File 4f2811eb-apparmor-new-libvirtd-caps.patch of Package libvirt
34
1
commit 4f2811eb816ed1da215b86778dfcf483917666a1
2
Author: Jim Fehlig <jfehlig@suse.com>
3
Date: Mon Jun 7 16:21:28 2021 -0600
4
5
apparmor: Permit new capabilities required by libvirtd
6
7
The audit log contains the following denials from libvirtd
8
9
apparmor="DENIED" operation="capable" profile="libvirtd" pid=6012 comm="daemon-init" capability=17 capname="sys_rawio"
10
apparmor="DENIED" operation="capable" profile="libvirtd" pid=6012 comm="rpc-worker" capability=39 capname="bpf"
11
apparmor="DENIED" operation="capable" profile="libvirtd" pid=6012 comm="rpc-worker" capability=38 capname="perfmon"
12
13
Squelch the denials and allow the capabilities in the libvirtd
14
apparmor profile.
15
16
Signed-off-by: Jim Fehlig <jfehlig@suse.com>
17
Reviewed-by: Neal Gompa <ngompa13@gmail.com>
18
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
19
20
Index: libvirt-7.1.0/src/security/apparmor/usr.sbin.libvirtd.in
21
===================================================================
22
--- libvirt-7.1.0.orig/src/security/apparmor/usr.sbin.libvirtd.in
23
+++ libvirt-7.1.0/src/security/apparmor/usr.sbin.libvirtd.in
24
25
capability fsetid,
26
capability audit_write,
27
capability ipc_lock,
28
+ capability sys_rawio,
29
+ capability bpf,
30
+ capability perfmon,
31
32
# Needed for vfio
33
capability sys_resource,
34