Thanks.  So looking at the current profile for virt-aa-helper, it is
allowed to read anything under /mnt, /opt, /srv, /media, most anything
under /home, but and anything under /var/lib/libvirt, /var/lib/nova,
and a few others.

Your vms are under /var/vm.  You can of course work around this trivially
by adding the line

  /var/vms/** r,

to /etc/apparmor.d/usr.lib.libvirt.virt-aa-helper.  The preferred
workaround would be to move the vms under /var/lib/libvirt/images
or another of the currently whitelisted paths.

I'm assigning this temporarily to Jamie to get his input on whether
the finer granularity under /var was on purpose (I assume it was),
or whether we can just whitelist all of /var/**. 

 status: confirmed
 assignee: jdstrand
 importance: medium


** Changed in: libvirt (Ubuntu)
   Importance: Undecided => Medium

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1320221

Title:
  Apparmor blocks creating external snaphshot

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1320221/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to