboard and mouse does not work. (From logs it is apparent that the appropriate modules fail to load - "Failed to create a device for ..")

expected behavior: as I have nothing in enforce mode and everything is in complain mode it should not mess-up with the X startup. I have no 'deny' rules in my settings.

apparmor off:

[   549.808] (WW) Failed to open protocol names file lib/xorg/protocol.txt
[   549.810] 
X.Org X Server 1.20.9
X Protocol Version 11, Revision 0
[   549.817] Build Operating System: Linux Arch Linux
[   549.819] Current Operating System: Linux PC 5.8.7.a-1-hardened #1 SMP PREEMPT Sat, 05 Sep 2020 18:03:55 +0000 x86_64
[   549.819] Kernel command line: pti=on page_alloc.shuffle=1 BOOT_IMAGE=/vmlinuz-linux-hardened root=/dev/mapper/vroot rw loglevel=3 quiet apparmor=1 audit=1 lsm=lockdown,yama,apparmor
[   549.822] Build Date: 02 September 2020  06:17:44AM
[   549.824]  
[   549.825] Current version of pixman: 0.40.0
[   549.829] 	Before reporting problems, check http://wiki.x.org
	to make sure that you have the latest version.
[   549.829] Markers: (--) probed, (**) from config file, (==) default setting,
	(++) from command line, (!!) notice, (II) informational,
	(WW) warning, (EE) error, (NI) not implemented, (??) unknown.
[   549.837] (==) Log file: "/home/user/.local/share/xorg/Xorg.0.log", Time: Sun Sep 13 09:34:33 2020
[   549.839] (==) Using system config directory "/usr/share/X11/xorg.conf.d"
[   549.839] (==) No Layout section.  Using the first Screen section.
[   549.839] (==) No screen section available. Using defaults.
[   549.839] (**) |-->Screen "Default Screen Section" (0)
[   549.839] (**) |   |-->Monitor "<default monitor>"
[   549.839] (==) No monitor specified for screen "Default Screen Section".
	Using a default monitor configuration.
[   549.839] (==) Automatically adding devices
[   549.839] (==) Automatically enabling devices
[   549.839] (==) Automatically adding GPU devices
[   549.839] (==) Automatically binding GPU devices
[   549.839] (==) Max clients allowed: 256, resource mask: 0x1fffff
[   549.839] (WW) The directory "/usr/share/fonts/misc" does not exist.
[   549.839] 	Entry deleted from font path.
[   549.839] (WW) The directory "/usr/share/fonts/TTF" does not exist.
[   549.839] 	Entry deleted from font path.
[   549.839] (WW) The directory "/usr/share/fonts/OTF" does not exist.
[   549.839] 	Entry deleted from font path.
[   549.839] (WW) The directory "/usr/share/fonts/Type1" does not exist.
[   549.839] 	Entry deleted from font path.
[   549.839] (==) FontPath set to:
	/usr/share/fonts/100dpi,
	/usr/share/fonts/75dpi
[   549.839] (==) ModulePath set to "/usr/lib/xorg/modules"
[   549.839] (II) The server relies on udev to provide the list of input devices.
	If no devices become available, reconfigure udev or disable AutoAddDevices.
[   549.839] (II) Module ABI versions:
[   549.839] 	X.Org ANSI C Emulation: 0.4
[   549.839] 	X.Org Video Driver: 24.1
[   549.839] 	X.Org XInput driver : 24.1
[   549.840] 	X.Org Server Extension : 10.0
[   549.841] (++) using VT number 1

