#1110985 unbound: will not start with AppArmor in enforcing mode

Package:
unbound
Source:
unbound
Description:
validating, recursive, caching DNS resolver
Submitter:
Brian Turek
Date:
2025-08-15 15:11:02 UTC
Severity:
normal
#1110985#5
Date:
2025-08-13 09:00:37 UTC
From:
To:
Dear Maintainer,

   * What led up to the situation?
     I recently just upgraded my Proxmox host from Debian 12 to 13 as well as Proxmox 8 to 9. Upon reboot, my existing/working installation of unbound did not start
   * What exactly did you do (or not do) that was effective (or
     ineffective)?
     After troubleshooting, I determined something in the stock AppArmor profile was blocking unbound from starting. Putting the unbound AppArmor profile into complain mode yielded ambiguous socket denial errors. Disabling the AppArmor profile allowed unbound to start correctly. I also purged my existing unbound install (reverting to stock configs) and it too would not start
   * What was the outcome of this action?
     unbound started correctly with the AppArmor profile disabled or put into complain mode
   * What outcome did you expect instead?
     Stock unbound to start correctly

#1110985#10
Date:
2025-08-14 10:36:31 UTC
From:
To:
What does it deny, exactly?

Thanks,

/mjt

#1110985#15
Date:
2025-08-14 15:47:35 UTC
From:
To:
Here's the audit output:

In Enforcing mode:
[116298.210537] audit: type=1400 audit(1755186236.003:693):
apparmor="STATUS" operation="profile_load" profile="unconfined"
name="unbound" pid=913125 comm="apparmor_parser"
[116301.019725] audit: type=1400 audit(1755186238.812:694):
apparmor="DENIED" operation="create" class="net" info="failed protocol
match" error=-13 profile="unbound" pid=913233 comm="unbound"
family="unix" sock_type="stream" protocol=0 requested="create"
denied="create" addr=none
[116301.019730] audit: type=1400 audit(1755186238.812:695):
apparmor="DENIED" operation="create" class="net" info="failed protocol
match" error=-13 profile="unbound" pid=913233 comm="unbound"
family="unix" sock_type="stream" protocol=0 requested="create"
denied="create" addr=none
[116301.020653] audit: type=1400 audit(1755186238.813:696):
apparmor="DENIED" operation="capable" class="cap" profile="unbound"
pid=913233 comm="unbound" capability=12  capname="net_admin"
[116301.021313] audit: type=1400 audit(1755186238.814:697):
apparmor="DENIED" operation="create" class="net" info="failed protocol
match" error=-13 profile="unbound" pid=913233 comm="unbound"
family="unix" sock_type="stream" protocol=0 requested="create"
denied="create" addr=none
[116301.340243] audit: type=1400 audit(1755186239.133:698):
apparmor="DENIED" operation="create" class="net" info="failed protocol
match" error=-13 profile="unbound" pid=913277 comm="unbound"
family="unix" sock_type="stream" protocol=0 requested="create"
denied="create" addr=none
[116301.340248] audit: type=1400 audit(1755186239.133:699):
apparmor="DENIED" operation="create" class="net" info="failed protocol
match" error=-13 profile="unbound" pid=913277 comm="unbound"
family="unix" sock_type="stream" protocol=0 requested="create"
denied="create" addr=none
[116301.341241] audit: type=1400 audit(1755186239.134:700):
apparmor="DENIED" operation="capable" class="cap" profile="unbound"
pid=913277 comm="unbound" capability=12  capname="net_admin"
[116301.341899] audit: type=1400 audit(1755186239.134:701):
apparmor="DENIED" operation="create" class="net" info="failed protocol
match" error=-13 profile="unbound" pid=913277 comm="unbound"
family="unix" sock_type="stream" protocol=0 requested="create"
denied="create" addr=none
[116301.637948] audit: type=1400 audit(1755186239.430:702):
apparmor="DENIED" operation="create" class="net" info="failed protocol
match" error=-13 profile="unbound" pid=913328 comm="unbound"
family="unix" sock_type="stream" protocol=0 requested="create"
denied="create" addr=none

