Hello,

Please find attached some more information (I anonymized the server name
with XXXXXXXXX).

apt remove haproxy -y
apt autoremove -y
apt install haproxy -y
systemctl status haproxy
systemctl restart haproxy
root@XXXXXXXXX:~# systemctl status haproxy
● haproxy.service - HAProxy Load Balancer
     Loaded: loaded (/usr/lib/systemd/system/haproxy.service; enabled; preset: 
enabled)
     Active: activating (start) since Tue 2026-08-18 06:55:09 UTC; 44s ago
        Job: 107193
 Invocation: ff198816afe24713845a144e18fa8e19
       Docs: man:haproxy(1)
             file:/usr/share/doc/haproxy/configuration.txt.gz
   Main PID: 30681 (haproxy)
      Tasks: 5 (limit: 10514)
     Memory: 44M (peak: 44.4M)
        CPU: 104ms
     CGroup: /system.slice/haproxy.service
             ├─30681 /usr/sbin/haproxy -Ws -f /etc/haproxy/haproxy.cfg -p 
/run/haproxy.pid -S /run/haproxy-master.sock
             └─30683 /usr/sbin/haproxy -Ws -f /etc/haproxy/haproxy.cfg -p 
/run/haproxy.pid -S /run/haproxy-master.sock

Aug 18 06:55:09 XXXXXXXXX systemd[1]: haproxy.service: Scheduled restart job, 
restart counter is at 1.
Aug 18 06:55:09 XXXXXXXXX systemd[1]: Starting haproxy.service - HAProxy Load 
Balancer...
Aug 18 06:55:09 XXXXXXXXX haproxy[30681]: [NOTICE]   (30681) : Initializing new 
worker (30683)
Aug 18 06:55:09 XXXXXXXXX haproxy[30681]: [NOTICE]   (30681) : Loading success.


root@XXXXXXXXX:/etc/apparmor.d# cat usr.sbin.haproxy
# Last Modified: Thu Jul 23 08:54:53 2026
abi <abi/5.0>,

