Hm weird, I get this:

$ tshark -w test
tshark: Can't open your preferences file 
"/home/lukas/.config/wireshark/preferences": Permission denied.
tshark: Can't open your preferences file 
"/home/lukas/.config/wireshark/preferences": Permission denied.
tshark: Could not open your disabled protocols file
"/home/lukas/.config/wireshark/disabled_protos": Permission denied.
tshark: Could not open your enabled protocols file
"/home/lukas/.config/wireshark/enabled_protos": Permission denied.
tshark: Could not open your heuristic dissectors file
"/home/lukas/.config/wireshark/heuristic_protos": Permission denied.
Capturing on 'enp1s0'
tshark: The file to which the capture would be saved ("test") could not be 
opened: Permission denied.

And this in the logs:
Aug 26 08:53:20 pulp-fiction kernel: audit: type=1400 
audit(1756191200.772:22039): apparmor="DENIED" operation="open" class="file" 
profile="tshark" name="/home/luk>
Aug 26 08:53:20 pulp-fiction kernel: audit: type=1400 
audit(1756191200.772:22040): apparmor="DENIED" operation="open" class="file" 
profile="tshark" name="/home/luk>
Aug 26 08:53:20 pulp-fiction kernel: audit: type=1400 
audit(1756191200.773:22041): apparmor="DENIED" operation="open" class="file" 
profile="tshark" name="/home/luk>
Aug 26 08:53:20 pulp-fiction kernel: audit: type=1400 
audit(1756191200.774:22042): apparmor="DENIED" operation="open" class="file" 
profile="tshark" name="/home/luk>
Aug 26 08:53:20 pulp-fiction kernel: audit: type=1400 
audit(1756191200.774:22043): apparmor="DENIED" operation="open" class="file" 
profile="tshark" name="/home/luk>
Aug 26 08:53:20 pulp-fiction kernel: audit: type=1400 
audit(1756191200.774:22044): apparmor="DENIED" operation="open" class="file" 
profile="tshark" name="/home/luk>
Aug 26 08:53:20 pulp-fiction kernel: audit: type=1400 
audit(1756191200.774:22045): apparmor="DENIED" operation="open" class="file" 
profile="tshark" name="/home/luk>
Aug 26 08:53:20 pulp-fiction kernel: r8169 0000:01:00.0 enp1s0: entered 
promiscuous mode
Aug 26 08:53:20 pulp-fiction kernel: audit: type=1400 
audit(1756191200.795:22046): apparmor="DENIED" operation="mknod" class="file" 
profile="tshark//dumpcap" name=>

Maybe I have something wrong with my permissions in general, I'll check.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2121132

Title:
  tshark apparmor permissions are too restrictive

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/wireshark/+bug/2121132/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to