[   549.845] (II) systemd-logind: took control of session /org/freedesktop/login1/session/_31
[   549.847] (II) xfree86: Adding drm device (/dev/dri/card0)
[   549.847] (II) Platform probe for /sys/devices/pci0000:00/0000:00:02.0/drm/card0
[   549.848] (II) systemd-logind: got fd for /dev/dri/card0 226:0 fd 10 paused 0
[   549.853] (--) PCI:*(0@0:2:0) 8086:0046:17aa:215a rev 2, Mem @ 0xf2000000/4194304, 0xd0000000/268435456, I/O @ 0x00001800/8, BIOS @ 0x????????/131072
[   549.853] (WW) Open ACPI failed (/var/run/acpid.socket) (No such file or directory)
[   549.853] (II) LoadModule: "glx"
[   549.853] (II) Loading /usr/lib/xorg/modules/extensions/libglx.so
[   549.855] (II) Module glx: vendor="X.Org Foundation"
[   549.855] 	compiled for 1.20.9, module version = 1.0.0
[   549.855] 	ABI class: X.Org Server Extension, version 10.0
[   549.855] (==) Matched intel as autoconfigured driver 0
[   549.855] (==) Matched modesetting as autoconfigured driver 1
[   549.855] (==) Matched fbdev as autoconfigured driver 2
[   549.855] (==) Matched vesa as autoconfigured driver 3
[   549.855] (==) Assigned the driver to the xf86ConfigLayout
[   549.855] (II) LoadModule: "intel"
[   549.855] (II) Loading /usr/lib/xorg/modules/drivers/intel_drv.so
[   549.855] (II) Module intel: vendor="X.Org Foundation"
[   549.855] 	compiled for 1.20.8, module version = 2.99.917
[   549.855] 	Module class: X.Org Video Driver
[   549.855] 	ABI class: X.Org Video Driver, version 24.1
[   549.855] (II) LoadModule: "modesetting"
[   549.855] (II) Loading /usr/lib/xorg/modules/drivers/modesetting_drv.so
[   549.856] (II) Module modesetting: vendor="X.Org Foundation"
[   549.856] 	compiled for 1.20.9, module version = 1.20.9
[   549.856] 	Module class: X.Org Video Driver
[   549.856] 	ABI class: X.Org Video Driver, version 24.1
[   549.856] (II) LoadModule: "fbdev"
[   549.856] (WW) Warning, couldn't open module fbdev
[   549.856] (EE) Failed to load module "fbdev" (module does not exist, 0)
[   549.856] (II) LoadModule: "vesa"
[   549.856] (II) Loading /usr/lib/xorg/modules/drivers/vesa_drv.so
[   549.856] (II) Module vesa: vendor="X.Org Foundation"
[   549.857] 	compiled for 1.20.8, module version = 2.4.0
[   549.857] 	Module class: X.Org Video Driver
[   549.857] 	ABI class: X.Org Video Driver, version 24.1
[   549.857] (II) intel: Driver for Intel(R) Integrated Graphics Chipsets:
	i810, i810-dc100, i810e, i815, i830M, 845G, 854, 852GM/855GM, 865G,
	915G, E7221 (i915), 915GM, 945G, 945GM, 945GME, Pineview GM,
	Pineview G, 965G, G35, 965Q, 946GZ, 965GM, 965GME/GLE, G33, Q35, Q33,
	GM45, 4 Series, G45/G43, Q45/Q43, G41, B43
[   549.857] (II) intel: Driver for Intel(R) HD Graphics
[   549.857] (II) intel: Driver for Intel(R) Iris(TM) Graphics
[   549.857] (II) intel: Driver for Intel(R) Iris(TM) Pro Graphics
[   549.857] (II) modesetting: Driver for Modesetting Kernel Drivers: kms
[   549.857] (II) VESA: driver for VESA chipsets: vesa
[   549.857] xf86EnableIOPorts: failed to set IOPL for I/O (Operation not permitted)
[   549.857] (II) intel(0): Using Kernel Mode Setting driver: i915, version 1.6.0 20200515
[   549.857] (II) intel(0): SNA compiled from 2.99.917-908-g7181c5a4
[   549.872] (WW) Falling back to old probe method for modesetting
[   549.872] (WW) VGA arbiter: cannot open kernel arbiter, no multi-card support
[   549.872] (--) intel(0): Integrated Graphics Chipset: Intel(R) HD Graphics
[   549.873] (--) intel(0): CPU: x86-64, sse2, sse3, ssse3, sse4.1, sse4.2; using a maximum of 2 threads
[   549.873] (II) intel(0): Creating default Display subsection in Screen section
	"Default Screen Section" for depth/fbbpp 24/32
[   549.873] (==) intel(0): Depth 24, (--) framebuffer bpp 32
[   549.873] (==) intel(0): RGB weight 888
[   549.873] (==) intel(0): Default visual is TrueColor
[   549.873] (II) intel(0): Output LVDS1 has no monitor section
[   549.874] (**) intel(0): Found backlight control interface intel_backlight (type 'raw') for output LVDS1
[   549.874] (II) intel(0): Enabled output LVDS1
[   549.874] (II) intel(0): Output VGA1 has no monitor section
[   549.874] (II) intel(0): Enabled output VGA1
[   549.874] (II) intel(0): Output HDMI1 has no monitor section
[   549.875] (II) intel(0): Enabled output HDMI1
[   549.875] (II) intel(0): Output DP1 has no monitor section
[   549.875] (II) intel(0): Enabled output DP1
[   549.875] (II) intel(0): Output HDMI2 has no monitor section
[   549.875] (II) intel(0): Enabled output HDMI2
[   549.875] (II) intel(0): Output HDMI3 has no monitor section
[   549.876] (II) intel(0): Enabled output HDMI3
[   549.876] (II) intel(0): Output DP2 has no monitor section
[   549.876] (II) intel(0): Enabled output DP2
[   549.876] (II) intel(0): Output DP3 has no monitor section
[   549.876] (II) intel(0): Enabled output DP3
[   549.876] (--) intel(0): Using a maximum size of 256x256 for hardware cursors
[   549.876] (II) intel(0): Output VIRTUAL1 has no monitor section
[   549.876] (II) intel(0): Enabled output VIRTUAL1
[   549.876] (--) intel(0): Output LVDS1 using initial mode 1440x900 on pipe 0
[   549.877] (==) intel(0): TearFree disabled
[   549.877] (==) intel(0): Using gamma correction (1.0, 1.0, 1.0)
[   549.877] (==) intel(0): DPI set to (96, 96)
[   549.877] (II) Loading sub module "dri3"
[   549.877] (II) LoadModule: "dri3"
[   549.877] (II) Module "dri3" already built-in
[   549.877] (II) Loading sub module "dri2"
[   549.877] (II) LoadModule: "dri2"
[   549.877] (II) Module "dri2" already built-in
[   549.877] (II) Loading sub module "present"
[   549.877] (II) LoadModule: "present"
[   549.877] (II) Module "present" already built-in
[   549.877] (II) UnloadModule: "modesetting"
[   549.877] (II) Unloading modesetting
[   549.877] (II) UnloadModule: "vesa"
[   549.877] (II) Unloading vesa
[   549.878] (II) intel(0): SNA initialized with Ironlake (gen5) backend
[   549.878] (==) intel(0): Backing store enabled
[   549.878] (==) intel(0): Silken mouse disabled
[   549.878] (II) intel(0): HW Cursor enabled
[   549.879] (==) intel(0): DPMS enabled
[   549.879] (==) intel(0): Display hotplug detection enabled
[   549.879] (II) intel(0): [XvMC] xvmc_vld driver initialized.
[   549.879] (II) intel(0): [DRI2] Setup complete
[   549.879] (II) intel(0): [DRI2]   DRI driver: i965
[   549.879] (II) intel(0): [DRI2]   VDPAU driver: va_gl
[   549.879] (II) intel(0): direct rendering: DRI2 DRI3 enabled
[   549.879] (II) intel(0): hardware support for Present enabled
[   549.879] (II) Initializing extension Generic Event Extension
[   549.879] (II) Initializing extension SHAPE
[   549.879] (II) Initializing extension MIT-SHM
[   549.879] (II) Initializing extension XInputExtension
[   549.879] (II) Initializing extension XTEST
[   549.879] (II) Initializing extension BIG-REQUESTS
[   549.879] (II) Initializing extension SYNC
[   549.879] (II) Initializing extension XKEYBOARD
[   549.879] (II) Initializing extension XC-MISC
[   549.879] (II) Initializing extension SECURITY
[   549.879] (II) Initializing extension XFIXES
