Public bug reported:
[Impact]
Since edk2 2025.11-3ubuntu7.2 (LP: #2160129), 60-edk2-x86_64-amdsev.json
maps OVMF.amdsev.fd with "device": "memory". On Resolute, a UEFI guest that
relies on libvirt firmware autoselection, with Secure Boot disabled and no
per-VM nvram, now selects that descriptor on a non-SEV Intel host. libvirt
uses it as a rom loader, virt-aa-helper rejects the path, and the domain
fails to start with a misleading AppArmor error:
error: Failed to start domain 'lp-repro-efi'
error: internal error: cannot load AppArmor profile
'libvirt-eb9cc8c8-f1f5-427c-9408-1645f8032f08'
libvirtd log:
internal error: Child process (LIBVIRT_LOG_OUTPUTS=3:stderr
/usr/lib/libvirt/virt-aa-helper -c -u
libvirt-eb9cc8c8-f1f5-427c-9408-1645f8032f08)
unexpected exit status 1: virt-aa-helper: error:
/usr/share/ovmf/OVMF.amdsev.fd
virt-aa-helper: error: skipped restricted file
virt-aa-helper: error: invalid VM definition
The guest requests no confidential-computing features. Our production
guests with the same firmware request (UEFI, secure-boot disabled, no
nvram) started normally before 7.2; failures began with the 7.2 upgrade.
Still reproduces with edk2 2025.11-3ubuntu7.3 and libvirt
12.0.0-1ubuntu5.5 (current resolute-updates).
[Test Plan]
On a non-SEV x86_64 host with the 7.2 descriptor installed:
1. Define the attached repro.xml (os firmware='efi', secure-boot
disabled, no nvram element, no disk):
virsh define repro.xml
2. virsh dumpxml lp-repro-efi | grep loader
-> <loader type='rom' format='raw'>/usr/share/ovmf/OVMF.amdsev.fd</loader>
3. virsh start lp-repro-efi
-> internal error: cannot load AppArmor profile
Expected: the guest starts, as such guests did before 7.2.
[Workaround]
Mask the descriptor using the qemu firmware-descriptor override
directory, then redefine affected domains:
sudo ln -s /dev/null /etc/qemu/firmware/60-edk2-x86_64-amdsev.json
[Notes]
Possible fixes:
- virt-aa-helper allows read access to memory-mapped (stateless) loaders, or
- autoselection does not pick SEV/TDX builds for guests that request no
launch security.
60-edk2-x86_64-inteltdx.json is also mapped "device": "memory"
(OVMF.inteltdx.ms.fd) and may hit the same path for secure-boot guests
without nvram; not tested.
Versions:
Ubuntu 26.04.1 LTS
ovmf 2025.11-3ubuntu7.3
ovmf-amdsev 2025.11-3ubuntu7.3
qemu-system-x86 1:10.2.1+ds-1ubuntu3.2
libvirt-daemon-system 12.0.0-1ubuntu5.5
apparmor 5.0.2-0ubuntu1~26.04.1
Related: LP: #2160129 (the SRU that changed the mapping; verified on an
AMD SEV-SNP host, where the memory mapping is intended).
** Affects: libvirt (Ubuntu)
Importance: Undecided
Status: New
** Tags: regression-update
** Attachment added: "repro.xml"
https://bugs.launchpad.net/bugs/2169887/+attachment/6006915/+files/repro.xml
** Tags added: regression-update
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169887
Title:
UEFI guests without nvram fail to start after edk2 2025.11-3ubuntu7.2:
autoselect picks memory-mapped amdsev firmware, virt-aa-helper rejects
it
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/2169887/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs