I just tested 5.21/stable and couldn't reproduce as it properly disable the /proc/sys/kernel/apparmor_restrict_unprivileged_userns and /proc/sys/kernel/apparmor_restrict_unprivileged_unconfined that would otherwise have caused those denials.
Marking as incomplete until you can reproduce with 5.21/stable (5.20 being EOL). Thanks
I just tested 5.21/stable and couldn't reproduce as it properly disable the /proc/sys/ kernel/ apparmor_ restrict_ unprivileged_ userns and /proc/sys/ kernel/ apparmor_ restrict_ unprivileged_ unconfined that would otherwise have caused those denials.
Marking as incomplete until you can reproduce with 5.21/stable (5.20 being EOL). Thanks