[   549.879] (II) Initializing extension RENDER
[   549.879] (II) Initializing extension RANDR
[   549.879] (II) Initializing extension COMPOSITE
[   549.879] (II) Initializing extension DAMAGE
[   549.879] (II) Initializing extension MIT-SCREEN-SAVER
[   549.879] (II) Initializing extension DOUBLE-BUFFER
[   549.879] (II) Initializing extension RECORD
[   549.879] (II) Initializing extension DPMS
[   549.879] (II) Initializing extension Present
[   549.879] (II) Initializing extension DRI3
[   549.879] (II) Initializing extension X-Resource
[   549.879] (II) Initializing extension XVideo
[   549.879] (II) Initializing extension XVideo-MotionCompensation
[   549.879] (II) Initializing extension GLX
[   549.899] (II) AIGLX: Loaded and initialized i965
[   549.899] (II) GLX: Initialized DRI2 GL provider for screen 0
[   549.899] (II) Initializing extension XFree86-VidModeExtension
[   549.899] (II) Initializing extension XFree86-DGA
[   549.899] (II) Initializing extension XFree86-DRI
[   549.899] (II) Initializing extension DRI2
[   549.910] (II) intel(0): switch to mode 1440x900@60.0 on LVDS1 using pipe 0, position (0, 0), rotation normal, reflection none
[   549.917] (II) intel(0): Setting screen physical size to 381 x 238
[   550.029] (II) config/udev: Adding input device Power Button (/dev/input/event2)
[   550.029] (**) Power Button: Applying InputClass "libinput keyboard catchall"
[   550.029] (II) LoadModule: "libinput"
[   550.029] (II) Loading /usr/lib/xorg/modules/input/libinput_drv.so
[   550.031] (II) Module libinput: vendor="X.Org Foundation"
[   550.031] 	compiled for 1.20.8, module version = 0.30.0
[   550.031] 	Module class: X.Org XInput Driver
[   550.031] 	ABI class: X.Org XInput driver, version 24.1
[   550.031] (II) Using input driver 'libinput' for 'Power Button'
[   550.033] (II) systemd-logind: got fd for /dev/input/event2 13:66 fd 16 paused 0
[   550.033] (**) Power Button: always reports core events
[   550.033] (**) Option "Device" "/dev/input/event2"
[   550.033] (**) Option "_source" "server/udev"
[   550.035] (II) event2  - Power Button: is tagged by udev as: Keyboard
[   550.035] (II) event2  - Power Button: device is a keyboard
[   550.036] (II) event2  - Power Button: device removed
[   550.036] (**) Option "config_info" "udev:/sys/devices/LNXSYSTM:00/LNXPWRBN:00/input/input2/event2"
[   550.036] (II) XINPUT: Adding extended input device "Power Button" (type: KEYBOARD, id 6)
[   550.037] (II) event2  - Power Button: is tagged by udev as: Keyboard
[   550.037] (II) event2  - Power Button: device is a keyboard
[   550.038] (II) config/udev: Adding input device Video Bus (/dev/input/event6)
[   550.038] (**) Video Bus: Applying InputClass "libinput keyboard catchall"
[   550.038] (II) Using input driver 'libinput' for 'Video Bus'
[   550.039] (II) systemd-logind: got fd for /dev/input/event6 13:70 fd 19 paused 0
[   550.040] (**) Video Bus: always reports core events
[   550.040] (**) Option "Device" "/dev/input/event6"
[   550.040] (**) Option "_source" "server/udev"
[   550.041] (II) event6  - Video Bus: is tagged by udev as: Keyboard
[   550.041] (II) event6  - Video Bus: device is a keyboard
[   550.041] (II) event6  - Video Bus: device removed
[   550.041] (**) Option "config_info" "udev:/sys/devices/LNXSYSTM:00/LNXSYBUS:00/PNP0A08:00/LNXVIDEO:00/input/input8/event6"
[   550.041] (II) XINPUT: Adding extended input device "Video Bus" (type: KEYBOARD, id 7)
[   550.043] (II) event6  - Video Bus: is tagged by udev as: Keyboard
[   550.043] (II) event6  - Video Bus: device is a keyboard
[   550.044] (II) config/udev: Adding input device Lid Switch (/dev/input/event0)
[   550.044] (II) No input driver specified, ignoring this device.
[   550.044] (II) This device may have been added with another device file.
[   550.044] (II) config/udev: Adding input device Sleep Button (/dev/input/event1)
[   550.044] (**) Sleep Button: Applying InputClass "libinput keyboard catchall"
[   550.044] (II) Using input driver 'libinput' for 'Sleep Button'
[   550.046] (II) systemd-logind: got fd for /dev/input/event1 13:65 fd 20 paused 0
[   550.046] (**) Sleep Button: always reports core events
[   550.046] (**) Option "Device" "/dev/input/event1"
[   550.046] (**) Option "_source" "server/udev"
[   550.048] (II) event1  - Sleep Button: is tagged by udev as: Keyboard
[   550.048] (II) event1  - Sleep Button: device is a keyboard
[   550.048] (II) event1  - Sleep Button: device removed
[   550.048] (**) Option "config_info" "udev:/sys/devices/LNXSYSTM:00/LNXSYBUS:00/PNP0C0E:00/input/input1/event1"
[   550.048] (II) XINPUT: Adding extended input device "Sleep Button" (type: KEYBOARD, id 8)
[   550.050] (II) event1  - Sleep Button: is tagged by udev as: Keyboard
[   550.050] (II) event1  - Sleep Button: device is a keyboard
[   550.052] (II) config/udev: Adding input device HDA Intel MID Dock Mic (/dev/input/event8)
[   550.053] (II) No input driver specified, ignoring this device.
[   550.053] (II) This device may have been added with another device file.
[   550.053] (II) config/udev: Adding input device HDA Intel MID Dock Headphone (/dev/input/event9)
[   550.053] (II) No input driver specified, ignoring this device.
[   550.053] (II) This device may have been added with another device file.
[   550.054] (II) config/udev: Adding input device HDA Intel MID Headphone (/dev/input/event10)
[   550.054] (II) No input driver specified, ignoring this device.
[   550.054] (II) This device may have been added with another device file.
[   550.055] (II) config/udev: Adding input device HDA Intel MID HDMI/DP,pcm=3 (/dev/input/event11)
[   550.055] (II) No input driver specified, ignoring this device.
[   550.055] (II) This device may have been added with another device file.
[   550.056] (II) config/udev: Adding input device HDA Intel MID HDMI/DP,pcm=7 (/dev/input/event12)
[   550.056] (II) No input driver specified, ignoring this device.
[   550.056] (II) This device may have been added with another device file.
[   550.056] (II) config/udev: Adding input device HDA Intel MID HDMI/DP,pcm=8 (/dev/input/event13)
[   550.056] (II) No input driver specified, ignoring this device.
[   550.056] (II) This device may have been added with another device file.
[   550.057] (II) config/udev: Adding input device HDA Intel MID Mic (/dev/input/event7)
[   550.057] (II) No input driver specified, ignoring this device.
[   550.057] (II) This device may have been added with another device file.
[   550.058] (II) config/udev: Adding input device AT Translated Set 2 keyboard (/dev/input/event3)
[   550.058] (**) AT Translated Set 2 keyboard: Applying InputClass "libinput keyboard catchall"
[   550.058] (II) Using input driver 'libinput' for 'AT Translated Set 2 keyboard'
[   550.060] (II) systemd-logind: got fd for /dev/input/event3 13:67 fd 21 paused 0
[   550.060] (**) AT Translated Set 2 keyboard: always reports core events
[   550.060] (**) Option "Device" "/dev/input/event3"
[   550.060] (**) Option "_source" "server/udev"
