From: Hector Cao <[email protected]>

Attaching a USB device as a <hostdev> fails under the libvirt-qemu
AppArmor profile because QEMU (via libusb) walks up the sysfs topology
of the passed-through device and reads the uevent file of the parent USB
host controller, which is a PCI (or platform) device that lives one
level above the usb[0-9]* directory:

  /sys/devices/pci0000:00/0000:00:01.2/uevent

The existing rule only grants read access to everything *under* a
usb[0-9]* directory:

  /sys/devices/**/usb[0-9]*/** r,

so the controller's uevent, which sits above usb[0-9]*, is not covered
and the access is denied:

  apparmor="DENIED" operation="open" class="file"
  profile="libvirt-<uuid>"
  name="/sys/devices/pci0000:00/0000:00:01.2/uevent"
  comm="qemu-system-x86" requested_mask="r" denied_mask="r"

uevent files only expose non-sensitive device metadata
(driver name, modalias, PCI IDs, DEVTYPE, etc.), so grant
read access to uevent files across the device tree might
be acceptable. This is enough to let USB hostdev attach and
hotplug succeed without broadening access to any other sysfs
attribute.

Signed-off-by: Hector Cao <[email protected]>
---
 src/security/apparmor/libvirt-qemu | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/src/security/apparmor/libvirt-qemu 
b/src/security/apparmor/libvirt-qemu
index 428f9a9731..9bf572692b 100644
--- a/src/security/apparmor/libvirt-qemu
+++ b/src/security/apparmor/libvirt-qemu
@@ -45,6 +45,12 @@
   /sys/bus/usb/devices/ r,
   /sys/bus/usb/devices/* r,
   /sys/devices/**/usb[0-9]*/** r,
+  # For USB hostdev access, QEMU (via libusb) walks up the sysfs topology
+  # of the passed-through device and reads the uevent of the parent USB
+  # host controller, which sits one level above the usb[0-9]* directory
+  # (e.g. /sys/devices/pci0000:00/0000:00:01.2/uevent). uevent files only
+  # expose non-sensitive device metadata.
+  /sys/devices/**/uevent r,
   # libusb needs udev data about usb devices (~equal to content of lsusb -v)
   /run/udev/data/+usb* r,
   /run/udev/data/c16[6,7]* r,
-- 
2.43.0

Reply via email to