apparmor rules block access to uefi info
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Nova Compute Charm |
Fix Released
|
Medium
|
Billy Olsen |
Bug Description
When apparmor is enabled, instances launched using UEFI bootloader fails with errors in the nova compute log indicating that UEFINotSupported as follows:
2022-01-21 18:36:27.711 210601 ERROR nova.compute.
d340dbbe1e3954d
This is due to apparmor denying access to the necessary firmware data, as seen in the kernel log:
Jan 21 18:36:19 juju-2fd326-
To recreate this, set the image to boot with UEFI bootloader:
$ openstack image set --property hw_firmware_
And launch an instance.
Work around is to disable apparmor or put it into complain mode.
Changed in charm-nova-compute: | |
status: | New → In Progress |
importance: | Undecided → High |
importance: | High → Medium |
assignee: | nobody → Billy Olsen (billy-olsen) |
milestone: | none → 22.04 |
description: | updated |
Changed in charm-nova-compute: | |
status: | Fix Committed → Fix Released |
Fix proposed to branch: master /review. opendev. org/c/openstack /charm- nova-compute/ +/826208
Review: https:/