livecd-rootfs 23.10.55 for mantic is currently migrating, and has apparmor changes as well (mounting different features in the build chroot). To help rule out some issues, I built a a qcow2 image and a squashfs for mantic using livecd-rootfs 23.10.55 Running the mantic host, and launching a released jammy container # On the mantic host VM journalctl -f -b -k Oct 05 21:25:26 novel-ram kernel: kauditd_printk_skb: 220 callbacks suppressed Oct 05 21:25:26 novel-ram kernel: audit: type=1400 audit(1696541126.968:6178): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=11660 comm="systemd" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:25:27 novel-ram kernel: audit: type=1400 audit(1696541127.036:6179): apparmor="DENIED" operation="signal" class="signal" profile="lxd-current-iguana_" pid=12656 comm="snapd" requested_mask="send" denied_mask="send" signal=urg peer="lxd-current-iguana_//&unconfined" Oct 05 21:25:27 novel-ram kernel: audit: type=1400 audit(1696541127.044:6180): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=11722 comm="systemd-journal" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:25:27 novel-ram kernel: audit: type=1400 audit(1696541127.044:6181): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=11722 comm="systemd-journal" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:25:27 novel-ram kernel: audit: type=1400 audit(1696541127.168:6182): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=12699 comm="systemctl" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:25:27 novel-ram kernel: audit: type=1400 audit(1696541127.228:6183): apparmor="DENIED" operation="signal" class="signal" profile="lxd-current-iguana_" pid=11660 comm="systemd" requested_mask="send" denied_mask="send" signal=exists peer="lxd-current-iguana_//&unconfined" Oct 05 21:25:27 novel-ram kernel: audit: type=1400 audit(1696541127.236:6184): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=12701 comm="systemctl" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:25:27 novel-ram kernel: audit: type=1400 audit(1696541127.240:6185): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=12702 comm="systemctl" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:25:27 novel-ram kernel: audit: type=1400 audit(1696541127.244:6186): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=12703 comm="systemctl" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:25:27 novel-ram kernel: audit: type=1400 audit(1696541127.252:6187): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=12704 comm="systemctl" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" within the mantic container: $ snap changes ID Status Spawn Ready Summary 1 Error today at 21:03 UTC today at 21:14 UTC Initialize system state 2 Done today at 21:14 UTC today at 21:14 UTC Initialize device 3 Error today at 21:14 UTC today at 21:14 UTC Initialize system state 4 Error today at 21:19 UTC today at 21:19 UTC Initialize system state 5 Error today at 21:24 UTC today at 21:30 UTC Initialize system state $ snap tasks 5 Status Spawn Ready Summary Done today at 21:24 UTC today at 21:30 UTC Ensure prerequisites for "snapd" are available Undone today at 21:24 UTC today at 21:30 UTC Prepare snap "/var/lib/snapd/seed/snaps/snapd_20092.snap" (20092) Error today at 21:24 UTC today at 21:24 UTC Mount snap "snapd" (20092) Hold today at 21:24 UTC today at 21:24 UTC Copy snap "snapd" data Hold today at 21:24 UTC today at 21:24 UTC Setup snap "snapd" (20092) security profiles ... Mount snap "snapd" (20092) 2023-10-05T21:24:57Z ERROR systemctl command [reload-or-restart snap-snapd-20092.mount] failed with exit status 4: Failed to reload-or-restart snap-snapd-20092.mount: Transaction for snap-snapd-20092.mount/start is destructive (halt.target has 'start' job queued, but 'stop' is included in transaction). See system logs and 'systemctl status snap-snapd-20092.mount' for details. # on the mantic host journalctl -f -b -k Oct 05 21:30:55 novel-ram kernel: kauditd_printk_skb: 184 callbacks suppressed Oct 05 21:30:55 novel-ram kernel: audit: type=1400 audit(1696541455.545:7246): apparmor="DENIED" operation="signal" class="signal" profile="lxd-sharing-tick_" pid=14545 