root@lp1905245-f:~# uname -a
Linux lp1905245-f 5.8.0-36-generic #40~20.04.1-Ubuntu SMP Wed Jan 6 10:15:55 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux
root@lp1905245-f:~# dpkg -l systemd|grep systemd
ii systemd 245.4-4ubuntu3.3 amd64 system and service manager
root@lp1905245-f:~# systemctl show -p CapabilityBoundingSet apparmor
Failed to parse bus message: Invalid argument
root@lp1905245-f:~# echo $?
1
focal container repro:
root@lp1905245-f:~# lxc shell focal
root@focal:~# dpkg -l systemd|grep systemd
ii systemd 245.4-4ubuntu3.3 amd64 system and service manager
root@focal:~# systemctl show -p CapabilityBoundingSet apparmor
Failed to parse bus message: Invalid argument
root@focal:~# echo $?
1
bionic container repro:
root@lp1905245-f:~# lxc shell bionic
root@bionic:~# dpkg -l systemd|grep systemd
ii systemd 237-3ubuntu10.43 amd64 system and service manager
root@bionic:~# systemctl show -p CapabilityBoundingSet apparmor
Failed to parse bus message: Invalid argument
root@bionic:~# echo $?
1
focal host verification:
root@lp1905245-f:~# dpkg -l systemd|grep systemd
ii systemd 245.4-4ubuntu3.4 amd64 system and service manager
root@lp1905245-f:~# systemctl show -p CapabilityBoundingSet apparmor
CapabilityBoundingSet=cap_chown cap_dac_override cap_dac_read_search cap_fowner cap_fsetid cap_kill cap_setgid cap_setuid cap_setpcap cap_linux_immutable cap_net_bind_service cap_net_broadcast cap_net_admin cap_net_raw cap_ipc_lock cap_ipc_owner cap_sys_module cap_sys_>
root@lp1905245-f:~# echo $?
0
focal container verification:
root@focal:~# dpkg -l systemd|grep systemd
ii systemd 245.4-4ubuntu3.4 amd64 system and service manager
root@focal:~# systemctl show -p CapabilityBoundingSet apparmor
CapabilityBoundingSet=cap_chown cap_dac_override cap_dac_read_search cap_fowner cap_fsetid cap_kill cap_setgid cap_setuid cap_setpcap cap_linux_immutable cap_net_bind_service cap_net_broadcast cap_net_admin cap_net_raw cap_ipc_lock cap_ipc_owner cap_sys_module cap_sys_>
root@focal:~# echo $?
0
bionic container verification:
root@bionic:~# dpkg -l systemd|grep systemd
ii systemd 237-3ubuntu10.44 amd64 system and service manager
root@bionic:~# systemctl show -p CapabilityBoundingSet apparmor
CapabilityBoundingSet=cap_chown cap_dac_override cap_dac_read_search cap_fowner cap_fsetid cap_kill cap_setgid cap_setuid cap_setpcap cap_linux_immutable cap_net_bind_service cap_net_broadcast cap_net_admin cap_net_raw cap_ipc_lock cap_ipc_owner cap_sys_module cap_sys_r
root@bionic:~# echo $?
0
focal host reproduction:
root@lp1905245-f:~# uname -a ingSet apparmor
Linux lp1905245-f 5.8.0-36-generic #40~20.04.1-Ubuntu SMP Wed Jan 6 10:15:55 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux
root@lp1905245-f:~# dpkg -l systemd|grep systemd
ii systemd 245.4-4ubuntu3.3 amd64 system and service manager
root@lp1905245-f:~# systemctl show -p CapabilityBound
Failed to parse bus message: Invalid argument
root@lp1905245-f:~# echo $?
1
focal container repro:
root@lp1905245-f:~# lxc shell focal ingSet apparmor
root@focal:~# dpkg -l systemd|grep systemd
ii systemd 245.4-4ubuntu3.3 amd64 system and service manager
root@focal:~# systemctl show -p CapabilityBound
Failed to parse bus message: Invalid argument
root@focal:~# echo $?
1
bionic container repro:
root@lp1905245-f:~# lxc shell bionic ingSet apparmor
root@bionic:~# dpkg -l systemd|grep systemd
ii systemd 237-3ubuntu10.43 amd64 system and service manager
root@bionic:~# systemctl show -p CapabilityBound
Failed to parse bus message: Invalid argument
root@bionic:~# echo $?
1
focal host verification:
root@lp1905245-f:~# dpkg -l systemd|grep systemd ingSet apparmor ingSet= cap_chown cap_dac_override cap_dac_read_search cap_fowner cap_fsetid cap_kill cap_setgid cap_setuid cap_setpcap cap_linux_immutable cap_net_ bind_service cap_net_broadcast cap_net_admin cap_net_raw cap_ipc_lock cap_ipc_owner cap_sys_module cap_sys_>
ii systemd 245.4-4ubuntu3.4 amd64 system and service manager
root@lp1905245-f:~# systemctl show -p CapabilityBound
CapabilityBound
root@lp1905245-f:~# echo $?
0
focal container verification:
root@focal:~# dpkg -l systemd|grep systemd ingSet apparmor ingSet= cap_chown cap_dac_override cap_dac_read_search cap_fowner cap_fsetid cap_kill cap_setgid cap_setuid cap_setpcap cap_linux_immutable cap_net_ bind_service cap_net_broadcast cap_net_admin cap_net_raw cap_ipc_lock cap_ipc_owner cap_sys_module cap_sys_>
ii systemd 245.4-4ubuntu3.4 amd64 system and service manager
root@focal:~# systemctl show -p CapabilityBound
CapabilityBound
root@focal:~# echo $?
0
bionic container verification:
root@bionic:~# dpkg -l systemd|grep systemd ingSet apparmor ingSet= cap_chown cap_dac_override cap_dac_read_search cap_fowner cap_fsetid cap_kill cap_setgid cap_setuid cap_setpcap cap_linux_immutable cap_net_ bind_service cap_net_broadcast cap_net_admin cap_net_raw cap_ipc_lock cap_ipc_owner cap_sys_module cap_sys_r
ii systemd 237-3ubuntu10.44 amd64 system and service manager
root@bionic:~# systemctl show -p CapabilityBound
CapabilityBound
root@bionic:~# echo $?
0