Public bug reported:
On Ubuntu 26.04, /usr/bin/gs works normally when launched from a regular
GNOME Terminal, but fails when the same command is launched from the
integrated terminal of the official VS Code Snap.
The failure appears to be associated with the Ubuntu AppArmor profile
for Ghostscript (profile="gs"). Kernel audit messages show file_inherit
denials against file descriptors inherited from the VS Code/Snap process
tree.
Ghostscript exits with status 255 and leaves an incomplete PDF without a
valid trailer/xref table.
The same Ghostscript binary and same input work from a normal terminal.
Environment
Ubuntu 26.04.1 LTS
Ghostscript 10.06.0 from Ubuntu packages
Official VS Code Snap, classic confinement
AppArmor enabled
/etc/apparmor.d/gs is the Ubuntu-provided Ghostscript profile
No custom changes to the packaged gs AppArmor profile are involved.
Observed behavior
When Ghostscript is launched from a normal GNOME Terminal, PDF
conversion succeeds.
When the same Ghostscript invocation is launched from the VS Code Snap
integrated terminal, Ghostscript exits:
Exit status: 255
The output PDF is incomplete. pdfinfo reports errors such as:
Syntax Error: Couldn't find trailer dictionary
Syntax Error: Couldn't read xref table
Kernel audit logging at the time of the failure reports AppArmor denials
attributed specifically to the gs profile, including:
apparmor="DENIED" operation="file_inherit" class="file"
profile="gs" name="/dev/pts/<N>" requested_mask="wr" denied_mask="wr"
and:
apparmor="DENIED" operation="file_inherit" class="file"
profile="gs"
name="/snap/code/<revision>/usr/share/code/v8_context_snapshot.bin"
requested_mask="r" denied_mask="r"
Additional denied reads may occur for locale files under the VS Code
Snap tree.
No usernames, home-directory paths, hostnames, PIDs, or other
identifying information are included here.
Process-context comparison
The working terminal shell is:
AppArmor: unconfined
NoNewPrivs: 0
Seccomp: 0
Seccomp_filters: 0
The VS Code integrated terminal shell is:
AppArmor: snap.code.code (complain)
NoNewPrivs: 0
Seccomp: 0
Seccomp_filters: 0
The failure therefore does not appear to be caused by seccomp or
NoNewPrivs.
Resource limits were also compared. No restrictive file-size, memory,
process, or open-file limit was found that explains the failure.
Environment-variable isolation
The Ghostscript command was also launched from the VS Code integrated
terminal using an almost-empty environment, for example:
env -i \
HOME="$HOME" \
USER="$USER" \
LOGNAME="$LOGNAME" \
PATH="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin" \
LANG="${LANG:-C.UTF-8}" \
/usr/bin/gs \
-dBATCH \
-dNOPAUSE \
-sDEVICE=pdfwrite \
-o /tmp/test-output.pdf \
input.pdf
The result remained the same: Ghostscript exited with status 255 and
produced an incomplete PDF.
This suggests the problem is not caused by normal inherited environment
variables.
Minimal reproducer
Based on the diagnostic testing so far, the following should provide a
minimal reproducer.
First create a trivial PostScript file:
cat >/tmp/gs-apparmor-test.ps <<'EOF'
%!PS
/Helvetica findfont 24 scalefont setfont
72 720 moveto
(Ghostscript AppArmor test) show
showpage
EOF
From a normal GNOME Terminal, run:
/usr/bin/gs \
-dBATCH \
-dNOPAUSE \
-sDEVICE=pdfwrite \
-o /tmp/gs-normal-terminal.pdf \
/tmp/gs-apparmor-test.ps
echo $?
Then run the same command from the integrated terminal of the official
VS Code Snap:
/usr/bin/gs \
-dBATCH \
-dNOPAUSE \
-sDEVICE=pdfwrite \
-o /tmp/gs-vscode-terminal.pdf \
/tmp/gs-apparmor-test.ps
echo $?
Based on the observed behavior with valid PDF input, the external-
terminal invocation is expected to succeed while the VS Code-terminal
invocation may exit 255.
The exact trivial-PostScript reproducer above was derived from the
already-confirmed PDF-input reproducer; the confirmed condition is that
ordinary /usr/bin/gs PDF conversion works externally and fails from the
VS Code integrated terminal.
After reproducing the VS Code failure, relevant audit events can be
checked with:
journalctl -k --since "2 minutes ago" --no-pager |
grep -Ei 'apparmor|ghostscript|/usr/bin/gs'
Expected behavior
Launching the Ubuntu-provided /usr/bin/gs from the integrated terminal
of the officially distributed VS Code Snap should work in the same way
as launching it from an ordinary terminal.
The Ghostscript AppArmor profile should safely handle file descriptors
inherited from common desktop application/process environments rather
than causing Ghostscript to terminate.
Actual behavior
When launched from the VS Code Snap process tree, the gs AppArmor
profile produces file_inherit denials involving VS Code/Snap
descriptors. Ghostscript exits with status 255 and leaves an invalid
output PDF.
The same command succeeds when launched outside VS Code.
Suspected cause
This appears to be an interaction between the Ubuntu 26.04 Ghostscript
AppArmor profile and file descriptors inherited when /usr/bin/gs is
executed as a descendant of the VS Code Snap.
This is a suspected cause rather than a definitive root-cause
determination.
The strongest evidence is:
Identical /usr/bin/gs command works from a normal terminal.
It fails from the VS Code integrated terminal.
Removing ordinary environment variables with env -i does not fix it.
Seccomp and NoNewPrivs are disabled in both contexts.
Kernel audit messages during the failure identify profile="gs" and
report file_inherit denials for descriptors originating from the VS
Code/Snap execution context.
Possible related issue
There have been other recent Ubuntu reports of Ghostscript failures
caused by the new AppArmor profile, although the specific VS Code/Snap
file_inherit interaction described here appears different.
Troubleshooting assistance
The investigation was performed interactively with assistance from
ChatGPT, using OpenAI's GPT-5.6 Sol model.
ChatGPT helped design the comparison tests, including:
reducing the original application-specific failure to a direct
/usr/bin/gs invocation;
comparing execution from GNOME Terminal and the VS Code integrated
terminal;
testing with a sanitized environment using env -i;
comparing AppArmor, seccomp, NoNewPrivs, cgroup, and resource-limit
state;
identifying and interpreting the contemporaneous AppArmor audit denials.
The commands and results reported above were executed and observed on
the affected Ubuntu system; the suspected AppArmor cause is based on
those observations.
** Affects: apparmor (Ubuntu)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169789
Title:
Ubuntu 26.04 gs AppArmor profile causes Ghostscript to exit 255 when
launched from VS Code Snap integrated terminal
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2169789/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs