On 9/29/26 01:07, Hector Cao via Devel wrote:
From: Hector Cao <hector.cao@canonical.com>
Attaching a USB device as a <hostdev> fails under the libvirt-qemu AppArmor profile because QEMU (via libusb) walks up the sysfs topology of the passed-through device and reads the uevent file of the parent USB host controller, which is a PCI (or platform) device that lives one level above the usb[0-9]* directory:
/sys/devices/pci0000:00/0000:00:01.2/uevent
The existing rule only grants read access to everything *under* a usb[0-9]* directory:
/sys/devices/**/usb[0-9]*/** r,
so the controller's uevent, which sits above usb[0-9]*, is not covered and the access is denied:
apparmor="DENIED" operation="open" class="file" profile="libvirt-<uuid>" name="/sys/devices/pci0000:00/0000:00:01.2/uevent" comm="qemu-system-x86" requested_mask="r" denied_mask="r"
uevent files only expose non-sensitive device metadata (driver name, modalias, PCI IDs, DEVTYPE, etc.), so grant read access to uevent files across the device tree might be acceptable. This is enough to let USB hostdev attach and hotplug succeed without broadening access to any other sysfs attribute.
Signed-off-by: Hector Cao <hector.cao@canonical.com> --- src/security/apparmor/libvirt-qemu | 6 ++++++ 1 file changed, 6 insertions(+)
Reviewed-by: Michal Privoznik <mprivozn@redhat.com> and merged. Michal