[   550.062] (II) event3  - AT Translated Set 2 keyboard: is tagged by udev as: Keyboard
[   550.062] (II) event3  - AT Translated Set 2 keyboard: device is a keyboard
[   550.063] (II) event3  - AT Translated Set 2 keyboard: device removed
[   550.063] (**) Option "config_info" "udev:/sys/devices/platform/i8042/serio0/input/input3/event3"
[   550.063] (II) XINPUT: Adding extended input device "AT Translated Set 2 keyboard" (type: KEYBOARD, id 9)
[   550.065] (II) event3  - AT Translated Set 2 keyboard: is tagged by udev as: Keyboard
[   550.065] (II) event3  - AT Translated Set 2 keyboard: device is a keyboard
[   550.066] (II) config/udev: Adding input device SynPS/2 Synaptics TouchPad (/dev/input/event14)
[   550.066] (**) SynPS/2 Synaptics TouchPad: Applying InputClass "libinput touchpad catchall"
[   550.066] (II) Using input driver 'libinput' for 'SynPS/2 Synaptics TouchPad'
[   550.068] (II) systemd-logind: got fd for /dev/input/event14 13:78 fd 22 paused 0
[   550.068] (**) SynPS/2 Synaptics TouchPad: always reports core events
[   550.068] (**) Option "Device" "/dev/input/event14"
[   550.068] (**) Option "_source" "server/udev"
[   550.070] (II) event14 - SynPS/2 Synaptics TouchPad: is tagged by udev as: Touchpad
[   550.071] (II) event14 - SynPS/2 Synaptics TouchPad: device is a touchpad
[   550.072] (II) event14 - SynPS/2 Synaptics TouchPad: device removed
[   550.072] (**) Option "config_info" "udev:/sys/devices/platform/i8042/serio1/input/input6/event14"
[   550.072] (II) XINPUT: Adding extended input device "SynPS/2 Synaptics TouchPad" (type: TOUCHPAD, id 10)
[   550.073] (**) Option "AccelerationScheme" "none"
[   550.073] (**) SynPS/2 Synaptics TouchPad: (accel) selected scheme none/0
[   550.073] (**) SynPS/2 Synaptics TouchPad: (accel) acceleration factor: 2.000
[   550.073] (**) SynPS/2 Synaptics TouchPad: (accel) acceleration threshold: 4
[   550.075] (II) event14 - SynPS/2 Synaptics TouchPad: is tagged by udev as: Touchpad
[   550.077] (II) event14 - SynPS/2 Synaptics TouchPad: device is a touchpad
[   550.078] (II) config/udev: Adding input device SynPS/2 Synaptics TouchPad (/dev/input/mouse0)
[   550.078] (II) No input driver specified, ignoring this device.
[   550.078] (II) This device may have been added with another device file.
[   550.079] (II) config/udev: Adding input device TPPS/2 IBM TrackPoint (/dev/input/event15)
[   550.079] (**) TPPS/2 IBM TrackPoint: Applying InputClass "libinput pointer catchall"
[   550.079] (II) Using input driver 'libinput' for 'TPPS/2 IBM TrackPoint'
[   550.080] (II) systemd-logind: got fd for /dev/input/event15 13:79 fd 23 paused 0
[   550.080] (**) TPPS/2 IBM TrackPoint: always reports core events
[   550.080] (**) Option "Device" "/dev/input/event15"
[   550.080] (**) Option "_source" "server/udev"
[   550.082] (II) event15 - TPPS/2 IBM TrackPoint: is tagged by udev as: Mouse Pointingstick
[   550.083] (II) event15 - TPPS/2 IBM TrackPoint: device is a pointer
[   550.084] (II) event15 - TPPS/2 IBM TrackPoint: device removed
[   550.084] (**) Option "config_info" "udev:/sys/devices/platform/i8042/serio1/serio2/input/input16/event15"
[   550.084] (II) XINPUT: Adding extended input device "TPPS/2 IBM TrackPoint" (type: MOUSE, id 11)
[   550.084] (**) Option "AccelerationScheme" "none"
[   550.084] (**) TPPS/2 IBM TrackPoint: (accel) selected scheme none/0
[   550.084] (**) TPPS/2 IBM TrackPoint: (accel) acceleration factor: 2.000
[   550.085] (**) TPPS/2 IBM TrackPoint: (accel) acceleration threshold: 4
[   550.087] (II) event15 - TPPS/2 IBM TrackPoint: is tagged by udev as: Mouse Pointingstick
[   550.087] (II) event15 - TPPS/2 IBM TrackPoint: device is a pointer
[   550.089] (II) config/udev: Adding input device TPPS/2 IBM TrackPoint (/dev/input/mouse1)
[   550.089] (II) No input driver specified, ignoring this device.
[   550.089] (II) This device may have been added with another device file.
[   550.090] (II) config/udev: Adding input device PC Speaker (/dev/input/event4)
[   550.090] (II) No input driver specified, ignoring this device.
[   550.090] (II) This device may have been added with another device file.
[   550.091] (II) config/udev: Adding input device ThinkPad Extra Buttons (/dev/input/event5)
[   550.091] (**) ThinkPad Extra Buttons: Applying InputClass "libinput keyboard catchall"
[   550.091] (II) Using input driver 'libinput' for 'ThinkPad Extra Buttons'
[   550.093] (II) systemd-logind: got fd for /dev/input/event5 13:69 fd 24 paused 0
[   550.093] (**) ThinkPad Extra Buttons: always reports core events
[   550.093] (**) Option "Device" "/dev/input/event5"
[   550.093] (**) Option "_source" "server/udev"
[   550.094] (II) event5  - ThinkPad Extra Buttons: is tagged by udev as: Keyboard Switch
[   550.094] (II) event5  - ThinkPad Extra Buttons: device is a keyboard
[   550.095] (II) event5  - ThinkPad Extra Buttons: device removed
[   550.095] (**) Option "config_info" "udev:/sys/devices/platform/thinkpad_acpi/input/input7/event5"
[   550.095] (II) XINPUT: Adding extended input device "ThinkPad Extra Buttons" (type: KEYBOARD, id 12)
[   550.096] (II) event5  - ThinkPad Extra Buttons: is tagged by udev as: Keyboard Switch
[   550.096] (II) event5  - ThinkPad Extra Buttons: device is a keyboard
[   550.606] (II) intel(0): EDID vendor "LEN", prod id 16438
[   550.606] (II) intel(0): Printing DDC gathered Modelines:
[   550.606] (II) intel(0): Modeline "1440x900"x0.0   96.10  1440 1488 1552 1728  900 903 909 926 -hsync -vsync (55.6 kHz eP)
[   550.606] (II) intel(0): Modeline "1440x900"x0.0   80.30  1440 1488 1552 1728  900 903 909 926 -hsync -vsync (46.5 kHz e)
[   559.785] (**) Option "fd" "16"
[   559.785] (II) event2  - Power Button: device removed
[   559.785] (**) Option "fd" "19"
[   559.785] (II) event6  - Video Bus: device removed
[   559.785] (**) Option "fd" "20"
[   559.785] (II) event1  - Sleep Button: device removed
[   559.785] (**) Option "fd" "21"
[   559.785] (II) event3  - AT Translated Set 2 keyboard: device removed
[   559.785] (**) Option "fd" "22"
[   559.785] (II) event14 - SynPS/2 Synaptics TouchPad: device removed
[   559.785] (**) Option "fd" "23"
[   559.785] (II) event15 - TPPS/2 IBM TrackPoint: device removed
[   559.786] (**) Option "fd" "24"
[   559.786] (II) event5  - ThinkPad Extra Buttons: device removed
[   559.786] (II) UnloadModule: "libinput"
[   559.786] (II) systemd-logind: releasing fd for 13:69
[   559.793] (II) UnloadModule: "libinput"
[   559.793] (II) systemd-logind: releasing fd for 13:79
[   559.842] (II) UnloadModule: "libinput"
[   559.842] (II) systemd-logind: releasing fd for 13:78
[   559.885] (II) UnloadModule: "libinput"
[   559.885] (II) systemd-logind: releasing fd for 13:67
[   559.925] (II) UnloadModule: "libinput"
[   559.925] (II) systemd-logind: releasing fd for 13:65
[   559.952] (II) UnloadModule: "libinput"
[   559.952] (II) systemd-logind: releasing fd for 13:70
[   560.019] (II) UnloadModule: "libinput"
[   560.019] (II) systemd-logind: releasing fd for 13:66
[   560.126] (II) Server terminated successfully (0). Closing log file.

