It looks like this but has reappeared in 4.9.3+ds1-1ubuntu0.2+esm1?

With 4.9.3+ds1-1ubuntu0.2+esm1 installed, i get

2025-05-08T22:48:02.424467+02:00 ember kernel: audit: type=1400 
audit(1746737282.423:240): apparmor="DENIED" operation="signal" class="signal" 
profile="containers-default-0.57.4" pid=5406 comm="3" requested_mask="receive" 
denied_mask="receive" signal=term peer="crun"
2025-05-08T22:48:12.447362+02:00 ember kernel: audit: type=1400 
audit(1746737292.444:241): apparmor="DENIED" operation="signal" class="signal" 
profile="containers-default-0.57.4" pid=5459 comm="3" requested_mask="receive" 
denied_mask="receive" signal=kill peer="crun" 

in kern.log when trying to stop a container started by root (directly or via 
systemd), and podman stop outputs
WARN[0010] StopSignal SIGTERM failed to stop container hlo in 10 seconds, 
resorting to SIGKILL
Error: given PID did not die within timeout

If i apt install podman=4.9.3+ds1-1ubuntu0.2 and then reboot, stopping
containers made both directly and with systemd works again.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2040483

Title:
  AppArmor denies crun sending signals to containers (stop, kill)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/golang-github-containers-common/+bug/2040483/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to