This is interesting. The apparmor policy includes the rule:
owner /run/shm/spice.* rw
/dev/shm is a symlink to /run/shm, so you should have the
needed permissions. Could you please show the results of
ls -ld /run/shm /dev/shm
ls -l /run/shm /dev/shm
status: incomplete
** Changed in: qemu
Seems to be an apparmor problem, given this kernel message:
[18863.831346] audit: type=1400 audit(1409779637.619:110):
apparmor=DENIED operation=mknod profile=libvirt-a83f3934-2f03-4915
-80fd-67130bcf234b name=/dev/shm/spice.31266 pid=31266 comm=qemu-
system-x86 requested_mask=c denied_mask=c