Hi,
bug 1320221 is about virt-aa-helper being denied which is different.
A dup of 1417288 it might be, but that is so old that I'd not want to wake it 
up :-)


> "It appears to me that whatever generates the .files listing should consider 
> derived names ..."

Yeah for some scenarios that is correct and for others it would be a truly evil 
security hole.
What I'd want in this case is to allow you to add rules per-guest which stay 
across restarts of the guest and without e.g. aa-enforce that you needed. That 
is implemented in new version by me via bug 1745114 (>=Groovy). Until then your 
script seems a complex but valid workaround.


The question that remains is if libvirt should have issued a labeling call for 
this file that would have added a rule to allow that filename. Also the fact 
that using spaces changes the behavior so drastically seems odd. I'd need to 
debug the case but am very busy atm.
I'll keep it open and hope to get into it some-when the next few days.

** Changed in: libvirt (Ubuntu)
     Assignee: (unassigned) => Christian Ehrhardt  (paelzer)

** Tags added: server-next

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1892306

Title:
  virsh snapshot-create-as fails when --disk-only is specified

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1892306/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to