[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-12-07 Thread Launchpad Bug Tracker
[Expired for libvirt (Ubuntu) because there has been no activity for 60
days.]

** Changed in: libvirt (Ubuntu)
   Status: Incomplete => Expired

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-10-08 Thread Serge Hallyn
@Mike,

when you say you restarted apparmor, could you say exactly what command
you used?

Was the problem you had also the ptrace DENIED messages?

Which release are you on?


** Changed in: libvirt (Ubuntu)
   Status: Confirmed => Incomplete

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-10-08 Thread Serge Hallyn
** Changed in: libvirt (Ubuntu)
   Status: Invalid => Confirmed

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-10-08 Thread Mike Lowe
I had the same problem, solved by restarting apparmor.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-09-30 Thread Serge Hallyn
Could you please file a new bug so we can gather the relevant system
information (release, libvirt versions, apparmor files, and DENIED
messages from syslog for a start) on a clean sheet of paper as it were?

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-09-26 Thread Genc Tato
Hi,

I have the same problem and those three lines that you suggest above are 
present in my usr.sbin.libvirtd.
I don't see any usr.sbin.libvirtd.dpkg-dist file in /etc/apparmor.d/.

I also tried to reinstall apparmor as Alex suggest but with no results.
Only if I disable apparmor, I can delete my containers (VMs).

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-07-10 Thread Axel Pospischil
I had the same problem after updates:

After

   service apparmor teardown

I can shutdown the machine.
So this is definitely a problem of apparmor.

I did:

  apt-get install --reinstall apparmor

And it works now.

 A file named usr.sbin.libvirtd.dpkg-dist  did not exist on the system

Greets

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-06-17 Thread Matej Kenda
diff -u usr.sbin.libvirtd usr.sbin.libvirtd.dpkg-dist 
--- usr.sbin.libvirtd   2014-01-27 11:31:51.209483436 +0100
+++ usr.sbin.libvirtd.dpkg-dist 2014-04-14 18:23:33.0 +0200
@@ -34,6 +34,10 @@
   network inet6 dgram,
   network packet dgram,
 
+  dbus bus=system,
+  signal,
+  ptrace,
+
   # for now, use a very lenient profile since we want to first focus on
   # confining the guests
   / r,

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-06-17 Thread Matej Kenda
After replacing usr.sbin.libvirtd with usr.sbin.libvirtd.dpkg-dist in
/etc permission denied is not reported any more.

Thanks.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-06-16 Thread Jamie Strandboge
As Serge said, you are missing required rules in your libvirtd profile. This 
probably happened during upgrade and you like have a 
/etc/apparmor.d/usr.sbin.libvirtd.dpkg-new file. If you add these rules to the 
profile then do:
$ sudo apparmor_parser -r /etc/apparmor.d/usr.sbin.libvirtd

things should start working again.

** Package changed: virt-manager (Ubuntu) => libvirt (Ubuntu)

** Changed in: libvirt (Ubuntu)
   Status: Incomplete => Invalid

** Changed in: libvirt (Ubuntu)
 Assignee: Jamie Strandboge (jdstrand) => (unassigned)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-06-16 Thread Serge Hallyn
It looks as though your /etc/apparmor.d/usr.sbin.libvirtd is missing at
least these lines:

  dbus bus=system,
  signal,
  ptrace,

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/virt-manager/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-06-16 Thread Matej Kenda
$ cat /etc/apparmor.d/usr.sbin.libvirtd
# Last Modified: Mon Jul  6 17:23:58 2009
#include 
@{LIBVIRT}="libvirt"

/usr/sbin/libvirtd {
  #include 
  #include 
  # Site-specific additions and overrides. See local/README for details.
  #include 

  capability kill,
  capability net_admin,
  capability net_raw,
  capability setgid,
  capability sys_admin,
  capability sys_module,
  capability sys_ptrace,
  capability sys_nice,
  capability sys_chroot,
  capability setuid,
  capability dac_override,
  capability dac_read_search,
  capability fowner,
  capability chown,
  capability setpcap,
  capability mknod,
  capability fsetid,
  capability ipc_lock,
  capability audit_write,

  network inet stream,
  network inet dgram,
  network inet6 stream,
  network inet6 dgram,
  network packet dgram,