In Complain mode:
[116330.288320] audit: type=1400 audit(1755186268.082:714):
apparmor="STATUS" operation="profile_replace" profile="unconfined"
name="unbound" pid=913713 comm="apparmor_parser"
[116331.912069] audit: type=1400 audit(1755186269.706:715):
apparmor="ALLOWED" operation="create" class="net" info="failed
protocol match" error=-13 profile="unbound" pid=913729 comm="unbound"
family="unix" sock_type="stream" protocol=0 requested="create"
denied="create" addr=none
[116331.912084] audit: type=1400 audit(1755186269.706:716):
apparmor="ALLOWED" operation="create" class="net" info="failed
protocol match" error=-13 profile="unbound" pid=913729 comm="unbound"
family="unix" sock_type="stream" protocol=0 requested="create"
denied="create" addr=none
[116331.913004] audit: type=1400 audit(1755186269.707:717):
apparmor="ALLOWED" operation="capable" class="cap" profile="unbound"
pid=913729 comm="unbound" capability=12  capname="net_admin"
[116331.913644] audit: type=1400 audit(1755186269.707:718):
apparmor="ALLOWED" operation="create" class="net" info="failed
protocol match" error=-13 profile="unbound" pid=913729 comm="unbound"
family="unix" sock_type="stream" protocol=0 requested="create"
denied="create" addr=none
[116331.914692] audit: type=1400 audit(1755186269.708:719):
apparmor="ALLOWED" operation="create" class="net" info="failed
protocol match" error=-13 profile="unbound" pid=913729 comm="unbound"
family="unix" sock_type="dgram" protocol=0 requested="create"
denied="create" addr=none
[116331.914716] audit: type=1400 audit(1755186269.708:720):
apparmor="ALLOWED" operation="create" class="net" info="failed
protocol match" error=-13 profile="unbound" pid=913729 comm="unbound"
family="unix" sock_type="stream" protocol=0 requested="create"
denied="create" addr=none
[116331.914731] audit: type=1400 audit(1755186269.708:721):
apparmor="ALLOWED" operation="create" class="net" info="failed
protocol match" error=-13 profile="unbound" pid=913729 comm="unbound"
family="unix" sock_type="stream" protocol=0 requested="create"
denied="create" addr=none
[116331.915012] audit: type=1400 audit(1755186269.709:722):
apparmor="ALLOWED" operation="create" class="net" info="failed
protocol match" error=-13 profile="unbound" pid=913729 comm="unbound"
family="unix" sock_type="stream" protocol=0 requested="create"
denied="create" addr=none
[116331.915023] audit: type=1400 audit(1755186269.709:723):
apparmor="ALLOWED" operation="connect" class="file" profile="unbound"
name="/run/samba/winbindd/pipe" pid=913729 comm="unbound"
requested_mask="wr" denied_mask="wr" fsuid=0 ouid=0

#1110985#20
Date:
2025-08-14 15:53:38 UTC
From:
To:
...

Now that's fun.

I suppose you have libnss-winbind installed.
Do you actually need it?
Can you check if unbound will work without this
module in /etc/nsswitch.conf?

Thanks,

/mjt

#1110985#25
Date:
2025-08-14 16:24:39 UTC
From:
To:
Resending with the appropriate To line:

I do unfortunately need libnss-winbind.

I should have mentioned that I previously attempted to add that pipe
to a local addition to the AppArmor protocol and it didn't help. Here
was my /etc/apparmor.d/local/usr.sbin.unbound:
    /run/samba/winbindd/pipe rw,

Here's the Complain audit log:
[118042.338643] audit: type=1400
audit(1755187980.146:820):apparmor="STATUS"
operation="profile_replace" profile="unconfined"name="unbound"
pid=927953 comm="apparmor_parser"
[118043.577014] audit: type=1400
audit(1755187981.384:821):apparmor="ALLOWED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=927968 comm="unbound" family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118043.577030] audit: type=1400
audit(1755187981.384:822):apparmor="ALLOWED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=927968 comm="unbound" family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118043.578034] audit: type=1400
audit(1755187981.385:823):apparmor="ALLOWED" operation="capable"
class="cap" profile="unbound"pid=927968 comm="unbound" capability=12
capname="net_admin"
[118043.578685] audit: type=1400
audit(1755187981.386:824):apparmor="ALLOWED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=927968 comm="unbound" family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118043.579738] audit: type=1400
audit(1755187981.387:825):apparmor="ALLOWED" operation="create"
class="net" info="failedprotocol match" error=-13 profile="unbound"
pid=927968 comm="unbound" family="unix" sock_type="dgram" protocol=0
requested="create"denied="create" addr=none
[118043.579762] audit: type=1400
audit(1755187981.387:826):apparmor="ALLOWED" operation="create"
class="net" info="failedprotocol match" error=-13 profile="unbound"
pid=927968 comm="unbound" family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118043.579776] audit: type=1400
audit(1755187981.387:827):apparmor="ALLOWED" operation="create"
class="net" info="failedprotocol match" error=-13 profile="unbound"
pid=927968 comm="unbound" family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118043.580050] audit: type=1400
audit(1755187981.387:828):apparmor="ALLOWED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=927968 comm="unbound" family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118043.717810] audit: type=1400
audit(1755187981.525:829):apparmor="ALLOWED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=927968 comm="unbound" family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none

So the winbind pipe needs to be added to the profile but it's not the
underlying problem.