apparmor on:

[   414.534] (WW) Failed to open protocol names file lib/xorg/protocol.txt
[   414.535] 
X.Org X Server 1.20.9
X Protocol Version 11, Revision 0
[   414.539] Build Operating System: Linux Arch Linux
[   414.541] Current Operating System: Linux PC 5.8.7.a-1-hardened #1 SMP PREEMPT Sat, 05 Sep 2020 18:03:55 +0000 x86_64
[   414.541] Kernel command line: pti=on page_alloc.shuffle=1 BOOT_IMAGE=/vmlinuz-linux-hardened root=/dev/mapper/vroot rw loglevel=3 quiet apparmor=1 audit=1 lsm=lockdown,yama,apparmor
[   414.544] Build Date: 02 September 2020  06:17:44AM
[   414.546]  
[   414.547] Current version of pixman: 0.40.0
[   414.550] 	Before reporting problems, check http://wiki.x.org
	to make sure that you have the latest version.
[   414.550] Markers: (--) probed, (**) from config file, (==) default setting,
	(++) from command line, (!!) notice, (II) informational,
	(WW) warning, (EE) error, (NI) not implemented, (??) unknown.
[   414.557] (==) Log file: "/home/user/.local/share/xorg/Xorg.0.log", Time: Sun Sep 13 09:32:18 2020
[   414.559] (==) Using system config directory "/usr/share/X11/xorg.conf.d"
[   414.559] (==) No Layout section.  Using the first Screen section.
[   414.559] (==) No screen section available. Using defaults.
[   414.559] (**) |-->Screen "Default Screen Section" (0)
[   414.559] (**) |   |-->Monitor "<default monitor>"
[   414.559] (==) No monitor specified for screen "Default Screen Section".
	Using a default monitor configuration.
[   414.559] (==) Automatically adding devices
[   414.559] (==) Automatically enabling devices
[   414.559] (==) Automatically adding GPU devices
[   414.559] (==) Automatically binding GPU devices
[   414.559] (==) Max clients allowed: 256, resource mask: 0x1fffff
[   414.559] (WW) The directory "/usr/share/fonts/misc" does not exist.
[   414.559] 	Entry deleted from font path.
[   414.559] (WW) The directory "/usr/share/fonts/TTF" does not exist.
[   414.559] 	Entry deleted from font path.
[   414.559] (WW) The directory "/usr/share/fonts/OTF" does not exist.
[   414.559] 	Entry deleted from font path.
[   414.559] (WW) The directory "/usr/share/fonts/Type1" does not exist.
[   414.559] 	Entry deleted from font path.
[   414.559] (==) FontPath set to:
	/usr/share/fonts/100dpi,
	/usr/share/fonts/75dpi
[   414.559] (==) ModulePath set to "/usr/lib/xorg/modules"
[   414.559] (II) The server relies on udev to provide the list of input devices.
	If no devices become available, reconfigure udev or disable AutoAddDevices.
[   414.559] (II) Module ABI versions:
[   414.559] 	X.Org ANSI C Emulation: 0.4
[   414.559] 	X.Org Video Driver: 24.1
[   414.559] 	X.Org XInput driver : 24.1
[   414.559] 	X.Org Server Extension : 10.0
[   414.561] (++) using VT number 1

