I updated my Arch Linux container, rebooted it and systemd-networkd cannot start anymore.
[root@twt ~]# systemctl --version
systemd 247 (247.1-1-arch)
+PAM +AUDIT -SELINUX -IMA -APPARMOR +SMACK -SYSVINIT +UTMP +LIBCRYPTSETUP +GCRYPT +GNUTLS +ACL +XZ +LZ4 +ZSTD +SECCOMP +BLKID +ELFUTILS +KMOD +IDN2 -IDN +PCRE2 default-hierarchy=hybrid
[root@twt ~]# systemctl status systemd-networkd
● systemd-networkd.service - Network Service
Loaded: loaded (/usr/lib/systemd/system/systemd-networkd.service; enabled; vendor preset: enabled)
Drop-In: /etc/systemd/system/systemd-networkd.service.d
└─lxc.conf
Active: failed (Result: exit-code) since Sat 2020-12-05 06:27:09 UTC; 14min ago
TriggeredBy: ● systemd-networkd.socket
Docs: man:systemd-networkd.service(8)
Process: 62 ExecStart=/usr/lib/systemd/systemd-networkd (code=exited, status=226/NAMESPACE)
Main PID: 62 (code=exited, status=226/NAMESPACE)
Dec 05 06:27:09 twt systemd[1]: systemd-networkd.service: Main process exited, code=exited, status=226/NAMESPACE
Dec 05 06:27:09 twt systemd[55]: systemd-networkd.service: Failed to set up mount namespacing: /run/systemd/unit-root/proc: Permission denied
Dec 05 06:27:09 twt systemd[55]: systemd-networkd.service: Failed at step NAMESPACE spawning /usr/lib/systemd/systemd-networkd: Permission denied
Dec 05 06:27:09 twt systemd[1]: systemd-networkd.service: Main process exited, code=exited, status=226/NAMESPACE
Dec 05 07:27:09 lxd00 audit[19428]: AVC apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19428 comm="(resolved)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 audit[19423]: AVC apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19423 comm="(resolved)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 audit[19420]: AVC apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19420 comm="(d-logind)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 audit[19411]: AVC apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19411 comm="(resolved)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 audit[19407]: AVC apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19407 comm="(d-logind)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 audit[19403]: AVC apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19403 comm="(resolved)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 audit[19395]: AVC apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19395 comm="(d-logind)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 kernel: audit: type=1400 audit(1607149629.774:72): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19379 comm="(resolved)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 audit[19379]: AVC apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19379 comm="(resolved)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 kernel: audit: type=1400 audit(1607149629.694:71): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19384 comm="(d-logind)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 audit[19384]: AVC apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19384 comm="(d-logind)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 kernel: audit: type=1400 audit(1607149629.578:70): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19370 comm="(networkd)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 audit[19370]: AVC apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19370 comm="(networkd)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 kernel: audit: type=1400 audit(1607149629.522:69): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19365 comm="(d-logind)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 audit[19365]: AVC apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19365 comm="(d-logind)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 kernel: audit: type=1400 audit(1607149629.366:68): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19361 comm="(networkd)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 audit[19361]: AVC apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19361 comm="(networkd)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 kernel: audit: type=1400 audit(1607149629.334:67): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19359 comm="(networkd)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 audit[19359]: AVC apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19359 comm="(networkd)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 kernel: audit: type=1400 audit(1607149629.270:66): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19358 comm="(networkd)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 audit[19358]: AVC apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19358 comm="(networkd)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 kernel: audit: type=1400 audit(1607149629.242:65): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19357 comm="(networkd)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Dec 05 07:27:09 lxd00 audit[19357]: AVC apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="lxd-twt_</var/snap/lxd/common/lxd>" name="/run/systemd/unit-root/proc/" pid=19357 comm="(networkd)" fstype="proc" srcname="proc" flags="rw, nosuid, nodev, noexec"
Seems related to AppArmor profile.
Is it a know issue?