If I remove the local AppAmor modification and remove all references
to wins and winbind in /etc/nsswitch.conf, it still won't start:

Enforcing log:
[118339.058213] audit: type=1400 audit(1755188276.869:876):
apparmor="STATUS" operation="profile_replace" profile="unconfined"
name="unbound" pid=930594 comm="apparmor_parser"
[118340.386319] audit: type=1400 audit(1755188278.197:877):
apparmor="DENIED" operation="create" class="net" info="failed protocol
match" error=-13 profile="unbound" pid=929938 comm="unbound"
family="unix" sock_type="dgram" protocol=0
requested="create"denied="create" addr=none
[118340.435786] audit: type=1400
audit(1755188278.247:878):apparmor="DENIED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=930699 comm="unbound"family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118340.435790] audit: type=1400
audit(1755188278.247:879):apparmor="DENIED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=930699 comm="unbound"family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118340.436718] audit: type=1400
audit(1755188278.247:880):apparmor="DENIED" operation="capable"
class="cap" profile="unbound"pid=930699 comm="unbound" capability=12
capname="net_admin"
[118340.437370] audit: type=1400
audit(1755188278.248:881):apparmor="DENIED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=930699 comm="unbound"family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118340.845239] audit: type=1400
audit(1755188278.656:882):apparmor="DENIED" operation="create"
class="net" info="failed protocolmatch" error=-13 profile="unbound"
pid=930744 comm="unbound"family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118340.845243] audit: type=1400
audit(1755188278.656:883):apparmor="DENIED" operation="create"
class="net" info="failed protocolmatch" error=-13 profile="unbound"
pid=930744 comm="unbound"family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118340.846177] audit: type=1400
audit(1755188278.657:884):apparmor="DENIED" operation="capable"
class="cap" profile="unbound"pid=930744 comm="unbound" capability=12
capname="net_admin"
[118340.846847] audit: type=1400
audit(1755188278.658:885):apparmor="DENIED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=930744 comm="unbound"family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none

Complain log:
[118356.454014] audit: type=1400
audit(1755188294.264:898):apparmor="STATUS"
operation="profile_replace" profile="unconfined" name="unbound"
pid=931019 comm="apparmor_parser"
[118358.060412] audit: type=1400
audit(1755188295.870:899):apparmor="ALLOWED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=931028 comm="unbound" family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118358.060427] audit: type=1400
audit(1755188295.870:900):apparmor="ALLOWED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=931028 comm="unbound" family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118358.061367] audit: type=1400
audit(1755188295.871:901):apparmor="ALLOWED" operation="capable"
class="cap" profile="unbound"pid=931028 comm="unbound" capability=12
capname="net_admin"
[118358.062018] audit: type=1400
audit(1755188295.872:902):apparmor="ALLOWED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=931028 comm="unbound" family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118358.063060] audit: type=1400
audit(1755188295.873:903):apparmor="ALLOWED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=931028 comm="unbound" family="unix" sock_type="dgram" protocol=0
requested="create"denied="create" addr=none
[118358.063084] audit: type=1400
audit(1755188295.873:904):apparmor="ALLOWED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=931028 comm="unbound" family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118358.063098] audit: type=1400
audit(1755188295.873:905):apparmor="ALLOWED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=931028 comm="unbound" family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118358.065697] audit: type=1400
audit(1755188295.876:906):apparmor="ALLOWED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=931028 comm="unbound" family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none
[118358.065703] audit: type=1400
audit(1755188295.876:907):apparmor="ALLOWED" operation="create"
class="net" info="failed protocol match" error=-13 profile="unbound"
pid=931028 comm="unbound" family="unix" sock_type="stream" protocol=0
requested="create"denied="create" addr=none

#1110985#30
Date:
2025-08-15 08:23:30 UTC
From:
To:
I never used apparmor before.

Now, looking at all this, I don't see how it is supposed to work.

First, there's a bug in apparmor package, namely, its
/etc/apparmor.d/abstractions/winbind (for nss-winbind, which is in
use here) lists /tmp/.winbindd/pipe, which moved to /run/winbind/pipe
more than a decade ago.  I wonder how it hasn't been noticed so far.
This needs to be fixed.

Second, none of the files included from
/etc/apparmor.d/abstractions/nameservice
allow unix sockets, while allowing inet/inet6 stream/dgram sockets.
But unix sockets are used - by nss-winbind, nss-systemd etc.  I've
no idea how it is supposed to work in the first place, - with this,
common nss modules wont work (as we see here).  I bet there are some
other nss modules used in this configuration - something like
nss-systemd, which is where other unix sockets comes from.

Third, I don't even know how to enable unix sockets creation in
an apparmor profile.  It should be enabled in nameservice-strict
abstraction already (but see 2nd above).

Overall, it all looks like bugs in apparmor package, not in unbound,
since unbound can't be responsible for nss configuration.

So, I need help with this stuff.  Maybe I should reassign this bug
to where it actually belongs.

At least, try adding these to /etc/apparmor.d/local/usr.sbin.unbound:

   unix,
   # pam_winbindd
   /run/winbindd/pipe  rw,

I dunno if this will work or not - the "unix" part.
winbind part should work.

Thanks,

/mjt

#1110985#35
Date:
2025-08-15 15:08:23 UTC
From:
To:
As predicted, the winbindd part works but unbound still fails to start
with the same errors.

The worst problems are those where you are asking yourself how they
ever worked. I am definitely not the AppArmor resource you're looking
for; I completely defer to you on how to proceed.