[libvirt] [PATCH v2] security: AppArmor profile fixes for swtpm

2019-09-24 Thread Chris Coulson
lock file. Signed-off-by: Chris Coulson --- src/security/virt-aa-helper.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/security/virt-aa-helper.c b/src/security/virt-aa-helper.c index 326cfaf52a..3d7cc32459 100644 --- a/src/security/virt-aa-helper.c +++ b/src/sec

[libvirt] [PATCH] security: AppArmor profile fixes for swtpm

2019-09-16 Thread Chris Coulson
The AppArmor profile generated by virt-aa-helper is too strict for swtpm. This change contains 2 small fixes: - Relax append access to swtpm's log file to permit write access instead. Append access is insufficient because the log is opened with O_CREAT. - Permit swtpm to acquire a lock on its lock