In the case of non-deb install (re-exec), Apparmor tunables from host /etc/apparmor.d/tunables/home.d/...
was not included in the profile for snap-update-ns. The a snapd 2.60 PR that aimed to fix home directories outside of /home/. missed adding it for the case of snap-update-ns template.
Please re-test on snapd edge tomorrow (after the nightly build that will include the fix).
It will be available in 2.63 which we are building today and releasing in approx 3 weeks.
Root cause was identified:
In the case of non-deb install (re-exec), Apparmor tunables from host /etc/apparmor. d/tunables/ home.d/ ...
was not included in the profile for snap-update-ns. The a snapd 2.60 PR that aimed to fix home directories outside of /home/. missed adding it for the case of snap-update-ns template.
(1) fixed /github. com/snapcore/ snapd/pull/ 13853
https:/
(2) and similar issue prevented in the future /github. com/snapcore/ snapd/pull/ 13854
https:/
Please re-test on snapd edge tomorrow (after the nightly build that will include the fix).
It will be available in 2.63 which we are building today and releasing in approx 3 weeks.