Lxc-attach: lsm/lsm.c: lsm_process_label_set_at: 174 Operation not permitted - Failed to set AppArmor label "lxc-nginx-debian_</var/lib/lxc>//&:lxc-nginx-debian_<-var-lib-lxc>:unconfined

recently, after i upgrade debian buser and its kernel to 4.19.0-17-amd64, when trying to attach container with lxc-attach -n container i facing with this error:

lxc-attach: nginx-debian: lsm/lsm.c: lsm_process_label_set_at: 174 Operation not permitted - Failed to set AppArmor label "lxc-nginx-debian_</var/lib/lxc>//&:lxc-nginx-debian_<-var-lib-lxc>:unconfined"
``
lxc-version : 3.0.3
1 Like

According to Bug#990140: upgrade-reports: lxc-attach does not start with apparmor problem after ugrade to 10.10 workaround should be to boot with kernel 4.19.0-16

Also worth following the LXC bug lxc-attach: nginx-debian: lsm/lsm.c: lsm_process_label_set_at: 174 Operation not permitted - Failed to set AppArmor label "lxc-nginx-debian_</var/lib/lxc>//&:lxc-nginx-debian_<-var-lib-lxc>:unconfined" · Issue #3872 · lxc/lxc · GitHub