On 9/29/26 01:07, Hector Cao via Devel wrote:
> From: Hector Cao <[email protected]>
> 
> Attaching a USB device as a <hostdev> fails under the libvirt-qemu
> AppArmor profile because QEMU (via libusb) walks up the sysfs topology
> of the passed-through device and reads the uevent file of the parent USB
> host controller, which is a PCI (or platform) device that lives one
> level above the usb[0-9]* directory:
> 
>   /sys/devices/pci0000:00/0000:00:01.2/uevent
> 
> The existing rule only grants read access to everything *under* a
> usb[0-9]* directory:
> 
>   /sys/devices/**/usb[0-9]*/** r,
> 
> so the controller's uevent, which sits above usb[0-9]*, is not covered
> and the access is denied:
> 
>   apparmor="DENIED" operation="open" class="file"
>   profile="libvirt-<uuid>"
>   name="/sys/devices/pci0000:00/0000:00:01.2/uevent"
>   comm="qemu-system-x86" requested_mask="r" denied_mask="r"
> 
> uevent files only expose non-sensitive device metadata
> (driver name, modalias, PCI IDs, DEVTYPE, etc.), so grant
> read access to uevent files across the device tree might
> be acceptable. This is enough to let USB hostdev attach and
> hotplug succeed without broadening access to any other sysfs
> attribute.
> 
> Signed-off-by: Hector Cao <[email protected]>
> ---
>  src/security/apparmor/libvirt-qemu | 6 ++++++
>  1 file changed, 6 insertions(+)
> 

Reviewed-by: Michal Privoznik <[email protected]>
and merged.

Michal

Reply via email to