include <tunables/global>

/usr/sbin/haproxy flags=(complain) {
  include <abstractions/base>

  /usr/sbin/haproxy mr,

}


root@XXXXXXXXX:~# journalctl -k | grep -i apparmor

Aug 18 06:52:58 XXXXXXXXX kernel: audit: type=1400 audit(1787035978.073:251): 
apparmor="STATUS" operation="profile_replace" info="same as current profile, 
skipping" profile="unconfined" name="rsyslogd" pid=30505 comm="apparmor_parser"
Aug 18 06:53:27 XXXXXXXXX kernel: audit: type=1400 audit(1787036007.088:252): 
apparmor="STATUS" operation="profile_load" profile="unconfined" 
name="/usr/sbin/haproxy" pid=30605 comm="apparmor_parser"
Aug 18 06:53:39 XXXXXXXXX kernel: audit: type=1400 audit(1787036019.212:253): 
apparmor="ALLOWED" operation="create" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30640 comm="haproxy" family="inet" 
sock_type="stream" protocol=0 requested="create" denied="create"
Aug 18 06:53:39 XXXXXXXXX kernel: audit: type=1400 audit(1787036019.212:254): 
apparmor="ALLOWED" operation="getsockopt" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30640 comm="haproxy" family="inet" 
sock_type="stream" protocol=6 requested="getopt" denied="getopt"
Aug 18 06:53:39 XXXXXXXXX kernel: audit: type=1400 audit(1787036019.212:255): 
apparmor="ALLOWED" operation="create" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30640 comm="haproxy" family="inet6" 
sock_type="stream" protocol=0 requested="create" denied="create"
Aug 18 06:53:39 XXXXXXXXX kernel: audit: type=1400 audit(1787036019.212:256): 
apparmor="ALLOWED" operation="getsockopt" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30640 comm="haproxy" family="inet6" 
sock_type="stream" protocol=6 requested="getopt" denied="getopt"
Aug 18 06:53:39 XXXXXXXXX kernel: audit: type=1400 audit(1787036019.212:257): 
apparmor="ALLOWED" operation="getsockopt" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30640 comm="haproxy" family="inet6" 
sock_type="stream" protocol=6 requested="getopt" denied="getopt"
Aug 18 06:53:39 XXXXXXXXX kernel: audit: type=1400 audit(1787036019.212:258): 
apparmor="ALLOWED" operation="create" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30640 comm="haproxy" family="inet" 
sock_type="stream" protocol=262 requested="create" denied="create"
Aug 18 06:53:39 XXXXXXXXX kernel: audit: type=1400 audit(1787036019.212:259): 
apparmor="ALLOWED" operation="getsockopt" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30640 comm="haproxy" family="inet" 
sock_type="stream" protocol=262 requested="getopt" denied="getopt"
Aug 18 06:53:39 XXXXXXXXX kernel: audit: type=1400 audit(1787036019.212:260): 
apparmor="ALLOWED" operation="create" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30640 comm="haproxy" family="inet6" 
sock_type="stream" protocol=262 requested="create" denied="create"
Aug 18 06:53:39 XXXXXXXXX kernel: audit: type=1400 audit(1787036019.212:261): 
apparmor="ALLOWED" operation="getsockopt" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30640 comm="haproxy" family="inet6" 
sock_type="stream" protocol=262 requested="getopt" denied="getopt"
Aug 18 06:53:39 XXXXXXXXX kernel: audit: type=1400 audit(1787036019.212:262): 
apparmor="ALLOWED" operation="create" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30640 comm="haproxy" family="inet" 
sock_type="dgram" protocol=0 requested="create" denied="create"
Aug 18 06:55:09 XXXXXXXXX kernel: audit: type=1400 audit(1787036109.300:971): 
apparmor="ALLOWED" operation="sendmsg" class="file" info="Failed name lookup - 
disconnected path" error=-13 profile="/usr/sbin/haproxy" 
name="run/systemd/notify" pid=30640 comm="haproxy" requested_mask="w" 
denied_mask="w" fsuid=0 ouid=0
Aug 18 06:55:09 XXXXXXXXX kernel: audit: type=1400 audit(1787036109.300:972): 
apparmor="ALLOWED" operation="capable" class="cap" profile="/usr/sbin/haproxy" 
pid=30640 comm="haproxy" capability=5  capname="kill"
Aug 18 06:55:09 XXXXXXXXX kernel: audit: type=1400 audit(1787036109.592:973): 
apparmor="ALLOWED" operation="create" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30681 comm="haproxy" family="inet" 
sock_type="stream" protocol=0 requested="create" denied="create"
Aug 18 06:55:09 XXXXXXXXX kernel: audit: type=1400 audit(1787036109.592:974): 
apparmor="ALLOWED" operation="getsockopt" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30681 comm="haproxy" family="inet" 
sock_type="stream" protocol=6 requested="getopt" denied="getopt"
Aug 18 06:55:09 XXXXXXXXX kernel: audit: type=1400 audit(1787036109.592:975): 
apparmor="ALLOWED" operation="create" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30681 comm="haproxy" family="inet6" 
sock_type="stream" protocol=0 requested="create" denied="create"
Aug 18 06:55:09 XXXXXXXXX kernel: audit: type=1400 audit(1787036109.592:976): 
apparmor="ALLOWED" operation="getsockopt" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30681 comm="haproxy" family="inet6" 
sock_type="stream" protocol=6 requested="getopt" denied="getopt"
Aug 18 06:55:09 XXXXXXXXX kernel: audit: type=1400 audit(1787036109.592:977): 
apparmor="ALLOWED" operation="getsockopt" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30681 comm="haproxy" family="inet6" 
sock_type="stream" protocol=6 requested="getopt" denied="getopt"
Aug 18 06:55:09 XXXXXXXXX kernel: audit: type=1400 audit(1787036109.592:978): 
apparmor="ALLOWED" operation="create" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30681 comm="haproxy" family="inet" 
sock_type="stream" protocol=262 requested="create" denied="create"
Aug 18 06:55:09 XXXXXXXXX kernel: audit: type=1400 audit(1787036109.592:979): 
apparmor="ALLOWED" operation="getsockopt" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30681 comm="haproxy" family="inet" 
sock_type="stream" protocol=262 requested="getopt" denied="getopt"
Aug 18 06:55:09 XXXXXXXXX kernel: audit: type=1400 audit(1787036109.592:980): 
apparmor="ALLOWED" operation="create" class="net" info="failed af match" 
error=-13 profile="/usr/sbin/haproxy" pid=30681 comm="haproxy" family="inet6" 
sock_type="stream" protocol=262 requested="create" denied="create"

