Public bug reported:

During attach new interface to the instance, I have an error (from
dmesg):
    [1387677.245725] audit: type=1400 audit(1550147444.575:10991):
apparmor="DENIED" operation="file_receive" profile="libvirt-fc5b1ccd-
6d5c-459e-8d6b-b98c26df504e" name="/dev/vhost-net" pid=36309 comm="qemu-
system-x86" requested_mask="wr" denied_mask="wr" fsuid=64055 ouid=0


Workaround is adding to: /etc/apparmor.d/abstractions/libvirt-qemu

    /dev/vhost-net rw,


More info:
Error that I get in nova-compute:

libvirtError: internal error: unable to execute QEMU command 'getfd': No
file descriptor supplied via SCM_RIGHTS


Libvirt version: 4.0.0-1ubuntu8.6
Ubuntu release: Bionic

Should libvirt be able to have access to /dev/vhost-net ?

** Affects: libvirt (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1815910

Title:
  Apparmor blocks access to /dev/vhost-net

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1815910/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to