virt-aa-helper denied messages with lvm volumes

Bug #565691 reported by earl
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
libvirt (Ubuntu)
Fix Released
Low
Jamie Strandboge
Lucid
Fix Released
Low
Jamie Strandboge

Bug Description

Binary package: libvirt-bin 0.7.5-5ubuntu25

Along the lines of the similar issue with eucalyptus disks:

virt-aa-helper checks disks to see if they have a backing store. The AppArmor profile for virt-aa-helper doesn't take into account paths of lvm volumes (/dev/mapper/*), so kern.log contains a bunch of non-fatal, but confusing denied messages:

kernel: [84488.601042] type=1503 audit(1271551329.109:25): operation="open" pid=32613 parent=27119 profile="/usr/lib/libvirt/virt-aa-helper" requested_mask="r::" denied_mask="r::" fsuid=0 ouid=0 name="/dev/mapper/vg0-vm.example.com"

Tags: apparmor

Related branches

earl (xearl)
description: updated
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thanks for reporting this and helping to make Ubuntu better. We can fix this in an SRU for lucid.

Changed in libvirt (Ubuntu):
importance: Undecided → Low
milestone: none → lucid-updates
status: New → Triaged
assignee: nobody → Jamie Strandboge (jdstrand)
Changed in libvirt (Ubuntu Lucid):
status: Triaged → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package libvirt - 0.7.5-5ubuntu26

---------------
libvirt (0.7.5-5ubuntu26) lucid; urgency=low

  * debian/patches/9022-dont-leak-log-fd.path.patch: Fix FD leak in
    qemudStartVMDaemon (LP: #567392)
  * debian/apparmor/usr.lib.libvirt.virt-aa-helper: update paths for LVM
    volumes and searching /sys/bus/usb/devices/ (LP: #565691)
 -- Jamie Strandboge <email address hidden> Tue, 20 Apr 2010 13:45:12 -0500

Changed in libvirt (Ubuntu Lucid):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.