comm="snap" requested_mask="send" denied_mask="send" signal=urg peer="lxd-sharing-tick_//&unconfined" Oct 05 21:30:56 novel-ram kernel: audit: type=1400 audit(1696541456.641:7247): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-sharing-tick_" pid=14232 comm="systemd" requested_mask="read" denied_mask="read" peer="lxd-sharing-tick_//&unconfined" Oct 05 21:30:56 novel-ram kernel: audit: type=1400 audit(1696541456.649:7248): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-sharing-tick_" pid=14292 comm="systemd-journal" requested_mask="read" denied_mask="read" peer="lxd-sharing-tick_//&unconfined" Oct 05 21:30:56 novel-ram kernel: audit: type=1400 audit(1696541456.649:7249): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-sharing-tick_" pid=14292 comm="systemd-journal" requested_mask="read" denied_mask="read" peer="lxd-sharing-tick_//&unconfined" Oct 05 21:30:57 novel-ram kernel: audit: type=1400 audit(1696541457.333:7250): apparmor="AUDIT" operation="change_profile" class="file" info="change_profile unprivileged unconfined converted to stacking" profile="unconfined" name="lxd-sharing-tick_//&unconfined//&:lxd-sharing-tick_:unconfined" pid=14632 comm="lxd" Oct 05 21:30:57 novel-ram kernel: audit: type=1400 audit(1696541457.341:7251): apparmor="DENIED" operation="signal" class="signal" profile="lxd-sharing-tick_" pid=14292 comm="systemd-journal" requested_mask="send" denied_mask="send" signal=exists peer="lxd-sharing-tick_//&unconfined" Oct 05 21:30:57 novel-ram kernel: audit: type=1400 audit(1696541457.341:7252): apparmor="DENIED" operation="signal" class="signal" profile="lxd-sharing-tick_" pid=14292 comm="systemd-journal" requested_mask="send" denied_mask="send" signal=exists peer="lxd-sharing-tick_//&unconfined" Oct 05 21:30:57 novel-ram kernel: audit: type=1400 audit(1696541457.341:7253): apparmor="DENIED" operation="signal" class="signal" profile="lxd-sharing-tick_" pid=14292 comm="systemd-journal" requested_mask="send" denied_mask="send" signal=exists peer="lxd-sharing-tick_//&unconfined" Oct 05 21:30:57 novel-ram kernel: audit: type=1400 audit(1696541457.341:7254): apparmor="DENIED" operation="signal" class="signal" profile="lxd-sharing-tick_" pid=14292 comm="systemd-journal" requested_mask="send" denied_mask="send" signal=exists peer="lxd-sharing-tick_//&unconfined" Oct 05 21:30:57 novel-ram kernel: audit: type=1400 audit(1696541457.341:7255): apparmor="DENIED" operation="signal" class="signal" profile="lxd-sharing-tick_" pid=14292 comm="systemd-journal" requested_mask="send" denied_mask="send" signal=exists peer="lxd-sharing-tick_//&unconfined" Oct 05 21:31:14 novel-ram kernel: kauditd_printk_skb: 14 callbacks suppressed Oct 05 21:31:14 novel-ram kernel: audit: type=1400 audit(1696541474.250:7270): apparmor="DENIED" operation="signal" class="signal" profile="lxd-sharing-tick_" pid=14657 comm="snap" requested_mask="send" denied_mask="send" signal=urg peer="lxd-sharing-tick_//&unconfined" Oct 05 21:31:21 novel-ram kernel: audit: type=1400 audit(1696541481.842:7271): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-sharing-tick_" pid=14292 comm="systemd-journal" requested_mask="read" denied_mask="read" peer="lxd-sharing-tick_//&unconfined" Oct 05 21:31:21 novel-ram kernel: audit: type=1400 audit(1696541481.842:7272): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-sharing-tick_" pid=14292 comm="systemd-journal" requested_mask="read" denied_mask="read" peer="lxd-sharing-tick_//&unconfined" Oct 05 21:31:51 novel-ram kernel: audit: type=1400 audit(1696541511.262:7273): apparmor="DENIED" operation="signal" class="signal" profile="lxd-sharing-tick_" pid=14545 comm="snap" requested_mask="send" denied_mask="send" signal=urg peer="lxd-sharing-tick_//&unconfined" Oct 05 21:32:55 novel-ram kernel: audit: type=1400 audit(1696541575.358:7274): apparmor="DENIED" operation="signal" class="signal" profile="lxd-sharing-tick_" pid=14641 comm="bash" requested_mask="send" denied_mask="send" signal=int peer="lxd-sharing-tick_//&unconfined" Oct 05 21:33:05 novel-ram kernel: audit: type=1400 audit(1696541585.198:7275): apparmor="DENIED" operation="signal" class="signal" profile="lxd-sharing-tick_" pid=14680 comm="journalctl" requested_mask="send" denied_mask="send" signal=cont peer="lxd-sharing-tick_//&unconfined" Oct 05 21:33:11 novel-ram kernel: audit: type=1400 audit(1696541591.070:7276): apparmor="DENIED" operation="signal" class="signal" profile="lxd-sharing-tick_" pid=14682 comm="journalctl" requested_mask="send" denied_mask="send" signal=cont peer="lxd-sharing-tick_//&unconfined" Launching a published Jammy LXC container results in errors as well: # inside Jammy Container $ cat /etc/cloud/build.info build_name: server serial: 20230927 $ cat /etc/os-release PRETTY_NAME="Ubuntu 22.04.3 LTS" NAME="Ubuntu" VERSION_ID="22.04" VERSION="22.04.3 LTS (Jammy Jellyfish)" VERSION_CODENAME=jammy ID=ubuntu ... $ snap changes ID Status Spawn Ready Summary 1 Error 8 days ago, at 02:11 UTC today at 20:49 UTC Initialize system state 2 Done today at 20:48 UTC today at 20:49 UTC Initialize device 3 Error today at 20:54 UTC today at 20:54 UTC Initialize system state 4 Error today at 20:59 UTC today at 20:59 UTC Initialize system state 5 Error today at 21:04 UTC today at 21:05 UTC Initialize system state 6 Error today at 21:10 UTC today at 21:10 UTC Initialize system state 7 Error today at 21:25 UTC today at 21:25 UTC Initialize system state 8 Error today at 21:30 UTC today at 21:30 UTC Initialize system state 9 Error today at 21:34 UTC today at 21:34 UTC Initialize system state $ snap tasks 9 ... Done today at 21:34 UTC today at 21:34 UTC Ensure prerequisites for "lxd" are available Undone today at 21:34 UTC today at 21:34 UTC Prepare snap "/var/lib/snapd/seed/snaps/lxd_24322.snap" (24322) Undone today at 21:34 UTC today at 21:34 UTC Mount snap "lxd" (24322) Error today at 21:34 UTC today at 21:34 UTC Copy snap "lxd" data Undone today at 21:34 UTC today at 21:34 UTC Setup snap "lxd" (24322) security profiles Undone today at 21:34 UTC today at 21:34 UTC Make snap "lxd" (24322) available to the system Undone today at 21:34 UTC today at 21:34 UTC Automatically connect eligible plugs and slots of snap "lxd" Undone today at 21:34 UTC today at 21:34 UTC Set automatic aliases for snap "lxd" Undone today at 21:34 UTC today at 21:34 UTC Setup snap "lxd" aliases Error today at 21:34 UTC today at 21:34 UTC Run install hook of "lxd" snap if present Hold today at 21:34 UTC today at 21:34 UTC Start snap "lxd" (24322) services Hold today at 21:34 UTC today at 21:34 UTC Run configure hook of "lxd" snap if present Hold today at 21:34 UTC today at 21:34 UTC Run health check of "lxd" snap Hold today at 21:34 UTC today at 21:34 UTC Mark system seeded Undone today at 21:34 UTC today at 21:34 UTC Connect lxd:lxd-support to snapd:lxd-support Undone today at 21:34 UTC today at 21:34 UTC Connect lxd:network to snapd:network Undone today at 21:34 UTC today at 21:34 UTC Connect lxd:network-bind to snapd:network-bind Undone today at 21:34 UTC today at 21:34 UTC Connect lxd:system-observe to snapd:system-observe Undone today at 21:34 UTC today at 21:34 UTC Setup snap "lxd" (24322) security profiles for auto-connections Make snap "snapd" (20092) available to the system 2023-10-05T21:34:47Z INFO Requested daemon restart (snapd snap). 2023-10-05T21:34:57Z INFO Requested daemon restart (snapd snap). ...................................................................... Automatically connect eligible plugs and slots of snap "snapd" 2023-10-05T21:34:47Z INFO Waiting for automatic snapd restart... ...................................................................... Copy snap "lxd" data 2023-10-05T21:34:56Z ERROR unlinkat /var/snap/lxd/common/var/lib/lxcfs/proc/cpuinfo: function not implemented ...................................................................... Run install hook of "lxd" snap if present 2023-10-05T21:34:55Z ERROR run hook "install": cannot read mount namespace identifier of pid 1: Permission denied # on mantic host Oct 05 21:34:58 novel-ram kernel: kauditd_printk_skb: 212 callbacks suppressed Oct 05 21:34:58 novel-ram kernel: audit: type=1400 audit(1696541698.251:8146): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=15416 comm="systemd" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:34:58 