Hi everyone
Just migrated 2 days ago from Windows 7 to Ubuntu and bumped into AppArmor and Snap-Store problems. In the section about “denied” entries you might start seeing where problems started. I then installed the Hello-World application because I expected that would be the litmus / smoke / sanity test here. If it’s the incorrect group, let me know and I’ll figure out how to update it.
Hope the information is useful.
Note that I have GNOME, KDE, and XFCE installed. Using KDE because I found it did freeze like GNOME for me.
:~$ snap version snap 2.42.5 snapd 2.42.5 series 16 ubuntu 19.10 kernel 5.3.0-26-generic
~$ uname -r 5.3.0-26-generic
:~$ freemind cannot self-bind mount /run/snapd/ns: Permission denied :~$ snap-store cannot self-bind mount /run/snapd/ns: Permission denied ~$ hello-world internal error, please report: running “hello-world” failed: open /snap/hello-world/29/meta/snap.yaml: permission denied
~$ snap list
Name | Version | Rev | Tracking | Publisher | Notes
core | 16-2.42.5 | 8268 | stable | canonical✓ | core
core18 | 20200113 | 1650 | stable | canonical✓ | base
freemind | 1.1.0-Beta-2 | 4 | stable | jibel | -
gnome-3-28-1804 | 3.28.0-16-g27c9498.27c9498 | 110 | stable/… | canonical✓ | -
gnome-calculator | 3.34.1+git1.d34dc842 | 544 | stable/… | canonical✓ | -
gnome-characters | v3.32.1+git3.b9120df | 375 | stable/… | canonical✓ | -
gnome-logs | 3.34.0 | 81 | stable/… | canonical✓ | -
gtk-common-themes | 0.1-28-g1503258 | 1440 | stable/… | canonical✓ | -
hello-world | 6.4 | 29 | stable | canonical✓ | -
kde-frameworks-5-core18 | 5.61.0 | 32 | stable | kde✓ | -
okular | 19.04.2 | 63 | stable | kde✓ | -
remmina | v1.3.10+git1.4dc89d74 | 3810 | stable | remmina✓ | -
snap-store | 20191114.a9948d5 | 209 | stable | canonical✓ | -
wine-platform-runtime | v1.0 | 62 | stable | mmtrt | -
~$ snap changes
ID | Status | Spawn | Ready | Summary
32 | Done | yesterday at 17:48 SAST | yesterday at 17:48 SAST | Remove "freemind" snap
33 | Done | yesterday at 17:49 SAST | yesterday at 17:50 SAST | Install "snap-store" snap
34 | Done | yesterday at 17:50 SAST | yesterday at 17:50 SAST | Connect snap-store:network-manager to core:network-manager
35 | Done | yesterday at 18:00 SAST | yesterday at 18:01 SAST | Remove "snap-store" snap
36 | Done | yesterday at 18:01 SAST | yesterday at 18:01 SAST | Install "snap-store" snap
37 | Done | yesterday at 19:21 SAST | yesterday at 19:21 SAST | Install "freemind" snap
38 | Done | yesterday at 20:01 SAST | yesterday at 20:01 SAST | Remove "freemind" snap
39 | Done | yesterday at 20:02 SAST | yesterday at 20:02 SAST | Install "freemind" snap
40 | Done | today at 00:38 SAST | today at 00:38 SAST | Install "hello-world" snap
~$ snap connections freemind
Interface | Plug | Slot | Notes
cups-control | freemind:cups-control | - | -
desktop | freemind:desktop | :desktop | -
desktop-legacy | freemind:desktop-legacy | :desktop-legacy | -
home | freemind:home | :home | -
network | freemind:network | :network | -
x11 | freemind:x11 | :x11 | -
~$ snap connections snap-store
Interface | Plug | Slot | Notes
content[gnome-3-28-1804] | snap-store:gnome-3-28-1804 | gnome-3-28-1804:gnome-3-28-1804 | -
content[gtk-3-themes] | snap-store:gtk-3-themes | gtk-common-themes:gtk-3-themes | -
content[icon-themes] | snap-store:icon-themes | gtk-common-themes:icon-themes | -
content[sound-themes] | snap-store:sound-themes | gtk-common-themes:sound-themes | -
dbus | - | snap-store:snap-store | -
desktop | snap-store:desktop | :desktop | -
desktop-legacy | snap-store:desktop-legacy | :desktop-legacy | -
gsettings | snap-store:gsettings | :gsettings | -
network | snap-store:network | :network | -
network-manager | snap-store:network-manager | - | -
password-manager-service | snap-store:password-manager-service | :password-manager-service | -
