From: Hector Cao <[email protected]> Attaching a USB device as a <hostdev> fails under the libvirt-qemu AppArmor profile because QEMU (via libusb) walks up the sysfs topology of the passed-through device and reads the uevent file of the parent USB host controller, which is a PCI (or platform) device that lives one level above the usb[0-9]* directory:
/sys/devices/pci0000:00/0000:00:01.2/uevent The existing rule only grants read access to everything *under* a usb[0-9]* directory: /sys/devices/**/usb[0-9]*/** r, so the controller's uevent, which sits above usb[0-9]*, is not covered and the access is denied: apparmor="DENIED" operation="open" class="file" profile="libvirt-<uuid>" name="/sys/devices/pci0000:00/0000:00:01.2/uevent" comm="qemu-system-x86" requested_mask="r" denied_mask="r" uevent files only expose non-sensitive device metadata (driver name, modalias, PCI IDs, DEVTYPE, etc.), so grant read access to uevent files across the device tree might be acceptable. This is enough to let USB hostdev attach and hotplug succeed without broadening access to any other sysfs attribute. Signed-off-by: Hector Cao <[email protected]> --- src/security/apparmor/libvirt-qemu | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/src/security/apparmor/libvirt-qemu b/src/security/apparmor/libvirt-qemu index 428f9a9731..9bf572692b 100644 --- a/src/security/apparmor/libvirt-qemu +++ b/src/security/apparmor/libvirt-qemu @@ -45,6 +45,12 @@ /sys/bus/usb/devices/ r, /sys/bus/usb/devices/* r, /sys/devices/**/usb[0-9]*/** r, + # For USB hostdev access, QEMU (via libusb) walks up the sysfs topology + # of the passed-through device and reads the uevent of the parent USB + # host controller, which sits one level above the usb[0-9]* directory + # (e.g. /sys/devices/pci0000:00/0000:00:01.2/uevent). uevent files only + # expose non-sensitive device metadata. + /sys/devices/**/uevent r, # libusb needs udev data about usb devices (~equal to content of lsusb -v) /run/udev/data/+usb* r, /run/udev/data/c16[6,7]* r, -- 2.43.0
