** Description changed: + [ Impact ] + + Attaching or hot-plugging a USB device to a guest as a <hostdev> fails under + the default libvirt-qemu AppArmor confinement. + + When QEMU (via libusb) sets up a passed-through USB device, it walks up the + sysfs topology of the device and reads the "uevent" file of the parent USB + host controller. That controller is a PCI (or platform) device that lives one + level *above* the usb[0-9]* directory, e.g.: + + /sys/devices/pci0000:00/0000:00:01.2/uevent + + The existing AppArmor rule only grants read access to everything *under* a + usb[0-9]* directory: + + /sys/devices/**/usb[0-9]*/** r, + + The parent controller's uevent sits above usb[0-9]* and is therefore not + covered, so the access is denied: + + apparmor="DENIED" operation="open" class="file" + profile="libvirt-<uuid>" + name="/sys/devices/pci0000:00/0000:00:01.2/uevent" + comm="qemu-system-x86" requested_mask="r" denied_mask="r" + + As a result USB <hostdev> attach/hotplug does not work out of the box. + + [ Test Plan ] + + On an affected release: + + 1) Start a VM, e.g. from an Ubuntu cloud image: + $ virsh start <vm> + $ virsh list + + 2) Prepare a USB hostdev definition /tmp/dev.xml (tune the address/IDs to a + USB device present on the host), for example: + + <hostdev mode='subsystem' type='usb'> + <source> + <vendor id='0x1d6b'/> + <product id='0x0001'/> + </source> + </hostdev> + + 3) Attach the device: + $ virsh attach-device --domain <vm> --file /tmp/dev.xml + + Before the fix: + - The command fails (or the device is not usable in the guest) and dmesg / + the audit log shows an AppArmor DENIED entry for + /sys/devices/.../uevent (see [ Impact ]). + + After the fix: + - "Device attached successfully" is reported, the device shows up inside + the guest (e.g. `lsusb` lists it), and no new AppArmor DENIED entries + referencing a uevent file appear in dmesg / the audit log. + + [ Where problems could occur ] + + The change only adds a single read-only AppArmor rule: + + /sys/devices/**/uevent r, + + to the libvirt-qemu profile, granting QEMU read access to sysfs uevent + files across the device tree. uevent files only expose non-sensitive device + metadata (driver name, modalias, PCI IDs, DEVTYPE, etc.), so the widened + access is limited to that metadata and does not grant access to any other + sysfs attribute. + + Any regression would be confined to AppArmor confinement of QEMU processes + started by libvirt: + - In the unlikely event the rule were malformed, the libvirt-qemu profile + could fail to load/reload, which would be immediately visible at guest + start. The rule has been validated by loading the profile and successfully + starting guests. + - The rule only broadens read access; it cannot cause previously-working + functionality to be denied. + + Users who have locally customised the libvirt-qemu AppArmor profile will get + the standard conffile-merge prompt on upgrade, as usual. + + [ Other Info ] + + * Noble (24.04) is not affected: USB hostdev attach already succeeds there. + * Forwarded upstream: + - https://gitlab.com/libvirt/libvirt/-/work_items/896 + - https://lists.libvirt.org/archives/list/[email protected]/thread/STRKGEF4HSYTDAZHBEUQADPM3S4IIGHN/ + * Fix carried as: + d/p/ubuntu-aa/lp2167823-apparmor-allow-reading-uevent-for-usb-hostdev.patch + + ---- + 1) Download a Ubuntu Cloud Image - $ wget https://cloud-images.ubuntu.com/noble/current/noble-server-cloudimg-amd64.img - and start a VM with virsh from the domain definition [2] + $ wget https://cloud-images.ubuntu.com/noble/current/noble-server-cloudimg-amd64.img + and start a VM with virsh from the domain definition [2] 2) Check VM running with: - $ virsh list + $ virsh list 3) virsh attach-device --domain ubuntu-cloud-vm --file dev.xml