Public bug reported:

[Impact]

Since edk2 2025.11-3ubuntu7.2 (LP: #2160129), 60-edk2-x86_64-amdsev.json
maps OVMF.amdsev.fd with "device": "memory". On Resolute, a UEFI guest that
relies on libvirt firmware autoselection, with Secure Boot disabled and no
per-VM nvram, now selects that descriptor on a non-SEV Intel host. libvirt
uses it as a rom loader, virt-aa-helper rejects the path, and the domain
fails to start with a misleading AppArmor error:

  error: Failed to start domain 'lp-repro-efi'
  error: internal error: cannot load AppArmor profile 
'libvirt-eb9cc8c8-f1f5-427c-9408-1645f8032f08'

libvirtd log:

  internal error: Child process (LIBVIRT_LOG_OUTPUTS=3:stderr
  /usr/lib/libvirt/virt-aa-helper -c -u 
libvirt-eb9cc8c8-f1f5-427c-9408-1645f8032f08)
  unexpected exit status 1: virt-aa-helper: error: 
/usr/share/ovmf/OVMF.amdsev.fd
  virt-aa-helper: error: skipped restricted file
  virt-aa-helper: error: invalid VM definition

The guest requests no confidential-computing features. Our production
guests with the same firmware request (UEFI, secure-boot disabled, no
nvram) started normally before 7.2; failures began with the 7.2 upgrade.

Still reproduces with edk2 2025.11-3ubuntu7.3 and libvirt
12.0.0-1ubuntu5.5 (current resolute-updates).

[Test Plan]

On a non-SEV x86_64 host with the 7.2 descriptor installed:

1. Define the attached repro.xml (os firmware='efi', secure-boot
   disabled, no nvram element, no disk):
     virsh define repro.xml
2. virsh dumpxml lp-repro-efi | grep loader
     -> <loader type='rom' format='raw'>/usr/share/ovmf/OVMF.amdsev.fd</loader>
3. virsh start lp-repro-efi
     -> internal error: cannot load AppArmor profile

Expected: the guest starts, as such guests did before 7.2.

[Workaround]

Mask the descriptor using the qemu firmware-descriptor override
directory, then redefine affected domains:

  sudo ln -s /dev/null /etc/qemu/firmware/60-edk2-x86_64-amdsev.json

[Notes]

Possible fixes:
- virt-aa-helper allows read access to memory-mapped (stateless) loaders, or
- autoselection does not pick SEV/TDX builds for guests that request no
  launch security.

60-edk2-x86_64-inteltdx.json is also mapped "device": "memory"
(OVMF.inteltdx.ms.fd) and may hit the same path for secure-boot guests
without nvram; not tested.

Versions:
  Ubuntu 26.04.1 LTS
  ovmf 2025.11-3ubuntu7.3
  ovmf-amdsev 2025.11-3ubuntu7.3
  qemu-system-x86 1:10.2.1+ds-1ubuntu3.2
  libvirt-daemon-system 12.0.0-1ubuntu5.5
  apparmor 5.0.2-0ubuntu1~26.04.1

Related: LP: #2160129 (the SRU that changed the mapping; verified on an
AMD SEV-SNP host, where the memory mapping is intended).

** Affects: libvirt (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: regression-update

** Attachment added: "repro.xml"
   https://bugs.launchpad.net/bugs/2169887/+attachment/6006915/+files/repro.xml

** Tags added: regression-update

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169887

Title:
  UEFI guests without nvram fail to start after edk2 2025.11-3ubuntu7.2:
  autoselect picks memory-mapped amdsev firmware, virt-aa-helper rejects
  it

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/2169887/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to