** Description changed:

+ [ Impact ]
+ 
+ Attaching or hot-plugging a USB device to a guest as a <hostdev> fails under
+ the default libvirt-qemu AppArmor confinement.
+ 
+ When QEMU (via libusb) sets up a passed-through USB device, it walks up the
+ sysfs topology of the device and reads the "uevent" file of the parent USB
+ host controller. That controller is a PCI (or platform) device that lives one
+ level *above* the usb[0-9]* directory, e.g.:
+ 
+     /sys/devices/pci0000:00/0000:00:01.2/uevent
+ 
+ The existing AppArmor rule only grants read access to everything *under* a
+ usb[0-9]* directory:
+ 
+     /sys/devices/**/usb[0-9]*/** r,
+ 
+ The parent controller's uevent sits above usb[0-9]* and is therefore not
+ covered, so the access is denied:
+ 
+     apparmor="DENIED" operation="open" class="file"
+     profile="libvirt-<uuid>"
+     name="/sys/devices/pci0000:00/0000:00:01.2/uevent"
+     comm="qemu-system-x86" requested_mask="r" denied_mask="r"
+ 
+ As a result USB <hostdev> attach/hotplug does not work out of the box.
+ 
+ [ Test Plan ]
+ 
+ On an affected release:
+ 
+ 1) Start a VM, e.g. from an Ubuntu cloud image:
+      $ virsh start <vm>
+      $ virsh list
+ 
+ 2) Prepare a USB hostdev definition /tmp/dev.xml (tune the address/IDs to a
+    USB device present on the host), for example:
+ 
+      <hostdev mode='subsystem' type='usb'>
+        <source>
+          <vendor id='0x1d6b'/>
+          <product id='0x0001'/>
+        </source>
+      </hostdev>
+ 
+ 3) Attach the device:
+      $ virsh attach-device --domain <vm> --file /tmp/dev.xml
+ 
+ Before the fix:
+  - The command fails (or the device is not usable in the guest) and dmesg /
+    the audit log shows an AppArmor DENIED entry for
+    /sys/devices/.../uevent (see [ Impact ]).
+ 
+ After the fix:
+  - "Device attached successfully" is reported, the device shows up inside
+    the guest (e.g. `lsusb` lists it), and no new AppArmor DENIED entries
+    referencing a uevent file appear in dmesg / the audit log.
+ 
+ [ Where problems could occur ]
+ 
+ The change only adds a single read-only AppArmor rule:
+ 
+     /sys/devices/**/uevent r,
+ 
+ to the libvirt-qemu profile, granting QEMU read access to sysfs uevent
+ files across the device tree. uevent files only expose non-sensitive device
+ metadata (driver name, modalias, PCI IDs, DEVTYPE, etc.), so the widened
+ access is limited to that metadata and does not grant access to any other
+ sysfs attribute.
+ 
+ Any regression would be confined to AppArmor confinement of QEMU processes
+ started by libvirt:
+  - In the unlikely event the rule were malformed, the libvirt-qemu profile
+    could fail to load/reload, which would be immediately visible at guest
+    start. The rule has been validated by loading the profile and successfully
+    starting guests.
+  - The rule only broadens read access; it cannot cause previously-working
+    functionality to be denied.
+ 
+ Users who have locally customised the libvirt-qemu AppArmor profile will get
+ the standard conffile-merge prompt on upgrade, as usual.
+ 
+ [ Other Info ]
+ 
+  * Noble (24.04) is not affected: USB hostdev attach already succeeds there.
+  * Forwarded upstream:
+    - https://gitlab.com/libvirt/libvirt/-/work_items/896
+    - 
https://lists.libvirt.org/archives/list/[email protected]/thread/STRKGEF4HSYTDAZHBEUQADPM3S4IIGHN/
+  * Fix carried as:
+    d/p/ubuntu-aa/lp2167823-apparmor-allow-reading-uevent-for-usb-hostdev.patch
+ 
+ ----
+ 
  1) Download a Ubuntu Cloud Image
-    $ wget 
https://cloud-images.ubuntu.com/noble/current/noble-server-cloudimg-amd64.img
-    and start a VM with virsh from the domain definition [2]
+    $ wget 
https://cloud-images.ubuntu.com/noble/current/noble-server-cloudimg-amd64.img
+    and start a VM with virsh from the domain definition [2]
  
  2) Check VM running with:
-    $ virsh list
+    $ virsh list
  
  3) virsh attach-device --domain ubuntu-cloud-vm --file dev.xml
  
  dev.xml contains an example of the USB the device, it usually works on all PC
- but if that does not, please tune it for the host system you are testing on. 
+ but if that does not, please tune it for the host system you are testing on.
  
