I migrated, according to the lxd-to-incus script, sucessfully to incus. When executing incus list I see all my container and VMs. But none of them will start. I don’t get any error messages when executing incus start u1. Also --show-log doesn’t show anything. The logs below are from /var/log/incus/u1.
$ cat u1/console.log
Failed to drop FS_IMMUTABLE_FL from /sys/firmware/efi/efivars/LoaderRandomSeed-xxx, ignoring: Permission denied
Failed to reduce access mode of /sys/firmware/efi/efivars/LoaderRandomSeed-xxx, ignoring: Permission denied
Failed to drop FS_IMMUTABLE_FL from /sys/firmware/efi/efivars/LoaderSystemToken-xxx, ignoring: Permission denied
Failed to reduce access mode of /sys/firmware/efi/efivars/LoaderSystemToken-xxx, ignoring: Permission denied
Failed to read LoaderRandomSeed EFI variable, ignoring: Permission denied
Welcome to Debian GNU/Linux 12 (bookworm)!
Failed to allocate notification socket: Permission denied
[!!!!!!] Failed to start up manager.
Exiting PID 1...
$ cat u1/lxc.log
lxc 20240224220931.810 ERROR af_unix - ../src/lxc/af_unix.c:lxc_abstract_unix_recv_fds_iov:218 - Connection reset by peer - Failed to receive response
lxc 20240224220931.810 ERROR commands - ../src/lxc/commands.c:lxc_cmd_rsp_recv_fds:128 - Failed to receive file descriptors for command "get_init_pid"
$ cat /etc/os-release
PRETTY_NAME="Debian GNU/Linux 12 (bookworm)"
$ uname -a
Linux vh 5.15.126-1-pve #1 SMP PVE 5.15.126-1 (2023-10-03T17:24Z) x86_64 GNU/Linux
$ dmesg
[35195.902029] vmbr0: port 2(veth132f931b) entered blocking state
[35195.902036] vmbr0: port 2(veth132f931b) entered disabled state
[35195.902075] device veth132f931b entered promiscuous mode
[35195.953412] audit: type=1400 audit(1708849699.241:61): apparmor="STATUS" operation="profile_load" profile="unconfined" name="incus-cmk_</var/lib/incus>" pid=2034074 comm="apparmor_parser"
[35196.100061] physeqJ3Ov: renamed from vethee4b904f
[35196.120683] eth0: renamed from physeqJ3Ov
[35196.156748] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready
[35196.156852] vmbr0: port 2(veth132f931b) entered blocking state
[35196.156866] vmbr0: port 2(veth132f931b) entered forwarding state
[35196.384204] audit: type=1400 audit(1708849699.673:62): apparmor="DENIED" operation="create" info="failed type and protocol match" error=-13 profile="incus-cmk_</var/lib/incus>" pid=2034212 comm="systemd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
[35196.444232] physeqJ3Ov: renamed from eth0
[35196.480163] vmbr0: port 2(veth132f931b) entered disabled state
[35196.489884] vethee4b904f: renamed from physeqJ3Ov
[35196.550168] device veth132f931b left promiscuous mode
[35196.550191] vmbr0: port 2(veth132f931b) entered disabled state
[35197.353330] audit: type=1400 audit(1708849700.641:63): apparmor="STATUS" operation="profile_remove" profile="unconfined" name="incus-cmk_</var/lib/incus>" pid=2034389 comm="apparmor_parser"
The installation was made with a Proxmox installation media and still uses the kernel from the project. Proxmox supports Debian with a zfs root, which Debian doesn`t. Directly after installation everything Proxmox related was removed, except the kernel plus necessary packages, and instead lxd via snap installed. It was running fine with lxd for multiple years.
ufw is inactive, iptables and nft show no configured rules. I used vmbr0 and vmbr1 in lxd. I assume lxd-to-incus converted this to incus configuration.
I removed incus completely, also all remaining zfs volumes remaining from lxd-to-incus conversion. Then executed incus admin init and started with a blank incus installation. Still the same problem:
[...]
Failed to allocate notification socket: Permission denied
[!!!!!!] Failed to start up manager.