novel-ram kernel: audit: type=1400 audit(1696541698.279:8147): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=15478 comm="systemd-journal" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:34:58 novel-ram kernel: audit: type=1400 audit(1696541698.279:8148): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=15478 comm="systemd-journal" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:34:58 novel-ram kernel: audit: type=1400 audit(1696541698.287:8149): apparmor="DENIED" operation="signal" class="signal" profile="lxd-current-iguana_" pid=16486 comm="snapd" requested_mask="send" denied_mask="send" signal=urg peer="lxd-current-iguana_//&unconfined" Oct 05 21:34:58 novel-ram kernel: audit: type=1400 audit(1696541698.443:8150): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=15478 comm="systemd-journal" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:34:58 novel-ram kernel: audit: type=1400 audit(1696541698.443:8151): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=15478 comm="systemd-journal" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:34:58 novel-ram kernel: audit: type=1400 audit(1696541698.467:8152): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=16529 comm="systemctl" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:34:58 novel-ram kernel: audit: type=1400 audit(1696541698.519:8153): apparmor="DENIED" operation="signal" class="signal" profile="lxd-current-iguana_" pid=15416 comm="systemd" requested_mask="send" denied_mask="send" signal=exists peer="lxd-current-iguana_//&unconfined" Oct 05 21:34:58 novel-ram kernel: audit: type=1400 audit(1696541698.523:8154): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=16531 comm="systemctl" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:34:58 novel-ram kernel: audit: type=1400 audit(1696541698.527:8155): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=16532 comm="systemctl" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:35:04 novel-ram kernel: kauditd_printk_skb: 41 callbacks suppressed Oct 05 21:35:04 novel-ram kernel: audit: type=1400 audit(1696541704.007:8197): apparmor="DENIED" operation="signal" class="signal" profile="lxd-current-iguana_" pid=16567 comm="snap" requested_mask="send" denied_mask="send" signal=urg peer="lxd-current-iguana_//&unconfined" Oct 05 21:35:11 novel-ram kernel: audit: type=1400 audit(1696541711.031:8198): apparmor="DENIED" operation="signal" class="signal" profile="lxd-current-iguana_" pid=15677 comm="snap" requested_mask="send" denied_mask="send" signal=urg peer="lxd-current-iguana_//&unconfined" Oct 05 21:35:14 novel-ram kernel: audit: type=1400 audit(1696541714.915:8199): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=15478 comm="systemd-journal" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:35:14 novel-ram kernel: audit: type=1400 audit(1696541714.915:8200): apparmor="DENIED" operation="ptrace" class="ptrace" profile="lxd-current-iguana_" pid=15478 comm="systemd-journal" requested_mask="read" denied_mask="read" peer="lxd-current-iguana_//&unconfined" Oct 05 21:35:33 novel-ram kernel: audit: type=1400 audit(1696541733.471:8201): apparmor="DENIED" operation="signal" class="signal" profile="lxd-current-iguana_" pid=16486 comm="snapd" requested_mask="send" denied_mask="send" signal=urg peer="lxd-current-iguana_//&unconfined" Oct 05 21:35:44 novel-ram kernel: audit: type=1400 audit(1696541744.875:8202): apparmor="DENIED" operation="signal" class="signal" profile="lxd-current-iguana_" pid=16574 comm="snap" requested_mask="send" denied_mask="send" signal=urg peer="lxd-current-iguana_//&unconfined" Oct 05 21:35:58 novel-ram kernel: audit: type=1400 audit(1696541758.587:8203): apparmor="DENIED" operation="signal" class="signal" profile="lxd-current-iguana_" pid=16579 comm="snap" requested_mask="send" denied_mask="send" signal=urg peer="lxd-current-iguana_//&unconfined" Oct 05 21:37:36 novel-ram kernel: audit: type=1400 audit(1696541856.872:8204): apparmor="DENIED" operation="signal" class="signal" profile="lxd-current-iguana_" pid=16596 comm="snap" requested_mask="send" denied_mask="send" signal=urg peer="lxd-current-iguana_//&unconfined"