qemu doesn't normally need /tmp and /var/tmp. Something is making it use
it (ie, VMs launched under local libvirt (ie, not OpenStack) don't have
this problem). One could add an explicit deny rule to
/etc/apparmor.d/abstractions/libvirt-qemu to deny /tmp and /var/tmp, but
I think it would be better to understand the problem (and that might
break testing environment that legitimately put the disk in /tmp).

The attached xml isn't what I was looking for. When an affected VM is running, 
can you do:
$ virsh dumpxml <domain>

where '<domain>' can be found from 'virsh list'.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1403648

Title:
  Apparmor denies qemu access to a number of important directories.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1403648/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to