From b2bf7c00b79de032bd7eeb6ba9c970895223a53f Mon Sep 17 00:00:00 2001 Message-Id: In-Reply-To: References: From: Mike Latimer Date: Mon, 19 Jan 2015 17:12:33 -0700 Subject: [PATCH 2/3] Grant access to helpers Apparmor must not prevent access to required helper programs. The following helpers should be allowed to run in unconfined execution mode: - libvirt_parthelper - libvirt_iohelper --- examples/apparmor/usr.sbin.libvirtd | 2 ++ 1 file changed, 2 insertions(+) diff --git a/examples/apparmor/usr.sbin.libvirtd b/examples/apparmor/usr.sbin.libvirtd index 9917836..ab6572a 100644 --- a/examples/apparmor/usr.sbin.libvirtd +++ b/examples/apparmor/usr.sbin.libvirtd @@ -57,6 +57,8 @@ audit deny /sys/kernel/security/apparmor/.* rwxl, /sys/kernel/security/apparmor/profiles r, /usr/{lib,lib64}/libvirt/* PUxr, + /usr/{lib,lib64}/libvirt/libvirt_parthelper Ux, + /usr/{lib,lib64}/libvirt/libvirt_iohelper Ux, /etc/libvirt/hooks/** rmix, /etc/xen/scripts/** rmix, -- 1.8.4.5