[Bug 2074204] Re: AppArmor profiles missing for jammy and 6.8 kernel
Steve Langasek
2074204 at bugs.launchpad.net
Tue Aug 13 21:47:45 UTC 2024
> It's so weird. Autopkgtest on s390x fails because it can't open
> http://people.canonical.com/~ubuntu-archive/seeds/ubuntu.jammy/STRUCTURE, apparently!?
This looks like a firewall problem on the s390x autopkgtest runners.
I see that you did a baseline retest with migration-reference/0 and that
one landed on a runner in the bos01 region:
https://autopkgtest.ubuntu.com/results/autopkgtest-
jammy/jammy/s390x/l/livecd-rootfs/20240812_102717_e29f6@/log.gz
The failures appear to be in the bos03 region:
https://autopkgtest.ubuntu.com/results/autopkgtest-
jammy/jammy/s390x/l/livecd-rootfs/20240812_201708_d80bd@/log.gz
--
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to livecd-rootfs in Ubuntu.
https://bugs.launchpad.net/bugs/2074204
Title:
AppArmor profiles missing for jammy and 6.8 kernel
Status in livecd-rootfs package in Ubuntu:
Fix Released
Status in livecd-rootfs source package in Jammy:
Fix Committed
Bug description:
A CPC test build of a jammy image with 6.8 edge kernel revealed that
AppArmor profiles are missing for 6.8 kernel in livecd-rootfs, leading
to fall back to generic AppArmor profiles which don't contain
configuration for io_uring. This leads to `snap debug seeding` output
non-empty `seed-restart-system-key` dict (attached in snap-debug-
seeding.json) after first boot.
[ Impact ]
Boot will be slowed by ~200ms until this is resolved in livecd-rootfs
[ Test Plan ]
* Build a jammy cloud image with preseeded snaps with the 6.8 edge kernel
* Boot an instance
* Invoke "snap debug seeding"
* Ensure the output does not include "seed-restart-system-key", if it does the difference between "preseed-system-key" and "apparmor-features"/"apparmor-parser-features" is other than "io_uring"
[ Where problems could occur ]
* If the attempted fix has problems "snap debug seeding" should continue to report "seed-restart-system-key". There should not be any other fallout.
[ Other Info ]
Public cloud images block image publication on a test ensuring that
snaps are preseeded. As a result this will block jammy image
publication once the edge kernel becomes the HWE kernel.
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/livecd-rootfs/+bug/2074204/+subscriptions
More information about the foundations-bugs
mailing list