[   414.563] (II) systemd-logind: took control of session /org/freedesktop/login1/session/_31
[   414.566] (II) xfree86: Adding drm device (/dev/dri/card0)
[   414.566] (II) Platform probe for /sys/devices/pci0000:00/0000:00:02.0/drm/card0
[   414.567] (II) systemd-logind: got fd for /dev/dri/card0 226:0 fd 10 paused 0
[   414.576] (--) PCI:*(0@0:2:0) 8086:0046:17aa:215a rev 2, Mem @ 0xf2000000/4194304, 0xd0000000/268435456, I/O @ 0x00001800/8, BIOS @ 0x????????/131072
[   414.576] (WW) Open ACPI failed (/var/run/acpid.socket) (No such file or directory)
[   414.576] (II) LoadModule: "glx"
[   414.576] (II) Loading /usr/lib/xorg/modules/extensions/libglx.so
[   414.578] (II) Module glx: vendor="X.Org Foundation"
[   414.578] 	compiled for 1.20.9, module version = 1.0.0
[   414.578] 	ABI class: X.Org Server Extension, version 10.0
[   414.578] (==) Matched intel as autoconfigured driver 0
[   414.578] (==) Matched modesetting as autoconfigured driver 1
[   414.578] (==) Matched fbdev as autoconfigured driver 2
[   414.578] (==) Matched vesa as autoconfigured driver 3
[   414.578] (==) Assigned the driver to the xf86ConfigLayout
[   414.578] (II) LoadModule: "intel"
[   414.579] (II) Loading /usr/lib/xorg/modules/drivers/intel_drv.so
[   414.579] (II) Module intel: vendor="X.Org Foundation"
[   414.579] 	compiled for 1.20.8, module version = 2.99.917
[   414.579] 	Module class: X.Org Video Driver
[   414.579] 	ABI class: X.Org Video Driver, version 24.1
[   414.579] (II) LoadModule: "modesetting"
[   414.579] (II) Loading /usr/lib/xorg/modules/drivers/modesetting_drv.so
[   414.580] (II) Module modesetting: vendor="X.Org Foundation"
[   414.580] 	compiled for 1.20.9, module version = 1.20.9
[   414.580] 	Module class: X.Org Video Driver
[   414.580] 	ABI class: X.Org Video Driver, version 24.1
[   414.580] (II) LoadModule: "fbdev"
[   414.580] (WW) Warning, couldn't open module fbdev
[   414.580] (EE) Failed to load module "fbdev" (module does not exist, 0)
[   414.580] (II) LoadModule: "vesa"
[   414.580] (II) Loading /usr/lib/xorg/modules/drivers/vesa_drv.so
[   414.581] (II) Module vesa: vendor="X.Org Foundation"
[   414.581] 	compiled for 1.20.8, module version = 2.4.0
[   414.581] 	Module class: X.Org Video Driver
[   414.581] 	ABI class: X.Org Video Driver, version 24.1
[   414.581] (II) intel: Driver for Intel(R) Integrated Graphics Chipsets:
	i810, i810-dc100, i810e, i815, i830M, 845G, 854, 852GM/855GM, 865G,
	915G, E7221 (i915), 915GM, 945G, 945GM, 945GME, Pineview GM,
	Pineview G, 965G, G35, 965Q, 946GZ, 965GM, 965GME/GLE, G33, Q35, Q33,
	GM45, 4 Series, G45/G43, Q45/Q43, G41, B43
[   414.581] (II) intel: Driver for Intel(R) HD Graphics
[   414.581] (II) intel: Driver for Intel(R) Iris(TM) Graphics
[   414.581] (II) intel: Driver for Intel(R) Iris(TM) Pro Graphics
[   414.581] (II) modesetting: Driver for Modesetting Kernel Drivers: kms
[   414.581] (II) VESA: driver for VESA chipsets: vesa
[   414.581] xf86EnableIOPorts: failed to set IOPL for I/O (Operation not permitted)
[   414.581] (II) intel(0): Using Kernel Mode Setting driver: i915, version 1.6.0 20200515
[   414.581] (II) intel(0): SNA compiled from 2.99.917-908-g7181c5a4
[   414.595] (WW) Falling back to old probe method for modesetting
[   414.595] (WW) VGA arbiter: cannot open kernel arbiter, no multi-card support
[   414.596] (--) intel(0): Integrated Graphics Chipset: Intel(R) HD Graphics
[   414.596] (--) intel(0): CPU: x86-64, sse2, sse3, ssse3, sse4.1, sse4.2; using a maximum of 2 threads
[   414.596] (II) intel(0): Creating default Display subsection in Screen section
	"Default Screen Section" for depth/fbbpp 24/32
[   414.596] (==) intel(0): Depth 24, (--) framebuffer bpp 32
[   414.596] (==) intel(0): RGB weight 888
[   414.596] (==) intel(0): Default visual is TrueColor
[   414.596] (II) intel(0): Output LVDS1 has no monitor section
[   414.597] (--) intel(0): Found backlight control interface intel_backlight (type 'raw') for output LVDS1
[   414.597] (II) intel(0): Enabled output LVDS1
[   414.597] (II) intel(0): Output VGA1 has no monitor section
[   414.597] (II) intel(0): Enabled output VGA1
[   414.597] (II) intel(0): Output HDMI1 has no monitor section
[   414.597] (II) intel(0): Enabled output HDMI1
[   414.597] (II) intel(0): Output DP1 has no monitor section
[   414.597] (II) intel(0): Enabled output DP1
[   414.597] (II) intel(0): Output HDMI2 has no monitor section
[   414.597] (II) intel(0): Enabled output HDMI2
[   414.598] (II) intel(0): Output HDMI3 has no monitor section
[   414.598] (II) intel(0): Enabled output HDMI3
[   414.598] (II) intel(0): Output DP2 has no monitor section
[   414.598] (II) intel(0): Enabled output DP2
[   414.598] (II) intel(0): Output DP3 has no monitor section
[   414.598] (II) intel(0): Enabled output DP3
[   414.598] (--) intel(0): Using a maximum size of 256x256 for hardware cursors
[   414.598] (II) intel(0): Output VIRTUAL1 has no monitor section
[   414.598] (II) intel(0): Enabled output VIRTUAL1
[   414.598] (--) intel(0): Output LVDS1 using initial mode 1440x900 on pipe 0
[   414.598] (==) intel(0): TearFree disabled
[   414.598] (==) intel(0): Using gamma correction (1.0, 1.0, 1.0)
[   414.598] (==) intel(0): DPI set to (96, 96)
[   414.598] (II) Loading sub module "dri3"
[   414.598] (II) LoadModule: "dri3"
[   414.598] (II) Module "dri3" already built-in
[   414.598] (II) Loading sub module "dri2"
[   414.598] (II) LoadModule: "dri2"
[   414.598] (II) Module "dri2" already built-in
[   414.598] (II) Loading sub module "present"
[   414.599] (II) LoadModule: "present"
[   414.599] (II) Module "present" already built-in
[   414.599] (II) UnloadModule: "modesetting"
[   414.599] (II) Unloading modesetting
[   414.599] (II) UnloadModule: "vesa"
[   414.599] (II) Unloading vesa
[   414.599] (II) intel(0): SNA initialized with Ironlake (gen5) backend
[   414.599] (==) intel(0): Backing store enabled
[   414.599] (==) intel(0): Silken mouse disabled
[   414.599] (II) intel(0): HW Cursor enabled
[   414.600] (==) intel(0): DPMS enabled
[   414.600] (==) intel(0): Display hotplug detection enabled
[   414.600] (II) intel(0): [XvMC] xvmc_vld driver initialized.
[   414.600] (II) intel(0): [DRI2] Setup complete
[   414.600] (II) intel(0): [DRI2]   DRI driver: i965
[   414.600] (II) intel(0): [DRI2]   VDPAU driver: va_gl
[   414.600] (II) intel(0): direct rendering: DRI2 DRI3 enabled
[   414.600] (II) intel(0): hardware support for Present enabled
[   414.600] (II) Initializing extension Generic Event Extension
[   414.600] (II) Initializing extension SHAPE
[   414.600] (II) Initializing extension MIT-SHM
[   414.600] (II) Initializing extension XInputExtension
[   414.600] (II) Initializing extension XTEST
[   414.600] (II) Initializing extension BIG-REQUESTS
[   414.600] (II) Initializing extension SYNC
[   414.600] (II) Initializing extension XKEYBOARD
[   414.600] (II) Initializing extension XC-MISC
[   414.600] (II) Initializing extension SECURITY
[   414.600] (II) Initializing extension XFIXES
[   414.600] (II) Initializing extension RENDER
[   414.600] (II) Initializing extension RANDR
[   414.600] (II) Initializing extension COMPOSITE
[   414.600] (II) Initializing extension DAMAGE
[   414.600] (II) Initializing extension MIT-SCREEN-SAVER
[   414.600] (II) Initializing extension DOUBLE-BUFFER
[   414.600] (II) Initializing extension RECORD
[   414.600] (II) Initializing extension DPMS
[   414.600] (II) Initializing extension Present
[   414.600] (II) Initializing extension DRI3
[   414.600] (II) Initializing extension X-Resource
[   414.600] (II) Initializing extension XVideo
[   414.600] (II) Initializing extension XVideo-MotionCompensation
[   414.600] (II) Initializing extension GLX
[   414.608] (EE) AIGLX error: Calling driver entry point failed
[   415.099] (II) IGLX: Loaded and initialized swrast
[   415.099] (II) GLX: Initialized DRISWRAST GL provider for screen 0
[   415.099] (II) Initializing extension XFree86-VidModeExtension
[   415.099] (II) Initializing extension XFree86-DGA
[   415.099] (II) Initializing extension XFree86-DRI
[   415.099] (II) Initializing extension DRI2
[   415.116] (II) intel(0): switch to mode 1440x900@60.0 on LVDS1 using pipe 0, position (0, 0), rotation normal, reflection none
[   415.126] (II) intel(0): Setting screen physical size to 381 x 238
[   415.276] (II) config/udev: Adding input device Power Button (/dev/input/event2)
[   415.276] (**) Power Button: Applying InputClass "libinput keyboard catchall"
[   415.276] (II) LoadModule: "libinput"
[   415.277] (II) Loading /usr/lib/xorg/modules/input/libinput_drv.so
[   415.279] (II) Module libinput: vendor="X.Org Foundation"
[   415.279] 	compiled for 1.20.8, module version = 0.30.0
[   415.279] 	Module class: X.Org XInput Driver
