On 9/29/26 01:07, Hector Cao via Devel wrote: > From: Hector Cao <[email protected]> > > Attaching a USB device as a <hostdev> fails under the libvirt-qemu > AppArmor profile because QEMU (via libusb) walks up the sysfs topology > of the passed-through device and reads the uevent file of the parent USB > host controller, which is a PCI (or platform) device that lives one > level above the usb[0-9]* directory: > > /sys/devices/pci0000:00/0000:00:01.2/uevent > > The existing rule only grants read access to everything *under* a > usb[0-9]* directory: > > /sys/devices/**/usb[0-9]*/** r, > > so the controller's uevent, which sits above usb[0-9]*, is not covered > and the access is denied: > > apparmor="DENIED" operation="open" class="file" > profile="libvirt-<uuid>" > name="/sys/devices/pci0000:00/0000:00:01.2/uevent" > comm="qemu-system-x86" requested_mask="r" denied_mask="r" > > uevent files only expose non-sensitive device metadata > (driver name, modalias, PCI IDs, DEVTYPE, etc.), so grant > read access to uevent files across the device tree might > be acceptable. This is enough to let USB hostdev attach and > hotplug succeed without broadening access to any other sysfs > attribute. > > Signed-off-by: Hector Cao <[email protected]> > --- > src/security/apparmor/libvirt-qemu | 6 ++++++ > 1 file changed, 6 insertions(+) >
Reviewed-by: Michal Privoznik <[email protected]> and merged. Michal