dev.xml contains an example of the USB the device, it usually works on all PC - but if that does not, please tune it for the host system you are testing on. + but if that does not, please tune it for the host system you are testing on. Access denied: (this is an exemple of the dmesg log message) audit: type=1400 audit(1784186108.556:533): apparmor="DENIED" operation="open" class="file" profile="libvirt-c13c2cda-4558-4fca-9146-9f2f8075d432" name="/sys/devices/pci0000:00/0000:00:01.2/uevent" pid=23339 comm="qemu- system-x86" requested_mask="r" denied_mask="r" fsuid=64055 ouid=0 - Original bug description --- Operating system: Ubuntu 26.04 LTS Architecture: x86_64 kernel version: Linux ubuntu 7.0.0-28-generic libvirt version: 12.0.0 Hypervisor and version: qemu-system-x86 10.2.1+ds-1ubuntu3.2 Start a VM and attach an usb host device: virsh attach-device --domain subVmTest1 --file /tmp/usbhostedxml Contents of the `/tmp/usbhostedxml`: <hostdev mode='subsystem' type='usb'> <source> <vendor id='0x1d6b'/> <product id='0x0001'/> </source> </hostdev> AppArmor denial: audit: type=1400 audit(1784186108.556:533): apparmor="DENIED" operation="open" class="file" profile="libvirt-c13c2cda-4558-4fca-9146-9f2f8075d432" name="/sys/devices/pci0000:00/0000:00:01.2/uevent" pid=23339 comm="qemu-system-x86" requested_mask="r" denied_mask="r" fsuid=64055 ouid=0 - [1] vm.xml <domain type='kvm'> - <name>ubuntu-cloud-vm</name> - <memory unit='GiB'>2</memory> - <currentMemory unit='GiB'>2</currentMemory> - <vcpu placement='static'>2</vcpu> + <name>ubuntu-cloud-vm</name> + <memory unit='GiB'>2</memory> + <currentMemory unit='GiB'>2</currentMemory> + <vcpu placement='static'>2</vcpu> - <os> - <type arch='x86_64'>hvm</type> - <boot dev='hd'/> - </os> + <os> + <type arch='x86_64'>hvm</type> + <boot dev='hd'/> + </os> - <features> - <acpi/> - <apic/> - </features> + <features> + <acpi/> + <apic/> + </features> - <cpu mode='host-passthrough'/> - <clock offset='utc'/> - - <on_poweroff>destroy</on_poweroff> - <on_reboot>restart</on_reboot> - <on_crash>destroy</on_crash> + <cpu mode='host-passthrough'/> + <clock offset='utc'/> - <devices> - <emulator>/usr/bin/qemu-system-x86_64</emulator> + <on_poweroff>destroy</on_poweroff> + <on_reboot>restart</on_reboot> + <on_crash>destroy</on_crash> - <!-- Main OS Disk (Ubuntu Cloud Image) --> - <disk type='file' device='disk'> - <driver name='qemu' type='qcow2'/> - <source file='/home/ubuntu/ubuntu-24.04-server-cloudimg-amd64.img'/> - <target dev='vda' bus='virtio'/> - </disk> + <devices> + <emulator>/usr/bin/qemu-system-x86_64</emulator> - <interface type='user'> - <model type='virtio'/> - </interface> + <!-- Main OS Disk (Ubuntu Cloud Image) --> + <disk type='file' device='disk'> + <driver name='qemu' type='qcow2'/> + <source file='/home/ubuntu/ubuntu-24.04-server-cloudimg-amd64.img'/> + <target dev='vda' bus='virtio'/> + </disk> - <!-- Serial console for 'virsh console' access --> - <serial type='pty'> - <target port='0'/> - </serial> - <console type='pty'> - <target type='serial' port='0'/> - </console> + <interface type='user'> + <model type='virtio'/> + </interface> - </devices> + <!-- Serial console for 'virsh console' access --> + <serial type='pty'> + <target port='0'/> + </serial> + <console type='pty'> + <target type='serial' port='0'/> + </console> + + </devices> </domain> - [2] dev.xml <hostdev mode='subsystem' type='usb'> - <source> - <address bus='1' device='1'/> - </source> + <source> + <address bus='1' device='1'/> + </source> </hostdev>
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2167823 Title: AppArmor denies QEMU to read /sys/devices/pci0000:00/0000:00:01.2/uevent To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/2167823/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