snapd-control | snap-store:snapd-control | :snapd-control | -
system-observe | snap-store:system-observe | :system-observe | -
unity7 | snap-store:unity7 | :unity7 | -
upower-observe | snap-store:upower-observe | :upower-observe | -
wayland | snap-store:wayland | :wayland | -
~$ snap connections hello-world
nothing retuned
~$ dmesg | grep denied
[ 87.958581] audit: type=1400 audit(1579773001.700:77): apparmor="DENIED" operation="open" profile="/usr/bin/snap" name="/home/nicolaas/snap/gog-galaxy-wine/" pid=1694 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000
[ 87.958954] audit: type=1400 audit(1579773001.700:78): apparmor="DENIED" operation="open" profile="/usr/bin/snap" name="/home/nicolaas/snap/snap-store/" pid=1694 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000
[13223.402949] audit: type=1400 audit(1579786137.354:79): apparmor="DENIED" operation="mkdir" profile="/usr/bin/snap" name="/home/nicolaas/snap/freemind/4/" pid=20858 comm="snap" requested_mask="c" denied_mask="c" fsuid=1000 ouid=1000
[13223.417487] audit: type=1400 audit(1579786137.370:80): apparmor="DENIED" operation="ptrace" profile="/usr/bin/snap" pid=20858 comm="snap-confine" requested_mask="read" denied_mask="read" peer="unconfined"
[13275.504374] audit: type=1400 audit(1579786189.451:81): apparmor="DENIED" operation="mkdir" profile="/usr/bin/snap" name="/home/nicolaas/snap/freemind/4/" pid=20911 comm="snap" requested_mask="c" denied_mask="c" fsuid=1000 ouid=1000
[13275.512181] audit: type=1400 audit(1579786189.459:82): apparmor="DENIED" operation="ptrace" profile="/usr/bin/snap" pid=20911 comm="snap-confine" requested_mask="read" denied_mask="read" peer="unconfined"
[14842.672584] audit: type=1400 audit(1579787756.639:83): apparmor="DENIED" operation="mkdir" profile="/usr/bin/snap" name="/home/nicolaas/snap/freemind/4/" pid=21430 comm="snap" requested_mask="c" denied_mask="c" fsuid=1000 ouid=1000
[14842.678889] audit: type=1400 audit(1579787756.643:84): apparmor="DENIED" operation="ptrace" profile="/usr/bin/snap" pid=21430 comm="snap-confine" requested_mask="read" denied_mask="read" peer="unconfined"
[17367.592032] audit: type=1400 audit(1579790281.581:87): apparmor="DENIED" operation="mkdir" profile="/usr/bin/snap" name="/home/nicolaas/snap/freemind/common/" pid=24806 comm="snap" requested_mask="c" denied_mask="c" fsuid=1000 ouid=1000
[17446.369267] audit: type=1400 audit(1579790360.358:89): apparmor="DENIED" operation="mkdir" profile="/usr/bin/snap" name="/home/nicolaas/snap/freemind/common/" pid=24888 comm="snap" requested_mask="c" denied_mask="c" fsuid=1000 ouid=1000
[18083.855577] audit: type=1400 audit(1579790997.852:91): apparmor="DENIED" operation="mkdir" profile="/usr/bin/snap" name="/home/nicolaas/snap/freemind/common/" pid=3691 comm="snap" requested_mask="c" denied_mask="c" fsuid=1000 ouid=1000
[18183.009579] audit: type=1400 audit(1579791097.005:93): apparmor="DENIED" operation="mkdir" profile="/usr/bin/snap" name="/home/nicolaas/snap/freemind/common/" pid=3807 comm="snap" requested_mask="c" denied_mask="c" fsuid=1000 ouid=1000
[19245.230821] audit: type=1400 audit(1579792159.243:100): apparmor="DENIED" operation="open" profile="/usr/bin/snap" name="/var/cache/snapd/commands.db" pid=4294 comm="snap" requested_mask="c" denied_mask="c" fsuid=1000 ouid=0
[20850.499936] audit: type=1400 audit(1579793764.541:101): apparmor="DENIED" operation="open" profile="/usr/bin/snap" name="/var/cache/snapd/commands.db" pid=5996 comm="snap" requested_mask="c" denied_mask="c" fsuid=1000 ouid=0
[21006.328602] audit: type=1400 audit(1579793920.372:102): apparmor="DENIED" operation="open" profile="/usr/bin/snap" name="/var/cache/snapd/commands.db" pid=6220 comm="snap" requested_mask="c" denied_mask="c" fsuid=1000 ouid=0
