Public bug reported:
I upgraded this machine from Ubuntu 24.04 LTS to Ubuntu 26.04 LTS using
`do-release-upgrade`.
After the upgrade, the graphical login no longer worked. The machine
uses MATE with LightDM. LightDM repeatedly started the greeter and then
exited with status 1, entering a restart loop.
Booting once with `apparmor=0` on the kernel command line made the
graphical environment work normally, so I investigated the AppArmor
logs.
The immediate failures were caused by `bwrap`, used by glycin while GTK
applications were loading images/icons. For example:
```
Gtk:ERROR:../../../gtk/gtkiconhelper.c:495:ensure_surface_for_gicon:
assertion failed (error == NULL):
Failed to load /usr/share/icons/mate/22x22/status/image-missing.png:
Loader process exited early with status '1'
Command:
"bwrap" "--unshare-all" ... "/usr/libexec/glycin-loaders/2+/glycin-image-rs" ...
```
At the same time the kernel log contained repeated AppArmor denials such
as:
```
apparmor="AUDIT" operation="userns_create" class="namespace"
profile="unconfined" comm="bwrap"
requested="userns_create" target="unprivileged_userns"
execpath="/usr/bin/bwrap"
apparmor="DENIED" operation="capable" class="cap"
profile="unprivileged_userns" comm="bwrap"
capability=8 capname="setpcap"
apparmor="DENIED" operation="capable" class="cap"
profile="unprivileged_userns" comm="bwrap"
capability=12 capname="net_admin"
```
I then found the following state in `/etc/apparmor.d`:
```
lrwxrwxrwx 1 root root 56 Apr 23 22:38 \
/etc/apparmor.d/bwrap-userns-restrict \
-> /usr/share/apparmor/extra-profiles/bwrap-userns-restrict
-rw-r--r-- 1 root root 3028 Jul 13 19:43 \
/etc/apparmor.d/bwrap-userns-restrict.dpkg-new
-rw-r--r-- 1 root root 3744 Jul 13 19:43 \
/etc/apparmor.d/glycin.bwrap
-rw-r--r-- 1 root root 882 Jul 13 19:43 \
/etc/apparmor.d/glycin.loaders
```
The symlink target
```
/usr/share/apparmor/extra-profiles/bwrap-userns-restrict
```
no longer existed, so `/etc/apparmor.d/bwrap-userns-restrict` was a
dangling symlink.
At the same time, the new profile which should apparently have occupied
that pathname had been left as:
```
/etc/apparmor.d/bwrap-userns-restrict.dpkg-new
```
Thus the specific bwrap profile was not loaded, and bwrap instead ended
up under the generic `unprivileged_userns` profile, where the operations
required by the glycin sandbox were denied.
I removed the dangling symlink and reinstalled the `apparmor` package.
Afterwards the layout became:
```
-rw-r--r-- 1 root root 3028 Jul 13 19:43 \
/etc/apparmor.d/bwrap-userns-restrict
-rw-r--r-- 1 root root 3744 Jul 13 19:43 \
/etc/apparmor.d/glycin.bwrap
-rw-r--r-- 1 root root 882 Jul 13 19:43 \
/etc/apparmor.d/glycin.loaders
```
I then rebooted normally, without `apparmor=0`. The graphical login and
MATE desktop worked normally again.
So the failure chain was approximately:
```
stale/dangling bwrap-userns-restrict symlink
->
new profile left as .dpkg-new
->
bwrap profile not loaded
->
bwrap falls under unprivileged_userns
->
AppArmor denies operations needed by bwrap
->
glycin image loaders fail
->
GTK cannot load images/icons
->
MATE/LightDM graphical login fails
```
This has a fairly severe impact because after an otherwise successful
LTS-to-LTS upgrade the machine appears unable to start its graphical
desktop.
One potentially relevant detail is that before the upgrade
`/etc/apparmor.d/bwrap-userns-restrict` already existed as the symlink
shown above. I do not know at this point whether that symlink was
originally created by an older Ubuntu package/configuration or as a
local configuration change.
I had previously done some partial package upgrades on this machine for
unrelated reasons. However, as far as AppArmor itself is concerned, the
dpkg logs show that it was still entirely on the Ubuntu 24.04 series
immediately before the release upgrade:
```
apparmor:
4.0.1really4.0.1-0ubuntu0.24.04.7
->
4.0.1really4.0.1-0ubuntu0.24.04.8
```
The actual transition to the Ubuntu 26.04 AppArmor package happened
during the release upgrade:
```
apparmor:
4.0.1really4.0.1-0ubuntu0.24.04.8
->
5.0.2-0ubuntu1~26.04.1
```
The same transition occurred for `apparmor-profiles`, `apparmor-utils`,
`libapparmor1`, and the Python AppArmor packages.
It may therefore be worth checking whether the 24.04 -> 26.04
package/release upgrade should detect and migrate this historical
`bwrap-userns-restrict` symlink, rather than preserving it while
installing the new profile as `.dpkg-new`.
Workaround:
```
rm /etc/apparmor.d/bwrap-userns-restrict
apt install --reinstall apparmor
reboot
```
After that, AppArmor remains enabled and the graphical desktop works
normally.
ProblemType: Bug
DistroRelease: Ubuntu 26.04
Package: apparmor 5.0.2-0ubuntu1~26.04.1
ProcVersionSignature: Ubuntu 7.0.0-34.34-generic 7.0.14
Uname: Linux 7.0.0-34-generic x86_64
ApportVersion: 2.34.1-0ubuntu0.1
Architecture: amd64
CasperMD5CheckResult: unknown
CurrentDesktop: MATE
Date: Thu Oct 1 12:25:39 2026
ProcKernelCmdline: BOOT_IMAGE=/@ubuntu2604/boot/vmlinuz-7.0.0-34-generic
root=UUID=5555f991-db31-45a1-b146-7e0f386aa59e ro rootflags=subvol=@ubuntu2604
resume=UUID=512604d0-a7bb-46c3-b592-51fd2198df9f
SourcePackage: apparmor
UpgradeStatus: Upgraded to resolute on 2026-09-30 (1 days ago)
** Affects: apparmor (Ubuntu)
Importance: Undecided
Status: New
** Tags: amd64 apport-bug resolute
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169135
Title:
24.04 → 26.04 upgrade can leave stale bwrap-userns-restrict symlink,
breaking graphical login
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2169135/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs