[regression] apparmor profile not updated on attach and detach of devices
Bug #435527 reported by
Jamie Strandboge
This bug affects 2 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
libvirt (Ubuntu) |
Fix Released
|
High
|
Jamie Strandboge |
Bug Description
bug #432154 (in kvm) masked the fact that the AppArmor libvirt integration did not allow for attaching and detaching of devices. This is a regression over Jaunty and required for eucalyptus and attached storage (ie AOE).
Related branches
Changed in libvirt (Ubuntu): | |
assignee: | nobody → Jamie Strandboge (jdstrand) |
importance: | Undecided → High |
milestone: | none → ubuntu-9.10-beta |
status: | New → In Progress |
tags: | added: regression-potential |
description: | updated |
To post a comment you must log in.
This bug was fixed in the package libvirt - 0.7.0-1ubuntu8
---------------
libvirt (0.7.0-1ubuntu8) karmic; urgency=low
* debian/ patches/ 9091-apparmor. patch: sync with upstream for maintenance, aa-helper- test script apparmor/ usr.sbin. libvirtd: add various capabilities
licensing compliance with upstream and bug fixes:
- handle files with spaces in the name (LP: #432810)
- add serial, console, kernel and initrd support (LP: #432581)
- allow read only access to /boot, /vmlinuz and /initrd.img
- allow access to character devices (eg USB devices)
- have virt-aa-helper accept XML on stdin, which allows for adding
other devices in the future and helps ensure we always have the most
up to date definition
- update profile on attach and detach of devices (LP: #435527)
- add --dryrun option to virt-aa-helper, and greatly improve the
virt-
* revert workaround for LP: #431090 now that kernel, initrd, et al is
properly supported
* debian/
recommended by upstream to prevent potential regressions
-- Jamie Strandboge <email address hidden> Tue, 22 Sep 2009 20:04:58 -0500