[21313.168925] audit: type=1400 audit(1579794227.218:112): apparmor="DENIED" operation="mkdir" profile="/usr/bin/snap" name="/root/snap/freemind/4/" pid=6622 comm="snap" requested_mask="c" denied_mask="c" fsuid=0 ouid=0
[21374.310882] audit: type=1400 audit(1579794288.359:118): apparmor="DENIED" operation="open" profile="/usr/bin/snap" name="/var/cache/snapd/commands.db" pid=7683 comm="snap" requested_mask="c" denied_mask="c" fsuid=1000 ouid=0
[21722.433123] audit: type=1400 audit(1579794636.489:169): apparmor="DENIED" operation="open" profile="/usr/bin/snap" name="/snap/snap-store/209/meta/snap.yaml" pid=8200 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[21732.673981] audit: type=1400 audit(1579794646.733:170): apparmor="DENIED" operation="open" profile="/usr/bin/snap" name="/snap/snap-store/209/meta/snap.yaml" pid=8225 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[21761.956861] audit: type=1400 audit(1579794676.013:173): apparmor="DENIED" operation="mkdir" profile="/usr/bin/snap" name="/home/nicolaas/snap/snap-store/209/" pid=8260 comm="snap" requested_mask="c" denied_mask="c" fsuid=1000 ouid=1000
[21778.770926] audit: type=1400 audit(1579794692.830:177): apparmor="DENIED" operation="mkdir" profile="/usr/bin/snap" name="/home/nicolaas/snap/snap-store/common/" pid=8294 comm="snap" requested_mask="c" denied_mask="c" fsuid=1000 ouid=1000
[21976.460790] audit: type=1400 audit(1579794890.521:188): apparmor="DENIED" operation="open" profile="/usr/bin/snap" name="/var/cache/snapd/commands.db" pid=8527 comm="snap" requested_mask="c" denied_mask="c" fsuid=1000 ouid=0
[22250.404714] audit: type=1400 audit(1579795164.469:196): apparmor="DENIED" operation="mkdir" profile="/usr/bin/snap" name="/root/snap/snap-store/" pid=8709 comm="snap" requested_mask="c" denied_mask="c" fsuid=0 ouid=0
[22394.253326] audit: type=1400 audit(1579795308.319:281): apparmor="DENIED" operation="getattr" info="Failed name lookup - disconnected path" error=-13 profile="/usr/bin/snap" name="" pid=9245 comm="snap-confine" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
[46212.680246] audit: type=1400 audit(1579819127.061:347): apparmor="DENIED" operation="open" profile="/usr/bin/snap" name="/snap/hello-world/29/meta/snap.yaml" pid=24849 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[46233.744077] audit: type=1400 audit(1579819148.126:348): apparmor="DENIED" operation="open" profile="/usr/bin/snap" name="/snap/hello-world/29/meta/snap.yaml" pid=24872 comm="snap" requested_mask="r" denied_mask="r" fsuid=0 ouid=0
[47076.883286] audit: type=1400 audit(1579819991.277:353): apparmor="DENIED" operation="open" profile="/usr/bin/snap" name="/snap/hello-world/29/meta/snap.yaml" pid=25356 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[47112.419239] audit: type=1400 audit(1579820026.813:356): apparmor="DENIED" operation="open" profile="/usr/bin/snap" name="/snap/hello-world/29/meta/snap.yaml" pid=25437 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[48174.199061] audit: type=1400 audit(1579821088.606:357): apparmor="ALLOWED" operation="open" profile="libreoffice-soffice" name="/usr/share/kubuntu-default-settings/kf5-settings/kdeglobals" pid=25768 comm="soffice.bin" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[48174.200062] audit: type=1400 audit(1579821088.606:358): apparmor="ALLOWED" operation="open" profile="libreoffice-soffice" name="/usr/share/kubuntu-default-settings/kf5-settings/kdeglobals" pid=25768 comm="soffice.bin" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[48174.200769] audit: type=1400 audit(1579821088.606:359): apparmor="ALLOWED" operation="open" profile="libreoffice-soffice" name="/usr/share/kubuntu-default-settings/kf5-settings/kdeglobals" pid=25768 comm="soffice.bin" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[48174.212135] audit: type=1400 audit(1579821088.618:360): apparmor="ALLOWED" operation="open" profile="libreoffice-soffice" name="/proc/sys/kernel/core_pattern" pid=25768 comm="soffice.bin" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[48174.217798] audit: type=1400 audit(1579821088.626:361): apparmor="ALLOWED" operation="open" profile="libreoffice-soffice" name="/usr/share/kubuntu-default-settings/kf5-settings/kdeglobals" pid=25768 comm="soffice.bin" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[48174.218340] audit: type=1400 audit(1579821088.626:362): apparmor="ALLOWED" operation="open" profile="libreoffice-soffice" name="/usr/share/kubuntu-default-settings/kf5-settings/breezerc" pid=25768 comm="soffice.bin" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[48174.432266] audit: type=1400 audit(1579821088.838:363): apparmor="ALLOWED" operation="open" profile="libreoffice-soffice" name="/usr/share/kubuntu-default-settings/kf5-settings/kdeglobals" pid=25768 comm="soffice.bin" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[48174.432739] audit: type=1400 audit(1579821088.838:364): apparmor="ALLOWED" operation="open" profile="libreoffice-soffice" name="/home/nicolaas/.config/emaildefaults" pid=25768 comm="soffice.bin" requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000
[48175.900498] audit: type=1400 audit(1579821090.306:365): apparmor="ALLOWED" operation="open" profile="libreoffice-soffice" name="/usr/share/kubuntu-default-settings/kf5-settings/kdeglobals" pid=25780 comm="soffice.bin" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[48175.901635] audit: type=1400 audit(1579821090.306:366): apparmor="ALLOWED" operation="open" profile="libreoffice-soffice" name="/usr/share/kubuntu-default-settings/kf5-settings/kdeglobals" pid=25780 comm="soffice.bin" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
[49104.117699] audit: type=1400 audit(1579822018.538:373): apparmor="DENIED" operation="open" profile="/usr/bin/snap" name="/snap/hello-world/29/meta/snap.yaml" pid=26067 comm="snap" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0
~$ sudo systemctl status snapd
● snapd.service - Snappy daemon
Loaded: loaded (/lib/systemd/system/snapd.service; enabled; vendor preset: enabled)
Active: active (running) since Thu 2020-01-23 11:48:41 SAST; 13h ago
Main PID: 653 (snapd)
Tasks: 21 (limit: 4915)
Memory: 52.1M
CGroup: /system.slice/snapd.service
└─653 /usr/lib/snapd/snapd
Jan 23 18:18:48 HP-ProBook snapd[653]: autorefresh.go:397: auto-refresh: all snaps are up-to-date
Jan 23 19:21:46 HP-ProBook snapd[653]: api.go:952: Installing snap "freemind" revision unset
Jan 23 20:01:56 HP-ProBook runuser[13607]: pam_unix(runuser:session): session opened for user nicolaas by (uid=0)
Jan 23 20:01:56 HP-ProBook runuser[13607]: pam_unix(runuser:session): session closed for user nicolaas
Jan 23 20:02:05 HP-ProBook snapd[653]: api.go:952: Installing snap "freemind" revision unset
Jan 23 20:45:15 HP-ProBook snapd[653]: api.go:952: Installing snap "snap-store" revision unset
Jan 23 21:31:30 HP-ProBook snapd[653]: hotplug.go:199: hotplug device add event ignored, enable experimental.hotplug
Jan 23 21:32:33 HP-ProBook snapd[653]: hotplug.go:199: hotplug device add event ignored, enable experimental.hotplug
Jan 23 23:33:32 HP-ProBook snapd[653]: 2020/01/23 23:33:32 Unsolicited response received on idle HTTP channel starting with "HTTP/1.0 408 Request Time-out\r\nCache-Control:
Jan 24 00:38:31 HP-ProBook snapd[653]: api.go:952: Installing snap "hello-world" revision unset
System specifications Operating System: Kubuntu 19.10 (DISTRIB_CODENAME=eoan) KDE Plasma Version: 5.16.5 KDE Frameworks Version: 5.62.0 Qt Version: 5.12.4 Kernel Version: 5.3.0-26-generic OS Type: 64-bit Processors: 4 × Intel® Core™ i3 CPU M 350 @ 2.27GHz Memory: 7,6 GiB of RAM