missing rules for block-iscsi.so and block-dmg.so
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
libvirt (Ubuntu) |
Fix Released
|
High
|
Unassigned |
Bug Description
The libvirt-qemu policy has:
# for rbd
/etc/
/usr/
# for curl
/usr/
but starting VMs on up to date xenial resulted in:
[114243.449268] audit: type=1400 audit(145747490
[114243.499942] audit: type=1400 audit(145747490
I suggest instead of the above doing:
/usr/
This will work on non-amd64 and will help future proof new helper libs.
tags: | added: apparmor |
Thanks for the suggestion - am rolling this into the next version.