  # for now, use a very lenient profile since we want to first focus on
  # confining the guests
  / r,
  /** rwmkl,

  /bin/* PUx,
  /sbin/* PUx,
  /usr/bin/* PUx,
  /usr/sbin/* PUx,
  /lib/udev/scsi_id PUx,
  /usr/lib/xen-common/bin/xen-toolstack PUx,

  # Required by nwfilter_ebiptables_driver.c:ebiptablesWriteToTempFile() to
  # write and run an ebtables script.
  /var/lib/libvirt/virtd* ixr,

  # force the use of virt-aa-helper
  audit deny /sbin/apparmor_parser rwxl,
  audit deny /etc/apparmor.d/libvirt/** wxl,
  audit deny /sys/kernel/security/apparmor/features rwxl,
  audit deny /sys/kernel/security/apparmor/matching rwxl,
  audit deny /sys/kernel/security/apparmor/.* rwxl,
  /sys/kernel/security/apparmor/profiles r,
  /usr/lib/libvirt/* PUxr,
  /etc/libvirt/hooks/** rmix,
  /etc/xen/scripts/** rmix,

  # allow changing to our UUID-based named profiles
  change_profile -> 
@{LIBVIRT}-[0-9a-f]*-[0-9a-f]*-[0-9a-f]*-[0-9a-f]*-[0-9a-f]*,

}

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/virt-manager/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-06-13 Thread Jamie Strandboge
This denial:
[575396.447436] type=1400 audit(1400831118.540:4053058): apparmor="DENIED" 
operation="ptrace" profile="/usr/sbin/libvirtd" pid=1375 comm="libvirtd" 
requested_mask="trace" denied_mask="trace" 
peer="libvirt-d5ad659b-6ea3-31ee-3680-6f7512b3e7c7"

shows that it is the libvirtd profile that doesn't have the correct
permissions (profile="/usr/sbin/libvirtd"). It sounds like
/etc/apparmor.d/usr.sbin.libvirtd did not get updated on upgrade. Can
you attach the output of:

$ cat /etc/apparmor.d/usr.sbin.libvirtd

** Changed in: virt-manager (Ubuntu)
   Status: New => Incomplete

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/virt-manager/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-06-13 Thread Serge Hallyn
Hi Jamie,

I've temporarily assigned this to you just to ask if you can think of
anything that would cause this?  I've not seen it happen myself at all.
His apparmor profile appears to be uptodate (see comment #3), yet
libvirt appears to be unable to signal or trace its vms when asked to
destroy them.

** Changed in: virt-manager (Ubuntu)
 Assignee: (unassigned) => Jamie Strandboge (jdstrand)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/virt-manager/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-06-10 Thread Serge Hallyn
** Changed in: virt-manager (Ubuntu)
   Status: Incomplete => New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/virt-manager/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-06-10 Thread Matej Kenda
Yes, the files are from remote server, of course.

$ virsh destroy tomcat
setlocale: No such file or directory
error: Failed to destroy domain tomcat
error: Failed to terminate process 5170 with SIGTERM: Permission denied

After reboot, the result is the same (system started with updated
kernel):

$ uname -a
Linux zeus 3.13.0-29-generic #53-Ubuntu SMP Wed Jun 4 21:00:20 UTC 2014 x86_64 
x86_64 x86_64 GNU/Linux
$ virsh destroy tomcat
error: Failed to destroy domain tomcat
error: Failed to terminate process 1577 with SIGTERM: Permission denied

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/virt-manager/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-06-09 Thread Serge Hallyn
Hi,

thanks for the information.  The apparmor files do look correct.  To be
sure, those came from the compute node (the remote server), not from the
client, right?

Does logging into the server and typing 'virsh destroy ' also
fail?  (I assume so)

All I can figure is that for some reason (a bug in apparmor or the
kernel) the running vm's policy did not get updated when the included
file in the apparmor policy was updated.  Is it possible to reboot the
server, start the VM, and confirm whether stop works then?

** Changed in: virt-manager (Ubuntu)
   Status: New => Incomplete

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/virt-manager/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-06-09 Thread Serge Hallyn
** Changed in: virt-manager (Ubuntu)
   Status: Incomplete => New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/virt-manager/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-06-02 Thread Matej Kenda
Can I somehow force the files to be upgraded manually?