root@XXXXXXXXX:~# aa-status
apparmor module is loaded.
188 profiles are loaded.
110 profiles are in enforce mode.
   /usr/bin/fail2ban-server
   /usr/bin/glpi-agent
   /usr/bin/man
   /usr/lib/snapd/snap-confine
   /usr/sbin/chronyd
   /usr/sbin/sssd
   :glycin:bwrap
   :glycin:loaders
   alsamixer
   babeld
   bfdd
   bgpd
   bwrap
   dig
   dnstracer
   eigrpd
   fabricd
   fusermount3
   gs
   hostname
   hwctl
   hwctl//kmod
   iotop-c
   ipa_verify
   irssi
   isisd
   john
   ldpd
   linux-boot-prober
   locale
   locale//compressor
   lsb_release
   lsblk
   lsusb
   man_filter
   man_groff
   mbsync
   mosquitto
   nc.openbsd
   nhrpd
   notify-send
   nslookup
   nvidia_modprobe
   nvidia_modprobe//kmod
   os-prober
   ospf6d
   ospfd
   pathd
   pbrd
   pim6d
   pimd
   plasmashell
   plasmashell//QtWebEngineProcess
   pollinate
   proftpd
   qpdf
   ripd
   ripngd
   rsyslogd
   sbuild
   sbuild-abort
   sbuild-adduser
   sbuild-apt
   sbuild-checkpackages
   sbuild-clean
   sbuild-createchroot
   sbuild-destroychroot
   sbuild-distupgrade
   sbuild-hold
   sbuild-shell
   sbuild-unhold
   sbuild-update
   sbuild-upgrade
   ssh-keyscan
   staticd
   systemd-detect-virt
   tc-eth0-inet-limit
   tcpdump
   tinyproxy
   tnftp
   tnftp//cmds
   tnftp//dash
   tnftp//dash//more
   transmission-cli
   transmission-daemon
   transmission-gtk
   transmission-qt
   tshark
   tshark//dumpcap
   ubuntu_pro_apt_news
   ubuntu_pro_esm_cache
   ubuntu_pro_esm_cache//apt_methods
   ubuntu_pro_esm_cache//apt_methods_gpgv
   ubuntu_pro_esm_cache//cloud_id
   ubuntu_pro_esm_cache//dpkg
   ubuntu_pro_esm_cache//ps
   ubuntu_pro_esm_cache//ubuntu_distro_info
   ubuntu_pro_esm_cache_systemctl
   ubuntu_pro_esm_cache_systemd_detect_virt
   unix-chkpwd
   unpriv_bwrap
   unprivileged_userns
   vrrpd
   wg
   wg-quick
   wg-quick//ip
   wg-quick//nft
   wg-quick//sysctl
   who
   znc
3 profiles are in complain mode.
   /usr/sbin/haproxy
   Xorg
   Xorg_wrap
0 profiles are in prompt mode.
0 profiles are in kill mode.
75 profiles are in unconfined mode.
   1password
   Discord
   MongoDB Compass
   QtWebEngineProcess
   balena-etcher
   brave
   buildah
   cam
   ch-checkns
   ch-run
   chrome
   chromium
   crun
   devhelp
   element-desktop
   epiphany
   evolution
   firefox
   flatpak
   foliate
   geary
   github-desktop
   goldendict
   kchmviewer
   keybase
   lc-compliance
   libcamerify
   linux-sandbox
   loupe
   lxc-attach
   lxc-create
   lxc-destroy
   lxc-execute
   lxc-stop
   lxc-unshare
   lxc-usernsexec
   mmdebstrap
   msedge
   notepadqq
   obsidian
   opam
   opera
   pageedit
   podman
   polypane
   privacybrowser
   qcam
   qmapshack
   qutebrowser
   rootlesskit
   rpm
   rssguard
   runc
   scide
   signal-desktop
   slack
   slirp4netns
   steam
   stress-ng
   surfshark
   systemd-coredump
   thunderbird
   toybox
   trinity
   tup
   tuxedo-control-center
   userbindmount
   uwsgi-core
   vdens
   virtiofsd
   vivaldi-bin
   vpnns
   vscode
   wike
   wpcom
12 processes have profiles defined.
10 processes are in enforce mode.
   /usr/bin/python3.14 (1125) /usr/bin/fail2ban-server
   /usr/bin/perl (1126) /usr/bin/glpi-agent
   /usr/sbin/chronyd (1111)
   /usr/sbin/chronyd (1146)
   /usr/sbin/sssd (1365)
   /usr/libexec/sssd/sssd_be (1371) /usr/sbin/sssd
   /usr/libexec/sssd/sssd_nss (1376) /usr/sbin/sssd
   /usr/libexec/sssd/sssd_pam (1377) /usr/sbin/sssd
   /usr/libexec/sssd/sssd_pac (1378) /usr/sbin/sssd
   /usr/sbin/rsyslogd (30507) rsyslogd
2 processes are in complain mode.
   /usr/sbin/haproxy (30754)
   /usr/sbin/haproxy (30756)
0 processes are in prompt mode.
0 processes are in kill mode.
0 processes are unconfined but have a profile defined.
0 processes are in mixed mode.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2162790

Title:
  Complain mode causes notify services to not start properly

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2162790/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to