apparmor denies virt-aa-helper access to ecryptfs files
Bug #591769 reported by
Jamie Strandboge
This bug affects 3 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
libvirt (Ubuntu) |
Fix Released
|
Low
|
Jamie Strandboge | ||
Lucid |
Won't Fix
|
Low
|
Unassigned | ||
Maverick |
Fix Released
|
Low
|
Jamie Strandboge |
Bug Description
/etc/apparmor.
owner @{HOME}/.Private/** mrixwlk,
owner @{HOMEDIRS}
This may be too strict for virt-aa-helper since it runs as root and user's may store there VMs in encrypted HOME or encrypted ~/Private with the files owned by the user, not root. The following should be added to /etc/apparmor.
@{HOME}
@{HOMEDIRS}
Related branches
Changed in libvirt (Ubuntu): | |
assignee: | nobody → Jamie Strandboge (jdstrand) |
importance: | Undecided → Medium |
status: | New → Triaged |
Changed in libvirt (Ubuntu Lucid): | |
status: | New → Triaged |
importance: | Undecided → Medium |
assignee: | nobody → Jamie Strandboge (jdstrand) |
milestone: | none → lucid-updates |
Changed in libvirt (Ubuntu Maverick): | |
status: | Triaged → In Progress |
Changed in libvirt (Ubuntu Maverick): | |
milestone: | none → maverick-alpha-2 |
Changed in libvirt (Ubuntu Lucid): | |
assignee: | Jamie Strandboge (jdstrand) → nobody |
To post a comment you must log in.
Reducing to low. The files are still allowed access by the VM, so the apparmor denied message is more confusing than anything else.