[Bug 2098906] Re: apparmor breaks sbuild with unshare on plucky

2025-02-20 Thread Launchpad Bug Tracker
This bug was fixed in the package apparmor - 4.1.0~beta5-0ubuntu4 --- apparmor (4.1.0~beta5-0ubuntu4) plucky; urgency=medium * Add patch to fix sbuild unshare breakage caused by the new unshare-userns-restrict profile (LP: #2098906) - d/p/u/sbuild_mr_1555.patch apparmor (4.

[Bug 2098906] Re: apparmor breaks sbuild with unshare on plucky

2025-02-20 Thread Thomas Bechtold
The workaround that worked for me is: $ sudo ln -s /etc/apparmor.d/unshare-userns-restrict /etc/apparmor.d/disable/ $ sudo apparmor_parser -R /etc/apparmor.d/unprivileged_userns -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://

[Bug 2098906] Re: apparmor breaks sbuild with unshare on plucky

2025-02-19 Thread Ryan Lee
** Changed in: apparmor (Ubuntu) Status: Confirmed => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2098906 Title: apparmor breaks sbuild with unshare on plucky To manage notif

[Bug 2098906] Re: apparmor breaks sbuild with unshare on plucky

2025-02-19 Thread Ryan Lee
This breakage is due to the latest AppArmor packaging enabling a unshare-userns-restrict profile by default. In most cases, this allows more usage of unshare than before (while limiting the attack surface exposed by capabilities in unprivileged user namespaces), but sbuild is one of the cases where

[Bug 2098906] Re: apparmor breaks sbuild with unshare on plucky

2025-02-19 Thread John Johansen
temporary fix sudo apparmor_parser -R /etc/apparmor.d/unprivileged_userns or to make it persist after reboot sudo aa-disable /etc/apparmor.d/unprivileged_userns -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.n