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/virt-manager/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-06-01 Thread Matej Kenda
$ cat /etc/apparmor.d/abstractions/libvirt-qemu
# Last Modified: Wed Jul  8 09:57:41 2009

  #include 
  #include 
  #include 

  # required for reading disk images
  capability dac_override,
  capability dac_read_search,
  capability chown,

  # needed to drop privileges
  capability setgid,
  capability setuid,

  # this is needed with libcap-ng support, however it breaks a lot of things
  # atm, so just silence the denial until libcap-ng works right. LP: #522845
  deny capability setpcap,

  network inet stream,
  network inet6 stream,

  /dev/net/tun rw,
  /dev/tap* rw,
  /dev/kvm rw,
  /dev/ptmx rw,
  /dev/kqemu rw,
  @{PROC}/*/status r,
  owner @{PROC}/*/auxv r,
  @{PROC}/sys/vm/overcommit_memory r,

  # For hostdev access. The actual devices will be added dynamically
  /sys/bus/usb/devices/ r,
  /sys/devices/**/usb[0-9]*/** r,

  # WARNING: this gives the guest direct access to host hardware and specific
  # portions of shared memory. This is required for sound using ALSA with kvm,
  # but may constitute a security risk. If your environment does not require
  # the use of sound in your VMs, feel free to comment out or prepend 'deny' to
  # the rules for files in /dev.
  /{dev,run}/shm r,
  /{dev,run}/shmpulse-shm* r,
  /{dev,run}/shmpulse-shm* rwk,
  /dev/snd/* rw,
  capability ipc_lock,
  # spice
  /usr/bin/qemu-system-i386-spice rmix,
  /usr/bin/qemu-system-x86_64-spice rmix,
  /run/shm/ r,
  owner /run/shm/spice.* rw,
  # 'kill' is not required for sound and is a security risk. Do not enable
  # unless you absolutely need it.
  deny capability kill,

  # Uncomment the following if you need access to /dev/fb*
  #/dev/fb* rw,

  /etc/pulse/client.conf r,
  @{HOME}/.pulse-cookie rwk,
  owner /root/.pulse-cookie rwk,
  owner /root/.pulse/ rw,
  owner /root/.pulse/* rw,
  /usr/share/alsa/** r,
  owner /tmp/pulse-*/ rw,
  owner /tmp/pulse-*/* rw,
  /var/lib/dbus/machine-id r,

  # access to firmware's etc
  /usr/share/kvm/** r,
  /usr/share/qemu/** r,
  /usr/share/bochs/** r,
  /usr/share/openbios/** r,
  /usr/share/openhackware/** r,
  /usr/share/proll/** r,
  /usr/share/vgabios/** r,
  /usr/share/seabios/** r,
  /usr/share/ovmf/** r,

  # access PKI infrastructure
  /etc/pki/libvirt-vnc/** r,

  # the various binaries
  /usr/bin/kvm rmix,
  /usr/bin/qemu rmix,
  /usr/bin/qemu-system-aarch64 rmix,
  /usr/bin/qemu-system-arm rmix,
  /usr/bin/qemu-system-cris rmix,
  /usr/bin/qemu-system-i386 rmix,
  /usr/bin/qemu-system-m68k rmix,
  /usr/bin/qemu-system-mips rmix,
  /usr/bin/qemu-system-mips64 rmix,
  /usr/bin/qemu-system-mips64el rmix,
  /usr/bin/qemu-system-mipsel rmix,
  /usr/bin/qemu-system-ppc rmix,
  /usr/bin/qemu-system-ppc64 rmix,
  /usr/bin/qemu-system-ppcemb rmix,
  /usr/bin/qemu-system-sh4 rmix,
  /usr/bin/qemu-system-sh4eb rmix,
  /usr/bin/qemu-system-sparc rmix,
  /usr/bin/qemu-system-sparc64 rmix,
  /usr/bin/qemu-system-x86_64 rmix,
  /usr/bin/qemu-system-x86_64-spice rmix,
  /usr/bin/qemu-alpha rmix,
  /usr/bin/qemu-arm rmix,
  /usr/bin/qemu-armeb rmix,
  /usr/bin/qemu-cris rmix,
  /usr/bin/qemu-i386 rmix,
  /usr/bin/qemu-m68k rmix,
  /usr/bin/qemu-mips rmix,
  /usr/bin/qemu-mipsel rmix,
  /usr/bin/qemu-ppc rmix,
  /usr/bin/qemu-ppc64 rmix,
  /usr/bin/qemu-ppc64abi32 rmix,
  /usr/bin/qemu-sh4 rmix,
  /usr/bin/qemu-sh4eb rmix,
  /usr/bin/qemu-sparc rmix,
  /usr/bin/qemu-sparc64 rmix,
  /usr/bin/qemu-sparc32plus rmix,
  /usr/bin/qemu-sparc64 rmix,
  /usr/bin/qemu-x86_64 rmix,

