]> git.ipfire.org Git - thirdparty/libvirt.git/commitdiff
apparmor: allow unmounting .dev entries
authorChristian Ehrhardt <christian.ehrhardt@canonical.com>
Fri, 7 Aug 2020 07:05:04 +0000 (09:05 +0200)
committerChristian Ehrhardt <christian.ehrhardt@canonical.com>
Thu, 13 Aug 2020 10:52:45 +0000 (12:52 +0200)
With qemu 5.0 and libvirt 6.6 there are new apparmor denials:
  apparmor="DENIED" operation="umount" profile="libvirtd"
  name="/run/libvirt/qemu/1-kvmguest-groovy-norm.dev/" comm="rpc-worker"

These are related to new issues around devmapper handling [1] and the
error path triggered by these issues now causes this new denial.

There are already related rules for mounting and it seems right to
allow also the related umount.

[1]: https://www.redhat.com/archives/libvir-list/2020-August/msg00236.html

Signed-off-by: Christian Ehrhardt <christian.ehrhardt@canonical.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
src/security/apparmor/usr.sbin.libvirtd.in

index 312fa4b6d1d565cceb866ce639765d37149ac3b8..4518e8f865dc302b7791f0d33f67710d08079d01 100644 (file)
@@ -31,6 +31,7 @@ profile libvirtd @sbindir@/libvirtd flags=(attach_disconnected) {
 
   mount options=(rw,rslave)  -> /,
   mount options=(rw, nosuid) -> /{var/,}run/libvirt/qemu/*.dev/,
+  umount /{var/,}run/libvirt/qemu/*.dev/,
 
   # libvirt provides any mounts under /dev to qemu namespaces
   mount options=(rw, move) /dev/ -> /{,var/}run/libvirt/qemu/*.dev/,