Thanks, I gave it a shot (after putting the profile into complain mode) and here are the unique denials that I see when starting the guest session:
operation="mknod" profile="/usr/lib/lightdm/lightdm-guest-session" name="/proc/1295/fd/2" pid=1295 comm="lightdm-session" requested_mask="c" denied_mask="c" fsuid=998 ouid=998 operation="mknod" profile="/usr/lib/lightdm/lightdm-guest-session" name="/proc/1297/fd/2" pid=1297 comm="lightdm-session" requested_mask="c" denied_mask="c" fsuid=998 ouid=998 operation="connect" profile="/usr/lib/lightdm/lightdm-guest-session" pid=1446 comm="initctl" family="unix" sock_type="stream" protocol=0 requested_mask="send receive accept" denied_mask="send accept" addr="@/com/ubuntu/upstart-session/998/1293" peer_addr=none peer="unconfined" operation="file_perm" profile="/usr/lib/lightdm/lightdm-guest-session" pid=1293 comm="upstart" family="unix" sock_type="stream" protocol=0 requested_mask="send receive" denied_mask="send" addr="@/com/ubuntu/upstart-session/998/1293" peer_addr=none peer="unconfined" operation="connect" profile="/usr/lib/lightdm/lightdm-guest-session" pid=1709 comm="unity-panel-ser" family="unix" sock_type="stream" protocol=0 requested_mask="send receive accept" denied_mask="send accept" addr="@/com/ubuntu/upstart-session/998/1293" peer_addr=none peer="unconfined"
and when logging out of the guest session:
operation="connect" profile="/usr/lib/lightdm/lightdm-guest-session" pid=2042 comm="dbus-send" family="unix" sock_type="stream" protocol=0 requested_mask="send receive accept" denied_mask="send accept" addr="@/com/ubuntu/upstart-session/998/1293" peer_addr=none peer="unconfined" operation="file_perm" profile="/usr/lib/lightdm/lightdm-guest-session" pid=1293 comm="upstart" family="unix" sock_type="stream" protocol=0 requested_mask="send receive" denied_mask="send" addr="@/com/ubuntu/upstart-session/998/1293" peer_addr=none peer="unconfined" operation="connect" profile="/usr/lib/lightdm/lightdm-guest-session" pid=2046 comm="initctl" family="unix" sock_type="stream" protocol=0 requested_mask="send receive accept" denied_mask="send accept" addr="@/com/ubuntu/upstart-session/998/1293" peer_addr=none peer="unconfined" operation="connect" profile="/usr/lib/lightdm/lightdm-guest-session" pid=1709 comm="unity-panel-ser" family="unix" sock_type="stream" protocol=0 requested_mask="send receive accept" denied_mask="send accept" addr="@/com/ubuntu/upstart-session/998/1293" peer_addr=none peer="unconfined"
Thanks, I gave it a shot (after putting the profile into complain mode) and here are the unique denials that I see when starting the guest session:
operation="mknod" profile= "/usr/lib/ lightdm/ lightdm- guest-session" name="/ proc/1295/ fd/2" pid=1295 comm="lightdm- session" requested_mask="c" denied_mask="c" fsuid=998 ouid=998 "/usr/lib/ lightdm/ lightdm- guest-session" name="/ proc/1297/ fd/2" pid=1297 comm="lightdm- session" requested_mask="c" denied_mask="c" fsuid=998 ouid=998 "/usr/lib/ lightdm/ lightdm- guest-session" pid=1446 comm="initctl" family="unix" sock_type="stream" protocol=0 requested_ mask="send receive accept" denied_mask="send accept" addr="@ /com/ubuntu/ upstart- session/ 998/1293" peer_addr=none peer="unconfined" "file_perm" profile= "/usr/lib/ lightdm/ lightdm- guest-session" pid=1293 comm="upstart" family="unix" sock_type="stream" protocol=0 requested_ mask="send receive" denied_mask="send" addr="@ /com/ubuntu/ upstart- session/ 998/1293" peer_addr=none peer="unconfined" "/usr/lib/ lightdm/ lightdm- guest-session" pid=1709 comm="unity- panel-ser" family="unix" sock_type="stream" protocol=0 requested_ mask="send receive accept" denied_mask="send accept" addr="@ /com/ubuntu/ upstart- session/ 998/1293" peer_addr=none peer="unconfined"
operation="mknod" profile=
operation="connect" profile=
operation=
operation="connect" profile=
and when logging out of the guest session:
operation="connect" profile= "/usr/lib/ lightdm/ lightdm- guest-session" pid=2042 comm="dbus-send" family="unix" sock_type="stream" protocol=0 requested_ mask="send receive accept" denied_mask="send accept" addr="@ /com/ubuntu/ upstart- session/ 998/1293" peer_addr=none peer="unconfined" "file_perm" profile= "/usr/lib/ lightdm/ lightdm- guest-session" pid=1293 comm="upstart" family="unix" sock_type="stream" protocol=0 requested_ mask="send receive" denied_mask="send" addr="@ /com/ubuntu/ upstart- session/ 998/1293" peer_addr=none peer="unconfined" "/usr/lib/ lightdm/ lightdm- guest-session" pid=2046 comm="initctl" family="unix" sock_type="stream" protocol=0 requested_ mask="send receive accept" denied_mask="send accept" addr="@ /com/ubuntu/ upstart- session/ 998/1293" peer_addr=none peer="unconfined" "/usr/lib/ lightdm/ lightdm- guest-session" pid=1709 comm="unity- panel-ser" family="unix" sock_type="stream" protocol=0 requested_ mask="send receive accept" denied_mask="send accept" addr="@ /com/ubuntu/ upstart- session/ 998/1293" peer_addr=none peer="unconfined"
operation=
operation="connect" profile=
operation="connect" profile=