With the new docker 18.09.9 snap on Ubuntu 20.04, I’m seeing Docker containers eventually stop working (seemingly at random times) with the following AppArmor error in dmesg
:
[82109.669473] kauditd_printk_skb: 2 callbacks suppressed
[82109.669475] audit: type=1400 audit(1574117861.497:670): apparmor="DENIED" operation="open" profile="snap.docker.docker" name="/sys/kernel/mm/transparent_hugepage/hpage_pmd_size" pid=277187 comm="docker" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[82109.845504] audit: type=1400 audit(1574117861.673:671): apparmor="DENIED" operation="open" profile="snap.docker.docker" name="/sys/kernel/mm/transparent_hugepage/hpage_pmd_size" pid=277218 comm="docker" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[82110.106467] audit: type=1400 audit(1574117861.934:672): apparmor="DENIED" operation="open" profile="snap.docker.docker" name="/sys/kernel/mm/transparent_hugepage/hpage_pmd_size" pid=277249 comm="docker" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[82110.383435] audit: type=1400 audit(1574117862.211:673): apparmor="DENIED" operation="open" profile="snap.docker.docker" name="/sys/kernel/mm/transparent_hugepage/hpage_pmd_size" pid=277279 comm="docker" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[82110.498594] audit: type=1400 audit(1574117862.326:674): apparmor="DENIED" operation="open" profile="snap.docker.docker" name="/sys/kernel/mm/transparent_hugepage/hpage_pmd_size" pid=277309 comm="docker" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[82110.646808] audit: type=1400 audit(1574117862.475:675): apparmor="DENIED" operation="open" profile="snap.docker.docker" name="/sys/kernel/mm/transparent_hugepage/hpage_pmd_size" pid=277339 comm="docker" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[82110.738045] audit: type=1400 audit(1574117862.566:676): apparmor="DENIED" operation="open" profile="snap.docker.docker" name="/sys/kernel/mm/transparent_hugepage/hpage_pmd_size" pid=277370 comm="docker" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[82110.842200] audit: type=1400 audit(1574117862.670:677): apparmor="DENIED" operation="open" profile="snap.docker.docker" name="/sys/kernel/mm/transparent_hugepage/hpage_pmd_size" pid=277401 comm="docker" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[82110.928289] audit: type=1400 audit(1574117862.756:678): apparmor="DENIED" operation="open" profile="snap.docker.docker" name="/sys/kernel/mm/transparent_hugepage/hpage_pmd_size" pid=277430 comm="docker" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[82111.025835] audit: type=1400 audit(1574117862.854:679): apparmor="DENIED" operation="open" profile="snap.docker.docker" name="/sys/kernel/mm/transparent_hugepage/hpage_pmd_size" pid=277460 comm="docker" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0