Public bug reported:
On Ubuntu 26.04, every execution of dig triggers
an AppArmor denial.
Kernel log:
apparmor="DENIED"
operation="open"
profile="dig"
requested_mask="wr"
name="/proc/<pid>/task/<tid>/comm"
strace shows dig attempting:
openat("/proc/self/task/<tid>/comm", O_RDWR)
DNS queries succeed, but audit logs are generated
for every execution.
Replacing dig with kdig avoids the issue.
This appears to be a mismatch between the dig
AppArmor profile and current dig runtime behavior.
ProblemType: Bug
DistroRelease: Ubuntu 26.04
Package: apparmor 5.0.0~beta1-0ubuntu7
ProcVersionSignature: Ubuntu 7.0.0-27.27-generic 7.0.6
Uname: Linux 7.0.0-27-generic x86_64
ApportVersion: 2.34.0-0ubuntu2
Architecture: amd64
CasperMD5CheckResult: unknown
CloudArchitecture: x86_64
CloudBuildName: server
CloudID: vmware
CloudName: vmware
CloudPlatform: vmware
CloudSerial: 20260627
CloudSubPlatform: guestinfo (guestinfo.metadata)
Date: Wed Jul 15 16:40:17 2026
ProcEnviron:
LANG=C.UTF-8
PATH=(custom, no user)
SHELL=/bin/bash
TERM=xterm-256color
ProcKernelCmdline: BOOT_IMAGE=/vmlinuz-7.0.0-27-generic
root=LABEL=cloudimg-rootfs ro console=tty1 console=ttyS0
SourcePackage: apparmor
Syslog: 2026-07-14T12:04:59.694370+09:00 pirika dbus-daemon[1480]: [system]
AppArmor D-Bus mediation is enabled
UpgradeStatus: No upgrade log present (probably fresh install)
** Affects: apparmor (Ubuntu)
Importance: Undecided
Status: New
** Tags: amd64 apport-bug cloud-image resolute
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2160686
Title:
dig AppArmor profile denies access to /proc/self/task/*/comm
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2160686/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs