A closer examination of the scripts update-systemd-resolved and dns- updown reveals that properly confining them would require writing multiple new profiles for the binaries that they invoke. This close to the 26.04 LTS release, I think the best course of action will be to pull the openvpn profile and then try to reintroduce a fixed version for 26.10.
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2146874 Title: OpenVPN fails to execute update-systemd-resolved scripts due to restrictive AppArmor profile To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2146874/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
