** Description changed: [ Impact ] Attaching or hot-plugging a USB device to a guest as a <hostdev> fails under the default libvirt-qemu AppArmor confinement. - When QEMU (via libusb) sets up a passed-through USB device, it walks up the - sysfs topology of the device and reads the "uevent" file of the parent USB - host controller. That controller is a PCI (or platform) device that lives one - level *above* the usb[0-9]* directory, e.g.: - - /sys/devices/pci0000:00/0000:00:01.2/uevent - The existing AppArmor rule only grants read access to everything *under* a usb[0-9]* directory: - /sys/devices/**/usb[0-9]*/** r, + /sys/devices/**/usb[0-9]*/** r, The parent controller's uevent sits above usb[0-9]* and is therefore not covered, so the access is denied: - apparmor="DENIED" operation="open" class="file" - profile="libvirt-<uuid>" - name="/sys/devices/pci0000:00/0000:00:01.2/uevent" - comm="qemu-system-x86" requested_mask="r" denied_mask="r" + apparmor="DENIED" operation="open" class="file" + profile="libvirt-<uuid>" + name="/sys/devices/pci0000:00/0000:00:01.2/uevent" + comm="qemu-system-x86" requested_mask="r" denied_mask="r" As a result USB <hostdev> attach/hotplug does not work out of the box. [ Test Plan ] - On an affected release: + 1) Download a Ubuntu Cloud Image + $ wget https://cloud-images.ubuntu.com/noble/current/noble-server-cloudimg-amd64.img + and start a VM with virsh from the domain definition [2] - 1) Start a VM, e.g. from an Ubuntu cloud image: - $ virsh start <vm> - $ virsh list + 2) Check VM running with: + $ virsh list - 2) Prepare a USB hostdev definition /tmp/dev.xml (tune the address/IDs to a - USB device present on the host), for example: + 3) virsh attach-device --domain ubuntu-cloud-vm --file dev.xml - <hostdev mode='subsystem' type='usb'> - <source> - <vendor id='0x1d6b'/> - <product id='0x0001'/> - </source> - </hostdev> + dev.xml contains an example of the USB the device, it usually works on all PC + but if that does not, please tune it for the host system you are testing on. - 3) Attach the device: - $ virsh attach-device --domain <vm> --file /tmp/dev.xml + A - Before the fix: + ------ - Before the fix: - - The command fails (or the device is not usable in the guest) and dmesg / - the audit log shows an AppArmor DENIED entry for - /sys/devices/.../uevent (see [ Impact ]). + Access denied: + (this is an exemple of the dmesg log message) - After the fix: - - "Device attached successfully" is reported, the device shows up inside - the guest (e.g. `lsusb` lists it), and no new AppArmor DENIED entries - referencing a uevent file appear in dmesg / the audit log. + audit: type=1400 audit(1784186108.556:533): apparmor="DENIED" + operation="open" class="file" + profile="libvirt-c13c2cda-4558-4fca-9146-9f2f8075d432" + name="/sys/devices/pci0000:00/0000:00:01.2/uevent" pid=23339 comm="qemu- + system-x86" requested_mask="r" denied_mask="r" fsuid=64055 ouid=0 + + B - After the fix: + ---- + + No more apparmor access denied warning. + The attach might success or fail (but for other reasons) [ Where problems could occur ] The change only adds a single read-only AppArmor rule: - /sys/devices/**/uevent r, + /sys/devices/**/uevent r, to the libvirt-qemu profile, granting QEMU read access to sysfs uevent files across the device tree. uevent files only expose non-sensitive device metadata (driver name, modalias, PCI IDs, DEVTYPE, etc.), so the widened access is limited to that metadata and does not grant access to any other sysfs attribute. Any regression would be confined to AppArmor confinement of QEMU processes started by libvirt: - - In the unlikely event the rule were malformed, the libvirt-qemu profile - could fail to load/reload, which would be immediately visible at guest - start. The rule has been validated by loading the profile and successfully - starting guests. - - The rule only broadens read access; it cannot cause previously-working - functionality to be denied. - - Users who have locally customised the libvirt-qemu AppArmor profile will get - the standard conffile-merge prompt on upgrade, as usual. + - In the unlikely event the rule were malformed, the libvirt-qemu profile + could fail to load/reload, which would be immediately visible at guest + start. The rule has been validated by loading the profile and successfully + starting guests. + - The rule only broadens read access; it cannot cause previously-working + functionality to be denied. [ Other Info ] - * Noble (24.04) is not affected: USB hostdev attach already succeeds there. - * Forwarded upstream: - - https://gitlab.com/libvirt/libvirt/-/work_items/896 - - https://lists.libvirt.org/archives/list/[email protected]/thread/STRKGEF4HSYTDAZHBEUQADPM3S4IIGHN/ - * Fix carried as: - d/p/ubuntu-aa/lp2167823-apparmor-allow-reading-uevent-for-usb-hostdev.patch + * Noble (24.04) is not affected: USB hostdev attach already succeeds there. + * Forwarded upstream: + - https://gitlab.com/libvirt/libvirt/-/work_items/896 + - https://lists.libvirt.org/archives/list/[email protected]/thread/STRKGEF4HSYTDAZHBEUQADPM3S4IIGHN/ + * Fix carried as: + d/p/ubuntu-aa/lp2167823-apparmor-allow-reading-uevent-for-usb-hostdev.patch ---- 1) Download a Ubuntu Cloud Image $ wget https://cloud-images.ubuntu.com/noble/current/noble-server-cloudimg-amd64.img and start a VM with virsh from the domain definition [2] 2) Check VM running with: $ virsh list 3) virsh attach-device --domain ubuntu-cloud-vm --file dev.xml dev.xml contains an example of the USB the device, it usually works on all PC but if that does not, please tune it for the host system you are testing on. Access denied: (this is an exemple of the dmesg log message) audit: type=1400 audit(1784186108.556:533): apparmor="DENIED" operation="open" class="file" profile="libvirt-c13c2cda-4558-4fca-9146-9f2f8075d432" name="/sys/devices/pci0000:00/0000:00:01.2/uevent" pid=23339 comm="qemu- system-x86" requested_mask="r" denied_mask="r" fsuid=64055 ouid=0 Original bug description --- Operating system: Ubuntu 26.04 LTS Architecture: x86_64 kernel version: Linux ubuntu 7.0.0-28-generic libvirt version: 12.0.0 Hypervisor and version: qemu-system-x86 10.2.1+ds-1ubuntu3.2 Start a VM and attach an usb host device: virsh attach-device --domain subVmTest1 --file /tmp/usbhostedxml Contents of the `/tmp/usbhostedxml`: <hostdev mode='subsystem' type='usb'> <source> <vendor id='0x1d6b'/> <product id='0x0001'/> </source> </hostdev> AppArmor denial: audit: type=1400 audit(1784186108.556:533): apparmor="DENIED" operation="open" class="file" profile="libvirt-c13c2cda-4558-4fca-9146-9f2f8075d432" name="/sys/devices/pci0000:00/0000:00:01.2/uevent" pid=23339 comm="qemu-system-x86" requested_mask="r" denied_mask="r" fsuid=64055 ouid=0 [1] vm.xml <domain type='kvm'> <name>ubuntu-cloud-vm</name> <memory unit='GiB'>2</memory> <currentMemory unit='GiB'>2</currentMemory> <vcpu placement='static'>2</vcpu> <os> <type arch='x86_64'>hvm</type> <boot dev='hd'/> </os> <features> <acpi/> <apic/> </features> <cpu mode='host-passthrough'/> <clock offset='utc'/> <on_poweroff>destroy</on_poweroff> <on_reboot>restart</on_reboot> <on_crash>destroy</on_crash> <devices> <emulator>/usr/bin/qemu-system-x86_64</emulator> <!-- Main OS Disk (Ubuntu Cloud Image) --> <disk type='file' device='disk'> <driver name='qemu' type='qcow2'/> <source file='/home/ubuntu/ubuntu-24.04-server-cloudimg-amd64.img'/> <target dev='vda' bus='virtio'/> </disk> <interface type='user'> <model type='virtio'/> </interface> <!-- Serial console for 'virsh console' access --> <serial type='pty'> <target port='0'/> </serial> <console type='pty'> <target type='serial' port='0'/> </console> </devices> </domain> [2] dev.xml <hostdev mode='subsystem' type='usb'> <source> <address bus='1' device='1'/> </source> </hostdev>
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2167823 Title: AppArmor denies QEMU to read /sys/devices/pci0000:00/0000:00:01.2/uevent To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/2167823/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