  Access denied:
  (this is an exemple of the dmesg log message)
  
  audit: type=1400 audit(1784186108.556:533): apparmor="DENIED"
  operation="open" class="file"
  profile="libvirt-c13c2cda-4558-4fca-9146-9f2f8075d432"
  name="/sys/devices/pci0000:00/0000:00:01.2/uevent" pid=23339 comm="qemu-
  system-x86" requested_mask="r" denied_mask="r" fsuid=64055 ouid=0
- 
  
  Original bug description
  ---
  
  Operating system: Ubuntu 26.04 LTS
  Architecture: x86_64
  kernel version: Linux ubuntu 7.0.0-28-generic
  libvirt version: 12.0.0
  Hypervisor and version: qemu-system-x86 10.2.1+ds-1ubuntu3.2
  
  Start a VM and attach an usb host device:
  
  virsh attach-device --domain subVmTest1 --file /tmp/usbhostedxml
  Contents of the `/tmp/usbhostedxml`:
  <hostdev mode='subsystem' type='usb'>
    <source>
      <vendor id='0x1d6b'/>
      <product id='0x0001'/>
    </source>
  </hostdev>
  
  AppArmor denial:
  audit: type=1400 audit(1784186108.556:533): apparmor="DENIED" 
operation="open" class="file" 
profile="libvirt-c13c2cda-4558-4fca-9146-9f2f8075d432" 
name="/sys/devices/pci0000:00/0000:00:01.2/uevent" pid=23339 
comm="qemu-system-x86" requested_mask="r" denied_mask="r" fsuid=64055 ouid=0
  
- 
  [1] vm.xml
  
  <domain type='kvm'>
-   <name>ubuntu-cloud-vm</name>
-   <memory unit='GiB'>2</memory>
-   <currentMemory unit='GiB'>2</currentMemory>
-   <vcpu placement='static'>2</vcpu>
+   <name>ubuntu-cloud-vm</name>
+   <memory unit='GiB'>2</memory>
+   <currentMemory unit='GiB'>2</currentMemory>
+   <vcpu placement='static'>2</vcpu>
  
-   <os>
-     <type arch='x86_64'>hvm</type>
-     <boot dev='hd'/>
-   </os>
+   <os>
+     <type arch='x86_64'>hvm</type>
+     <boot dev='hd'/>
+   </os>
  
-   <features>
-     <acpi/>
-     <apic/>
-   </features>
+   <features>
+     <acpi/>
+     <apic/>
+   </features>
  
-   <cpu mode='host-passthrough'/>
-   <clock offset='utc'/>
-   
-   <on_poweroff>destroy</on_poweroff>
-   <on_reboot>restart</on_reboot>
-   <on_crash>destroy</on_crash>
+   <cpu mode='host-passthrough'/>
+   <clock offset='utc'/>
  
-   <devices>
-     <emulator>/usr/bin/qemu-system-x86_64</emulator>
+   <on_poweroff>destroy</on_poweroff>
+   <on_reboot>restart</on_reboot>
+   <on_crash>destroy</on_crash>
  
-     <!-- Main OS Disk (Ubuntu Cloud Image) -->
-     <disk type='file' device='disk'>
-       <driver name='qemu' type='qcow2'/>
-       <source file='/home/ubuntu/ubuntu-24.04-server-cloudimg-amd64.img'/>
-       <target dev='vda' bus='virtio'/>
-     </disk>
+   <devices>
+     <emulator>/usr/bin/qemu-system-x86_64</emulator>
  
-     <interface type='user'>
-       <model type='virtio'/>
-     </interface>
+     <!-- Main OS Disk (Ubuntu Cloud Image) -->
+     <disk type='file' device='disk'>
+       <driver name='qemu' type='qcow2'/>
+       <source file='/home/ubuntu/ubuntu-24.04-server-cloudimg-amd64.img'/>
+       <target dev='vda' bus='virtio'/>
+     </disk>
  
-     <!-- Serial console for 'virsh console' access -->
-     <serial type='pty'>
-       <target port='0'/>
-     </serial>
-     <console type='pty'>
-       <target type='serial' port='0'/>
-     </console>
+     <interface type='user'>
+       <model type='virtio'/>
+     </interface>
  
-   </devices>
+     <!-- Serial console for 'virsh console' access -->
+     <serial type='pty'>
+       <target port='0'/>
+     </serial>
+     <console type='pty'>
+       <target type='serial' port='0'/>
+     </console>
+ 
+   </devices>
  </domain>
- 
  
  [2] dev.xml
  
  <hostdev mode='subsystem' type='usb'>
-   <source>
-     <address bus='1' device='1'/>
-   </source>
+   <source>
+     <address bus='1' device='1'/>
+   </source>
  </hostdev>

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167823

Title:
  AppArmor denies QEMU to read
  /sys/devices/pci0000:00/0000:00:01.2/uevent

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/2167823/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to