A new pve-container package with version 6.0.3 has just been uploaded, it contains a fix to generates the relevant mqueue apparmor rule by default.
Please note though that enabling keyctl and other features might still be required and is not...
I have the same issue from time to time on different machines. It seems to happen more often on nodes with lower performance. I also didn't find any hidden mounts or processes which using the snapshot. I'm already using the kernel 6.14.
It...