AppArmor DENIES reading of /sys/devices/system/cpu/possible
Bug #1989073 reported by
Marius Vollmer
This bug affects 2 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
apparmor (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned | ||
Kinetic |
Won't Fix
|
Undecided
|
Unassigned |
Bug Description
libvirt 8.6.0-0ubuntu1
apparmor 3.0.7-1ubuntu1
Creating a VM with virt-install produces this AppAmore denial:
AVC apparmor="DENIED" operation="open" profile=
Creation of the VM is successful. This is with nested virtualization.
This did not happen with libvirt 8.0.0-1ubuntu8 and apparmor 3.0.7-1ubuntu1.
tags: | added: kinetic regression-release |
To post a comment you must log in.
Hello,
Thank you for the bug report. I managed to reproduce the apparmor denial once by creating an Ubuntu Kinetic vm with virt-manager, and then running the following commands:
# sudo apt update && sudo apt dist-upgrade -y /releases. ubuntu. com/22. 04.1/ubuntu- 22.04.1- desktop- amd64.iso 22.04.1- desktop- amd64.iso --disk size=10 --memory 2048 \"DENIED\ ""
# sudo apt install apparmor virtinst wget -y
# wget https:/
# virt-install --osinfo ubuntu-lts-latest -c ubuntu-
# sudo dmesg | grep "apparmor=
However, every additional time I attempted to reproduce the denial I was unable to, even when creating a new base virtual machine. Does the denial appear for you every time?
If you could also add the specific virt-install parameters to this bug report too that may help.
Thanks!