This can be reproduced by just running "wg genkey" in a questing
container:

ubuntu@q-wg:~$ wg genkey; echo $?
0

Which results in no key being printed, and these apparmor DENIED
messages in dmesg of the host:

[Tue Jan  6 17:18:10 2026] audit: type=1400 audit(1767719889.884:799): 
apparmor="DENIED" operation="file_inherit" class="file" 
namespace="root//lxd-q-wg_<var-snap-lxd-common-lxd>" profile="wg" 
name="/dev/pts/2" pid=97928 comm="wg" requested_mask="wr" denied_mask="wr" 
fsuid=1001000 ouid=1001000
[Tue Jan  6 17:18:10 2026] audit: type=1400 audit(1767719889.884:800): 
apparmor="DENIED" operation="file_inherit" class="file" 
namespace="root//lxd-q-wg_<var-snap-lxd-common-lxd>" profile="wg" 
name="/dev/pts/2" pid=97928 comm="wg" requested_mask="wr" denied_mask="wr" 
fsuid=1001000 ouid=1001000
[Tue Jan  6 17:18:10 2026] audit: type=1400 audit(1767719889.884:801): 
apparmor="DENIED" operation="open" class="file" 
namespace="root//lxd-q-wg_<var-snap-lxd-common-lxd>" profile="wg" 
name="/apparmor/.null" pid=97928 comm="wg" requested_mask="wr" denied_mask="wr" 
fsuid=1001000 ouid=0
[Tue Jan  6 17:18:10 2026] audit: type=1400 audit(1767719889.884:802): 
apparmor="DENIED" operation="file_inherit" class="file" 
namespace="root//lxd-q-wg_<var-snap-lxd-common-lxd>" profile="wg" 
name="/dev/pts/2" pid=97928 comm="wg" requested_mask="wr" denied_mask="wr" 
fsuid=1001000 ouid=1001000
[Tue Jan  6 17:18:10 2026] audit: type=1400 audit(1767719889.884:803): 
apparmor="DENIED" operation="file_inherit" class="file" 
namespace="root//lxd-q-wg_<var-snap-lxd-common-lxd>" profile="wg" 
name="/dev/pts/2" pid=97928 comm="wg" requested_mask="wr" denied_mask="wr" 
fsuid=1001000 ouid=1001000

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2136094

Title:
  wg genkey generate empty key through vscode console

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2136094/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to