[   415.279] 	ABI class: X.Org XInput driver, version 24.1
[   415.279] (II) Using input driver 'libinput' for 'Power Button'
[   415.280] (II) systemd-logind: got fd for /dev/input/event2 13:66 fd 15 paused 0
[   415.280] (**) Power Button: always reports core events
[   415.280] (**) Option "Device" "/dev/input/event2"
[   415.280] (**) Option "_source" "server/udev"
[   415.282] (II) event2  - failed to create input device '/dev/input/event2'.
[   415.283] (EE) libinput: Power Button: Failed to create a device for /dev/input/event2
[   415.283] (EE) PreInit returned 2 for "Power Button"
[   415.283] (II) UnloadModule: "libinput"
[   415.283] (II) systemd-logind: releasing fd for 13:66
[   415.303] (II) config/udev: Adding input device Video Bus (/dev/input/event6)
[   415.303] (**) Video Bus: Applying InputClass "libinput keyboard catchall"
[   415.303] (II) Using input driver 'libinput' for 'Video Bus'
[   415.305] (II) systemd-logind: got fd for /dev/input/event6 13:70 fd 15 paused 0
[   415.305] (**) Video Bus: always reports core events
[   415.305] (**) Option "Device" "/dev/input/event6"
[   415.305] (**) Option "_source" "server/udev"
[   415.308] (II) event6  - failed to create input device '/dev/input/event6'.
[   415.308] (EE) libinput: Video Bus: Failed to create a device for /dev/input/event6
[   415.308] (EE) PreInit returned 2 for "Video Bus"
[   415.308] (II) UnloadModule: "libinput"
[   415.308] (II) systemd-logind: releasing fd for 13:70
[   415.350] (II) config/udev: Adding input device Lid Switch (/dev/input/event0)
[   415.350] (II) No input driver specified, ignoring this device.
[   415.350] (II) This device may have been added with another device file.
[   415.352] (II) config/udev: Adding input device Sleep Button (/dev/input/event1)
[   415.352] (**) Sleep Button: Applying InputClass "libinput keyboard catchall"
[   415.352] (II) Using input driver 'libinput' for 'Sleep Button'
[   415.353] (II) systemd-logind: got fd for /dev/input/event1 13:65 fd 15 paused 0
[   415.353] (**) Sleep Button: always reports core events
[   415.353] (**) Option "Device" "/dev/input/event1"
[   415.353] (**) Option "_source" "server/udev"
[   415.358] (II) event1  - failed to create input device '/dev/input/event1'.
[   415.359] (EE) libinput: Sleep Button: Failed to create a device for /dev/input/event1
[   415.359] (EE) PreInit returned 2 for "Sleep Button"
[   415.359] (II) UnloadModule: "libinput"
[   415.359] (II) systemd-logind: releasing fd for 13:65
[   415.395] (II) config/udev: Adding input device HDA Intel MID Dock Mic (/dev/input/event8)
[   415.395] (II) No input driver specified, ignoring this device.
[   415.395] (II) This device may have been added with another device file.
[   415.396] (II) config/udev: Adding input device HDA Intel MID Dock Headphone (/dev/input/event9)
[   415.396] (II) No input driver specified, ignoring this device.
[   415.396] (II) This device may have been added with another device file.
[   415.398] (II) config/udev: Adding input device HDA Intel MID Headphone (/dev/input/event10)
[   415.398] (II) No input driver specified, ignoring this device.
[   415.398] (II) This device may have been added with another device file.
[   415.400] (II) config/udev: Adding input device HDA Intel MID HDMI/DP,pcm=3 (/dev/input/event11)
[   415.400] (II) No input driver specified, ignoring this device.
[   415.400] (II) This device may have been added with another device file.
[   415.401] (II) config/udev: Adding input device HDA Intel MID HDMI/DP,pcm=7 (/dev/input/event12)
[   415.401] (II) No input driver specified, ignoring this device.
[   415.401] (II) This device may have been added with another device file.
[   415.403] (II) config/udev: Adding input device HDA Intel MID HDMI/DP,pcm=8 (/dev/input/event13)
[   415.403] (II) No input driver specified, ignoring this device.
[   415.403] (II) This device may have been added with another device file.
[   415.404] (II) config/udev: Adding input device HDA Intel MID Mic (/dev/input/event7)
[   415.405] (II) No input driver specified, ignoring this device.
[   415.405] (II) This device may have been added with another device file.
[   415.406] (II) config/udev: Adding input device AT Translated Set 2 keyboard (/dev/input/event3)
[   415.406] (**) AT Translated Set 2 keyboard: Applying InputClass "libinput keyboard catchall"
[   415.406] (II) Using input driver 'libinput' for 'AT Translated Set 2 keyboard'
[   415.408] (II) systemd-logind: got fd for /dev/input/event3 13:67 fd 15 paused 0
[   415.408] (**) AT Translated Set 2 keyboard: always reports core events
[   415.408] (**) Option "Device" "/dev/input/event3"
[   415.408] (**) Option "_source" "server/udev"
[   415.411] (II) event3  - failed to create input device '/dev/input/event3'.
[   415.411] (EE) libinput: AT Translated Set 2 keyboard: Failed to create a device for /dev/input/event3
[   415.411] (EE) PreInit returned 2 for "AT Translated Set 2 keyboard"
[   415.411] (II) UnloadModule: "libinput"
[   415.411] (II) systemd-logind: releasing fd for 13:67
[   415.430] (II) config/udev: Adding input device SynPS/2 Synaptics TouchPad (/dev/input/event14)
[   415.430] (**) SynPS/2 Synaptics TouchPad: Applying InputClass "libinput touchpad catchall"
[   415.430] (II) Using input driver 'libinput' for 'SynPS/2 Synaptics TouchPad'
[   415.432] (II) systemd-logind: got fd for /dev/input/event14 13:78 fd 15 paused 0
[   415.432] (**) SynPS/2 Synaptics TouchPad: always reports core events
[   415.432] (**) Option "Device" "/dev/input/event14"
[   415.432] (**) Option "_source" "server/udev"
[   415.436] (II) event14 - failed to create input device '/dev/input/event14'.
[   415.436] (EE) libinput: SynPS/2 Synaptics TouchPad: Failed to create a device for /dev/input/event14
[   415.436] (EE) PreInit returned 2 for "SynPS/2 Synaptics TouchPad"
[   415.436] (II) UnloadModule: "libinput"
[   415.436] (II) systemd-logind: releasing fd for 13:78
[   415.471] (II) config/udev: Adding input device SynPS/2 Synaptics TouchPad (/dev/input/mouse0)
[   415.471] (II) No input driver specified, ignoring this device.
[   415.471] (II) This device may have been added with another device file.
[   415.473] (II) config/udev: Adding input device TPPS/2 IBM TrackPoint (/dev/input/event15)
[   415.473] (**) TPPS/2 IBM TrackPoint: Applying InputClass "libinput pointer catchall"
[   415.473] (II) Using input driver 'libinput' for 'TPPS/2 IBM TrackPoint'
[   415.475] (II) systemd-logind: got fd for /dev/input/event15 13:79 fd 15 paused 0
[   415.475] (**) TPPS/2 IBM TrackPoint: always reports core events
[   415.475] (**) Option "Device" "/dev/input/event15"
[   415.475] (**) Option "_source" "server/udev"
[   415.478] (II) event15 - failed to create input device '/dev/input/event15'.
[   415.478] (EE) libinput: TPPS/2 IBM TrackPoint: Failed to create a device for /dev/input/event15
[   415.478] (EE) PreInit returned 2 for "TPPS/2 IBM TrackPoint"
[   415.478] (II) UnloadModule: "libinput"
[   415.478] (II) systemd-logind: releasing fd for 13:79
[   415.540] (II) config/udev: Adding input device TPPS/2 IBM TrackPoint (/dev/input/mouse1)
[   415.540] (II) No input driver specified, ignoring this device.
[   415.540] (II) This device may have been added with another device file.
[   415.541] (II) config/udev: Adding input device PC Speaker (/dev/input/event4)
[   415.541] (II) No input driver specified, ignoring this device.
[   415.541] (II) This device may have been added with another device file.
[   415.544] (II) config/udev: Adding input device ThinkPad Extra Buttons (/dev/input/event5)
[   415.544] (**) ThinkPad Extra Buttons: Applying InputClass "libinput keyboard catchall"
[   415.544] (II) Using input driver 'libinput' for 'ThinkPad Extra Buttons'
[   415.546] (II) systemd-logind: got fd for /dev/input/event5 13:69 fd 15 paused 0
[   415.546] (**) ThinkPad Extra Buttons: always reports core events
[   415.546] (**) Option "Device" "/dev/input/event5"
[   415.546] (**) Option "_source" "server/udev"
[   415.550] (II) event5  - failed to create input device '/dev/input/event5'.
[   415.551] (EE) libinput: ThinkPad Extra Buttons: Failed to create a device for /dev/input/event5
[   415.551] (EE) PreInit returned 2 for "ThinkPad Extra Buttons"
[   415.551] (II) UnloadModule: "libinput"
[   415.551] (II) systemd-logind: releasing fd for 13:69
[   416.206] (II) intel(0): EDID vendor "LEN", prod id 16438
[   416.206] (II) intel(0): Printing DDC gathered Modelines:
[   416.206] (II) intel(0): Modeline "1440x900"x0.0   96.10  1440 1488 1552 1728  900 903 909 926 -hsync -vsync (55.6 kHz eP)
[   416.206] (II) intel(0): Modeline "1440x900"x0.0   80.30  1440 1488 1552 1728  900 903 909 926 -hsync -vsync (46.5 kHz e)
[   424.551] (II) Server terminated successfully (0). Closing log file.

