Public bug reported:

On Ubuntu 26.04, every execution of dig triggers
an AppArmor denial.

Kernel log:

apparmor="DENIED"
operation="open"
profile="dig"
requested_mask="wr"
name="/proc/<pid>/task/<tid>/comm"

strace shows dig attempting:

openat("/proc/self/task/<tid>/comm", O_RDWR)

DNS queries succeed, but audit logs are generated
for every execution.

Replacing dig with kdig avoids the issue.

This appears to be a mismatch between the dig
AppArmor profile and current dig runtime behavior.

ProblemType: Bug
DistroRelease: Ubuntu 26.04
Package: apparmor 5.0.0~beta1-0ubuntu7
ProcVersionSignature: Ubuntu 7.0.0-27.27-generic 7.0.6
Uname: Linux 7.0.0-27-generic x86_64
ApportVersion: 2.34.0-0ubuntu2
Architecture: amd64
CasperMD5CheckResult: unknown
CloudArchitecture: x86_64
CloudBuildName: server
CloudID: vmware
CloudName: vmware
CloudPlatform: vmware
CloudSerial: 20260627
CloudSubPlatform: guestinfo (guestinfo.metadata)
Date: Wed Jul 15 16:40:17 2026
ProcEnviron:
 LANG=C.UTF-8
 PATH=(custom, no user)
 SHELL=/bin/bash
 TERM=xterm-256color
ProcKernelCmdline: BOOT_IMAGE=/vmlinuz-7.0.0-27-generic 
root=LABEL=cloudimg-rootfs ro console=tty1 console=ttyS0
SourcePackage: apparmor
Syslog: 2026-07-14T12:04:59.694370+09:00 pirika dbus-daemon[1480]: [system] 
AppArmor D-Bus mediation is enabled
UpgradeStatus: No upgrade log present (probably fresh install)

** Affects: apparmor (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: amd64 apport-bug cloud-image resolute

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2160686

Title:
  dig AppArmor profile denies access to /proc/self/task/*/comm

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2160686/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to