** Description changed:

  [ Impact ]
  
  Attaching or hot-plugging a USB device to a guest as a <hostdev> fails under
  the default libvirt-qemu AppArmor confinement.
  
- When QEMU (via libusb) sets up a passed-through USB device, it walks up the
- sysfs topology of the device and reads the "uevent" file of the parent USB
- host controller. That controller is a PCI (or platform) device that lives one
- level *above* the usb[0-9]* directory, e.g.:
- 
-     /sys/devices/pci0000:00/0000:00:01.2/uevent
- 
  The existing AppArmor rule only grants read access to everything *under* a
  usb[0-9]* directory:
  
-     /sys/devices/**/usb[0-9]*/** r,
+     /sys/devices/**/usb[0-9]*/** r,
  
  The parent controller's uevent sits above usb[0-9]* and is therefore not
  covered, so the access is denied:
  
-     apparmor="DENIED" operation="open" class="file"
-     profile="libvirt-<uuid>"
-     name="/sys/devices/pci0000:00/0000:00:01.2/uevent"
-     comm="qemu-system-x86" requested_mask="r" denied_mask="r"
+     apparmor="DENIED" operation="open" class="file"
+     profile="libvirt-<uuid>"
+     name="/sys/devices/pci0000:00/0000:00:01.2/uevent"
+     comm="qemu-system-x86" requested_mask="r" denied_mask="r"
  
  As a result USB <hostdev> attach/hotplug does not work out of the box.
  
  [ Test Plan ]
  
- On an affected release:
+ 1) Download a Ubuntu Cloud Image
+    $ wget 
https://cloud-images.ubuntu.com/noble/current/noble-server-cloudimg-amd64.img
+    and start a VM with virsh from the domain definition [2]
  
- 1) Start a VM, e.g. from an Ubuntu cloud image:
-      $ virsh start <vm>
-      $ virsh list
+ 2) Check VM running with:
+    $ virsh list
  
- 2) Prepare a USB hostdev definition /tmp/dev.xml (tune the address/IDs to a
-    USB device present on the host), for example:
+ 3) virsh attach-device --domain ubuntu-cloud-vm --file dev.xml
  
-      <hostdev mode='subsystem' type='usb'>
-        <source>
-          <vendor id='0x1d6b'/>
-          <product id='0x0001'/>
-        </source>
-      </hostdev>
+ dev.xml contains an example of the USB the device, it usually works on all PC
+ but if that does not, please tune it for the host system you are testing on.
  
- 3) Attach the device:
-      $ virsh attach-device --domain <vm> --file /tmp/dev.xml
+ A - Before the fix:
+ ------
  
- Before the fix:
-  - The command fails (or the device is not usable in the guest) and dmesg /
-    the audit log shows an AppArmor DENIED entry for
-    /sys/devices/.../uevent (see [ Impact ]).
+ Access denied:
+ (this is an exemple of the dmesg log message)
  
- After the fix:
-  - "Device attached successfully" is reported, the device shows up inside
-    the guest (e.g. `lsusb` lists it), and no new AppArmor DENIED entries
-    referencing a uevent file appear in dmesg / the audit log.
+ audit: type=1400 audit(1784186108.556:533): apparmor="DENIED"
+ operation="open" class="file"
+ profile="libvirt-c13c2cda-4558-4fca-9146-9f2f8075d432"
+ name="/sys/devices/pci0000:00/0000:00:01.2/uevent" pid=23339 comm="qemu-
+ system-x86" requested_mask="r" denied_mask="r" fsuid=64055 ouid=0
+ 
+ B - After the fix:
+ ----
+ 
+ No more apparmor access denied warning.
+ The attach might success or fail (but for other reasons)
  
  [ Where problems could occur ]
  
  The change only adds a single read-only AppArmor rule:
  
-     /sys/devices/**/uevent r,
+     /sys/devices/**/uevent r,
  
  to the libvirt-qemu profile, granting QEMU read access to sysfs uevent
  files across the device tree. uevent files only expose non-sensitive device
  metadata (driver name, modalias, PCI IDs, DEVTYPE, etc.), so the widened
  access is limited to that metadata and does not grant access to any other
  sysfs attribute.
  
  Any regression would be confined to AppArmor confinement of QEMU processes
  started by libvirt:
-  - In the unlikely event the rule were malformed, the libvirt-qemu profile
-    could fail to load/reload, which would be immediately visible at guest
-    start. The rule has been validated by loading the profile and successfully
-    starting guests.
-  - The rule only broadens read access; it cannot cause previously-working
-    functionality to be denied.
- 
- Users who have locally customised the libvirt-qemu AppArmor profile will get
- the standard conffile-merge prompt on upgrade, as usual.
+  - In the unlikely event the rule were malformed, the libvirt-qemu profile
+    could fail to load/reload, which would be immediately visible at guest
+    start. The rule has been validated by loading the profile and successfully
+    starting guests.
+  - The rule only broadens read access; it cannot cause previously-working
+    functionality to be denied.
  
  [ Other Info ]
  
-  * Noble (24.04) is not affected: USB hostdev attach already succeeds there.
-  * Forwarded upstream:
-    - https://gitlab.com/libvirt/libvirt/-/work_items/896
-    - 
https://lists.libvirt.org/archives/list/[email protected]/thread/STRKGEF4HSYTDAZHBEUQADPM3S4IIGHN/
-  * Fix carried as:
-    d/p/ubuntu-aa/lp2167823-apparmor-allow-reading-uevent-for-usb-hostdev.patch
+  * Noble (24.04) is not affected: USB hostdev attach already succeeds there.
+  * Forwarded upstream:
+    - https://gitlab.com/libvirt/libvirt/-/work_items/896
+    - 
https://lists.libvirt.org/archives/list/[email protected]/thread/STRKGEF4HSYTDAZHBEUQADPM3S4IIGHN/
+  * Fix carried as:
+    d/p/ubuntu-aa/lp2167823-apparmor-allow-reading-uevent-for-usb-hostdev.patch
  
  ----
  
  1) Download a Ubuntu Cloud Image
     $ wget 
https://cloud-images.ubuntu.com/noble/current/noble-server-cloudimg-amd64.img
     and start a VM with virsh from the domain definition [2]
  
  2) Check VM running with:
     $ virsh list
  
  3) virsh attach-device --domain ubuntu-cloud-vm --file dev.xml
  
  dev.xml contains an example of the USB the device, it usually works on all PC
  but if that does not, please tune it for the host system you are testing on.
  
  Access denied:
  (this is an exemple of the dmesg log message)
  
  audit: type=1400 audit(1784186108.556:533): apparmor="DENIED"
  operation="open" class="file"
  profile="libvirt-c13c2cda-4558-4fca-9146-9f2f8075d432"
  name="/sys/devices/pci0000:00/0000:00:01.2/uevent" pid=23339 comm="qemu-
  system-x86" requested_mask="r" denied_mask="r" fsuid=64055 ouid=0
  
  Original bug description
  ---
  
  Operating system: Ubuntu 26.04 LTS
  Architecture: x86_64
  kernel version: Linux ubuntu 7.0.0-28-generic
  libvirt version: 12.0.0
  Hypervisor and version: qemu-system-x86 10.2.1+ds-1ubuntu3.2
  
  Start a VM and attach an usb host device:
  
  virsh attach-device --domain subVmTest1 --file /tmp/usbhostedxml
  Contents of the `/tmp/usbhostedxml`:
  <hostdev mode='subsystem' type='usb'>
    <source>
      <vendor id='0x1d6b'/>
      <product id='0x0001'/>
    </source>
  </hostdev>
  
  AppArmor denial:
  audit: type=1400 audit(1784186108.556:533): apparmor="DENIED" 
operation="open" class="file" 
profile="libvirt-c13c2cda-4558-4fca-9146-9f2f8075d432" 
name="/sys/devices/pci0000:00/0000:00:01.2/uevent" pid=23339 
comm="qemu-system-x86" requested_mask="r" denied_mask="r" fsuid=64055 ouid=0
  
  [1] vm.xml
  
  <domain type='kvm'>
    <name>ubuntu-cloud-vm</name>
    <memory unit='GiB'>2</memory>
    <currentMemory unit='GiB'>2</currentMemory>
    <vcpu placement='static'>2</vcpu>
  
    <os>
      <type arch='x86_64'>hvm</type>
      <boot dev='hd'/>
    </os>
  
    <features>
      <acpi/>
      <apic/>
    </features>
  
    <cpu mode='host-passthrough'/>
    <clock offset='utc'/>
  
    <on_poweroff>destroy</on_poweroff>
    <on_reboot>restart</on_reboot>
    <on_crash>destroy</on_crash>
  
    <devices>
      <emulator>/usr/bin/qemu-system-x86_64</emulator>
  
      <!-- Main OS Disk (Ubuntu Cloud Image) -->
      <disk type='file' device='disk'>
        <driver name='qemu' type='qcow2'/>
        <source file='/home/ubuntu/ubuntu-24.04-server-cloudimg-amd64.img'/>
        <target dev='vda' bus='virtio'/>
      </disk>
  
      <interface type='user'>
        <model type='virtio'/>
      </interface>
  
      <!-- Serial console for 'virsh console' access -->
      <serial type='pty'>
        <target port='0'/>
      </serial>
      <console type='pty'>
        <target type='serial' port='0'/>
      </console>
  
    </devices>
  </domain>
  
  [2] dev.xml
  
  <hostdev mode='subsystem' type='usb'>
    <source>
      <address bus='1' device='1'/>
    </source>
  </hostdev>

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167823

Title:
  AppArmor denies QEMU to read
  /sys/devices/pci0000:00/0000:00:01.2/uevent

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/2167823/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to