  # for save and resume
  /bin/dash rmix,
  /bin/dd rmix,
  /bin/cat rmix,
  /etc/pki/CA/ r,
  /etc/pki/CA/* r,
  /etc/pki/libvirt/ r,
  /etc/pki/libvirt/** r,

  # for rbd
  /etc/ceph/ceph.conf r,

  # for access to hugepages
  owner "/run/hugepages/kvm/libvirt/qemu/**" rw,

  # for usb access
  /dev/bus/usb/ r,
  /etc/udev/udev.conf r,
  /sys/bus/ r,
  /sys/class/ r,

  signal (receive) peer=/usr/sbin/libvirtd,
  ptrace (tracedby) peer=/usr/sbin/libvirtd,

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/virt-manager/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-06-01 Thread Matej Kenda
$ dpkg -l | grep libvirt
ii  libvirt-bin 1.2.2-0ubuntu13.1   
amd64programs for the libvirt library
ii  libvirt01.2.2-0ubuntu13.1   
amd64library for interfacing with different virtualization systems
ii  python-libvirt  1.2.2-0ubuntu1  
amd64libvirt Python bindings

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/virt-manager/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-06-01 Thread Matej Kenda
$ cat /etc/apparmor.d/libvirt/libvirt-6a3beaf2-5362-11e3-bc34-001e4f354ef5
#
# This profile is for the domain whose UUID matches this file.
#

#include 

profile libvirt-6a3beaf2-5362-11e3-bc34-001e4f354ef5 {
  #include 
  #include 

}

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/virt-manager/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-06-01 Thread Matej Kenda
matejk@zeus:~$ cat 
/etc/apparmor.d/libvirt/libvirt-6a3beaf2-5362-11e3-bc34-001e4f354ef5.files 
# DO NOT EDIT THIS FILE DIRECTLY. IT IS MANAGED BY LIBVIRT.
  "/var/log/libvirt/**/win8-build.log" w,
  "/var/lib/libvirt/**/win8-build.monitor" rw,
  "/var/run/libvirt/**/win8-build.pid" rwk,
  "/run/libvirt/**/win8-build.pid" rwk,
  "/var/run/libvirt/**/*.tunnelmigrate.dest.win8-build" rw,
  "/run/libvirt/**/*.tunnelmigrate.dest.win8-build" rw,
  "/dev/dm-5" rw,

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/virt-manager/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1324393] Re: "Force off" fails with "Permission denied" after upgrading to 14.04

2014-05-30 Thread Serge Hallyn
Thanks for submitting this bug.  Could you please show your libvirt
version?  (dpkg -l | grep libvirt)

What you describe sounds like the file /etc/apparmor.d/abstractions
/libvirt-qemu did not get updated correctly with version 1.2.2-0ubuntu9,
which should have done:

  [ Jamie Strandboge ]
  * updates for AppArmor signals and ptrace mediation (LP: #1298611)
- debian/apparmor/libvirt-qemu: allow guests to receive signals from and
  be tracedby libvirtd (additional signal and ptrace rules come from the
  AppArmor base abstraction)

Could you please show the contents of both 
/etc/apparmor.d/abstractions/libvirt-qemu and
/etc/apparmor.d/libvirt/libvirt-6a3beaf2-5362-11e3-bc34-001e4f354ef5* ?

** Changed in: virt-manager (Ubuntu)
   Status: New => Incomplete

** Changed in: virt-manager (Ubuntu)
   Importance: Undecided => High

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1324393

Title:
  "Force off" fails with "Permission denied" after upgrading to 14.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/virt-manager/+bug/1324393/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs