qemu-bridge-helper fails due to apparmor blocks
Bug #1754871 reported by
Toni Spets
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
libvirt (Ubuntu) |
Fix Released
|
Low
|
Unassigned |
Bug Description
The qemu-bridge-helper binary provided in qemu-system-common has at least two issues:
1. it's not setuid root
2. it doesn't have proper apparmor profile
Trying to use the bridge helper as a regular user will fail unless I set the setuid bit after every package upgrade and tear down the apparmor profiles. I'm probably the only one using it but it would be nice if worked since it's part of the package.
The setuid bit is probably an upstream issue from Debian but the apparmor issue is likely Ubuntu specific.
I'm on Ubuntu 18.04 and the qemu packages are 1:2.11+
To post a comment you must log in.
Correct, it's not suid root because of security concerns, according to this changelog entry from verison 2.1+dfsg-3:
* include /usr/lib/ qemu-bridge- helper binary, but not make it setuid
due to security concerns outlined in #691138 (Closes: #691138)
https:/ /bugs.debian. org/cgi- bin/bugreport. cgi?bug= 691138: "qemu-bridge-helper is not packaged"
I'll subscribe @paelzer for further commenting.