$ cat /etc/apparmor.d/usr.bin.startx:

#include <tunables/global>
profile /usr/bin/startx flags=(complain) {
}

My question is why the apparmor behaves like this? Am I misunderstanding the aa-complain command?

Tried to google, no succes, tried on two different archlinux installations (different GUIs) - both behave in the same way (reproducibility == high). Let me know uf any other log is needed, I will provide it. In audit log there are only "ALLOWED" signals from apparmor.

Thanks in advance for any explanation.

Offline

#2 2020-09-13 09:25:52

solskog
Member
Registered: 2020-09-05
Posts: 416

Re: AppArmor aa-complain startx blocks input devices

I am also new to apparmor but based on your profile setting I get the same result as you are, It looks like a chain of complain has been triggered.

# aa-status
18 profiles are in complain mode.
   /usr/bin/startx
   /usr/bin/startx//null-/usr/bin/expr
   /usr/bin/startx//null-/usr/bin/grep
   /usr/bin/startx//null-/usr/bin/hostname
   /usr/bin/startx//null-/usr/bin/mcookie
   /usr/bin/startx//null-/usr/bin/mktemp
   /usr/bin/startx//null-/usr/bin/sed
   /usr/bin/startx//null-/usr/bin/tty
   /usr/bin/startx//null-/usr/bin/uname
   /usr/bin/startx//null-/usr/bin/xauth
   /usr/bin/startx//null-/usr/bin/xinit
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/twm
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/Xorg
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/Xorg//null-/usr/lib/Xorg.wrap
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/Xorg//null-/usr/lib/Xorg.wrap//null-/usr/lib/Xorg
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/Xorg//null-/usr/lib/Xorg.wrap//null-/usr/lib/Xorg//null-/usr/bin/bash
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/Xorg//null-/usr/lib/Xorg.wrap//null-/usr/lib/Xorg//null-/usr/bin/bash//null-/usr/bin/xkbcomp
4 processes have profiles defined.
0 processes are in enforce mode.
4 processes are in complain mode.
   /usr/bin/bash (1453) /usr/bin/startx
   /usr/bin/xinit (1475) /usr/bin/startx//null-/usr/bin/xinit
   /usr/bin/twm (1482) /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/twm
   /usr/lib/Xorg (1476) /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/Xorg//null-/usr/lib/Xorg.wrap//null-/usr/lib/Xorg

Last edited by solskog (2020-09-13 09:26:56)

Offline

#3 2020-09-13 13:17:35

3yan
Member
Registered: 2016-10-06
Posts: 8

Re: AppArmor aa-complain startx blocks input devices

I agree with your observation. It lists undefined profiles. But as all of them are in complain mode, they should allow the GUI to operate normally.

xfce4:

apparmor module is loaded.
38 profiles are loaded.
0 profiles are in enforce mode.
38 profiles are in complain mode.
   /usr/bin/startx
   /usr/bin/startx//null-/usr/bin/deallocvt
   /usr/bin/startx//null-/usr/bin/expr
   /usr/bin/startx//null-/usr/bin/grep
   /usr/bin/startx//null-/usr/bin/hostname
   /usr/bin/startx//null-/usr/bin/mcookie
   /usr/bin/startx//null-/usr/bin/mktemp
   /usr/bin/startx//null-/usr/bin/rm
   /usr/bin/startx//null-/usr/bin/sed
   /usr/bin/startx//null-/usr/bin/tty
   /usr/bin/startx//null-/usr/bin/uname
   /usr/bin/startx//null-/usr/bin/xauth
   /usr/bin/startx//null-/usr/bin/xinit
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/Xorg
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/Xorg//null-/usr/lib/Xorg.wrap
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/Xorg//null-/usr/lib/Xorg.wrap//null-/usr/lib/Xorg
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/Xorg//null-/usr/lib/Xorg.wrap//null-/usr/lib/Xorg//null-/usr/bin/bash
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/Xorg//null-/usr/lib/Xorg.wrap//null-/usr/lib/Xorg//null-/usr/bin/bash//null-/usr/bin/xkbcomp
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/Xorg//null-/usr/lib/Xorg.wrap//null-/usr/lib/Xorg//null-/usr/lib/xf86-video-intel-backlight-helper
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash//null-/usr/bin/cat
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash//null-/usr/bin/dbus-update-activation-environment
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash//null-/usr/bin/systemctl
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash//null-/usr/bin/xfce4-session
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash//null-/usr/bin/xfce4-session//null-/usr/bin/bash
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash//null-/usr/bin/xfce4-session//null-/usr/bin/bash//null-/usr/bin/iceauth
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash//null-/usr/bin/xfce4-session//null-/usr/bin/gpg-agent
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash//null-/usr/bin/xfce4-session//null-/usr/bin/thunar
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash//null-/usr/bin/xfce4-session//null-/usr/bin/xfce4-panel
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash//null-/usr/bin/xfce4-session//null-/usr/bin/xfce4-panel//null-/usr/lib/xfce4/panel/wrapper-2.0
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash//null-/usr/bin/xfce4-session//null-/usr/bin/xfce4-power-manager
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash//null-/usr/bin/xfce4-session//null-/usr/bin/xfdesktop
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash//null-/usr/bin/xfce4-session//null-/usr/bin/xfsettingsd
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash//null-/usr/bin/xfce4-session//null-/usr/bin/xfwm4
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash//null-/usr/bin/xfce4-session//null-/usr/lib/polkit-gnome/polkit-gnome-authentication-agent-1
   /usr/bin/startx//null-/usr/bin/xinit//null-/usr/bin/bash//null-/usr/bin/startxfce4//null-/usr/bin/bash//null-/usr/bin/xrdb
0 processes have profiles defined.
0 processes are in enforce mode.
0 processes are in complain mode.
0 processes are unconfined but have a profile defined.

Offline

Board footer

Powered by FluxBB