** Description changed:

+ 1) Download a Ubuntu Cloud Image
+    $ wget 
https://cloud-images.ubuntu.com/noble/current/noble-server-cloudimg-amd64.img
+    and start a VM with virsh from the domain definition [2]
+ 
+ 2) Check VM running with:
+    $ virsh list
+ 
+ 3) virsh attach-device --domain ubuntu-cloud-vm --file dev.xml
+ 
+ dev.xml contains an example of the USB the device, it usually works on all PC
+ but if that does not, please tune it for the host system you are testing on. 
+ 
+ Access denied:
+ (this is an exemple of the dmesg log message)
+ 
+ audit: type=1400 audit(1784186108.556:533): apparmor="DENIED"
+ operation="open" class="file"
+ profile="libvirt-c13c2cda-4558-4fca-9146-9f2f8075d432"
+ name="/sys/devices/pci0000:00/0000:00:01.2/uevent" pid=23339 comm="qemu-
+ system-x86" requested_mask="r" denied_mask="r" fsuid=64055 ouid=0
+ 
+ 
+ Original bug description
+ ---
+ 
  Operating system: Ubuntu 26.04 LTS
  Architecture: x86_64
  kernel version: Linux ubuntu 7.0.0-28-generic
  libvirt version: 12.0.0
  Hypervisor and version: qemu-system-x86 10.2.1+ds-1ubuntu3.2
  
  Start a VM and attach an usb host device:
  
  virsh attach-device --domain subVmTest1 --file /tmp/usbhostedxml
  Contents of the `/tmp/usbhostedxml`:
  <hostdev mode='subsystem' type='usb'>
    <source>
      <vendor id='0x1d6b'/>
      <product id='0x0001'/>
    </source>
  </hostdev>
  
  AppArmor denial:
  audit: type=1400 audit(1784186108.556:533): apparmor="DENIED" 
operation="open" class="file" 
profile="libvirt-c13c2cda-4558-4fca-9146-9f2f8075d432" 
name="/sys/devices/pci0000:00/0000:00:01.2/uevent" pid=23339 
comm="qemu-system-x86" requested_mask="r" denied_mask="r" fsuid=64055 ouid=0
+ 
+ 
+ [1] vm.xml
+ 
+ <domain type='kvm'>
+   <name>ubuntu-cloud-vm</name>
+   <memory unit='GiB'>2</memory>
+   <currentMemory unit='GiB'>2</currentMemory>
+   <vcpu placement='static'>2</vcpu>
+ 
+   <os>
+     <type arch='x86_64'>hvm</type>
+     <boot dev='hd'/>
+   </os>
+ 
+   <features>
+     <acpi/>
+     <apic/>
+   </features>
+ 
+   <cpu mode='host-passthrough'/>
+   <clock offset='utc'/>
+   
+   <on_poweroff>destroy</on_poweroff>
+   <on_reboot>restart</on_reboot>
+   <on_crash>destroy</on_crash>
+ 
+   <devices>
+     <emulator>/usr/bin/qemu-system-x86_64</emulator>
+ 
+     <!-- Main OS Disk (Ubuntu Cloud Image) -->
+     <disk type='file' device='disk'>
+       <driver name='qemu' type='qcow2'/>
+       <source file='/home/ubuntu/ubuntu-24.04-server-cloudimg-amd64.img'/>
+       <target dev='vda' bus='virtio'/>
+     </disk>
+ 
+     <interface type='user'>
+       <model type='virtio'/>
+     </interface>
+ 
+     <!-- Serial console for 'virsh console' access -->
+     <serial type='pty'>
+       <target port='0'/>
+     </serial>
+     <console type='pty'>
+       <target type='serial' port='0'/>
+     </console>
+ 
+   </devices>
+ </domain>
+ 
+ 
+ [2] dev.xml
+ 
+ <hostdev mode='subsystem' type='usb'>
+   <source>
+     <address bus='1' device='1'/>
+   </source>
+ </hostdev>

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167823

Title:
  AppArmor denies QEMU to read
  /sys/devices/pci0000:00/0000:00:01.2/uevent

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/2167823/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to