apparmor recipe doesn't allow access to /proc/device-tree/ on ppc, so fails to work
Bug #1326851 reported by
Ben Collins
This bug report is a duplicate of:
Bug #1321365: virsh (ppc) fails with "missing /proc/device-tree/cpu ".
Edit
Remove
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
libvirt (Ubuntu) |
Confirmed
|
Critical
|
Unassigned |
Bug Description
The default apparmor recipe should allow "/proc/
To post a comment you must log in.
Here is the failure from syslog:
Jun 5 10:14:21 CTS0015 kernel: [2386259.248034] type=1400 audit(140198126 1.112:21) : apparmor="DENIED" operation="open" profile= "libvirt- 646711db- 3f9c-4db5- ba8d-1a7a502c4a bb" name="/ proc/device- tree/cpus/ " pid=7070 comm="qemu- system- ppc" requested_mask="r" denied_mask="r" fsuid=106 ouid=0
This prevents VMs from working at all, so hence the severity.