From nobody Mon Aug 24 09:08:42 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) client-ip=38.145.34.151; envelope-from=devel-bounces@lists.libvirt.org; helo=lists.libvirt.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass(p=reject dis=none) header.from=lists.libvirt.org ARC-Seal: i=1; a=rsa-sha256; t=1786453289; cv=none; d=zohomail.com; s=zohoarc; b=VrScUjhRjiAKpqnOtqSE1SjnkYN4p7YNvYmwEhFY9TTgXCWYst7vlHsIe/IdGx49FFviS/FK30LiZUFIWi8A+VvSFrb9ulVkvLzO7CB2wQRRNgkmf9iyJ1xEymlW1AEwJtvy1lqOV00svpDWPwhGKhuGfMvFee7BkOjgyeQtyO4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786453289; h=Content-Transfer-Encoding:Date:Date:From:From:List-Subscribe:List-Post:List-Owner:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:Reply-To:Subject:Subject:To:To:Message-Id:Cc; bh=ou+XAHh1QqyQwgy/+MyzdbhFeomemav/J5akhnAxaqI=; b=Wom5uGQLINZ3K7DRrAbUZciVGDPV1G4GFVkA1MVimHPflyODaMxxTEAQipHTV6AEZY5kjCDDL3icJsv28KrQdVTspwc8Xi+fX2DjOixDyWvvpGrcxRTEbDamjyVPZ9AcXUPsaAaWYLJ2Jy8PM8tHHNVYIZFKgD9R1KQfYN6PUak= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.libvirt.org (lists.libvirt.org [38.145.34.151]) by mx.zohomail.com with SMTPS id 1786453289560968.0326194147268; Tue, 11 Aug 2026 06:01:29 -0700 (PDT) Received: by lists.libvirt.org (Postfix, from userid 993) id 91BFE3F8C6; Tue, 11 Aug 2026 09:01:27 -0400 (EDT) Received: from [172.19.199.10] (unknown [10.16.107.18]) by lists.libvirt.org (Postfix) with ESMTP id 04ED541A2B; Tue, 11 Aug 2026 09:00:36 -0400 (EDT) Received: by lists.libvirt.org (Postfix, from userid 993) id C43A13F35F; Tue, 11 Aug 2026 09:00:27 -0400 (EDT) Received: from smtp-relay-canonical-0.canonical.com (smtp-relay-canonical-0.canonical.com [185.125.188.120]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (3072 bits)) (No client certificate requested) by lists.libvirt.org (Postfix) with ESMTPS id 8489F3F932 for ; Tue, 11 Aug 2026 09:00:05 -0400 (EDT) Received: from localhost.localdomain (1.general.hector.uk.vpn [10.172.192.134]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by smtp-relay-canonical-0.canonical.com (Postfix) with ESMTPSA id A87E53FA39; Tue, 11 Aug 2026 12:52:42 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on lists.libvirt.org X-Spam-Level: X-Spam-Status: No, score=-5.0 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,MAILING_LIST_MULTI,RCVD_IN_DNSWL_MED,SPF_HELO_NONE autolearn=unavailable autolearn_force=no version=4.0.1 X-Greylist: delayed 440 seconds by postgrey-1.37 at lists.libvirt.org; Tue, 11 Aug 2026 09:00:05 EDT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=canonical.com; s=20251003; t=1786452762; bh=ou+XAHh1QqyQwgy/+MyzdbhFeomemav/J5akhnAxaqI=; h=From:To:Subject:Date:Message-ID:MIME-Version; b=cDl+r8pRAEbjpUsHINx6kg24Hr2w/SHn349zMsEbutmu1w5ALVO2AchMTwA/7CoVk ts2AJEmDtwZufdUBVK7/pK7abxiwKk+FVl5Uso+rksvZwN0ABPa+DRVGtesIKgcwGy RLcb0jTeM+jvLo0VVew2FO2PMOrhjsFjGBmoViDuS6z3luOykI58S+0ctAckBJfKUr 7uB7OrzJcO/xw578oL3C9pnbzMfibufQF9CU5K4PuJ+TX7rW1GA2kfvXrba1EwCB84 gtgyqVpp/UD8cPvilHWWXoAMvBBE/SZi+O5tbbmPbxHtzhqnhMWQOjQoSNnjYiDVnM 5lzA3IQGokMN+kwP4exY8sClY7+x5YPh4KaP2E6Rxhf1tUJgpW9n/24CRd100gXE1y s+FmhVXy71g0WHWZ4t2HmBN0Z9V7AboySL4JwpeUilav+9WKQeUSkIW+PbJRu9wLAY 2LsUwUAp4xncmUTkktc4n2h2PROJrCO3lv5WiQpYQn9pnQ/fEGTbNyOXh52YMdXHs2 6pDDhWTlF8fewpwEzuQgTSdK5isQDKFS88v9p5Mff4BmXoRd1PruFsbaOH+LZy41fT VFCTmogg1tjJ6xLnjMn/UpyCbBKRBhuEYMLs3jmKGCVxZ4DQL9Y7nytzUMkCTFHrcR eVpnim8qcGsEZzY0Bexuxwuw= To: hector.cao@canonical.com, devel@lists.libvirt.org Subject: [PATCH] apparmor: Allow vfio-ccw hostdev sysfs access Date: Tue, 11 Aug 2026 14:52:38 +0200 Message-ID: <20260811125238.38066-1-hector.cao@canonical.com> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Message-ID-Hash: M2HCHQOP3KVPQAJBXNKRL5VPMQ5O3OK6 X-Message-ID-Hash: M2HCHQOP3KVPQAJBXNKRL5VPMQ5O3OK6 X-MailFrom: hector.cao@canonical.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.lists.libvirt.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Development discussions about the libvirt library & tools Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: From: Hector Cao via Devel Reply-To: Hector Cao X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZM-MESSAGEID: 1786453294964158500 Content-Type: text/plain; charset="utf-8" Attaching a vfio-ccw mediated device as a fails under the libvirt-qemu AppArmor profile because QEMU's channel subsystem code (hw/s390x/css.c) reads several sysfs attributes of the passed-through subchannel when building the guest SCHIB, and the profile does not grant read access to them: css_sch_get_chpids() -> /sys/bus/css/devices//chpids css_sch_get_path_masks() -> /sys/bus/css/devices//pimpampom css_sch_get_chpid_type() -> /sys/devices/css/chp0./type The first two are opened via /sys/bus/css/devices/ symlinks, which AppArmor resolves to the real device path /sys/devices/css// before mediating the access; the CHPID type file is read directly under /sys/devices/. Without these rules the attach (or hotplug) fails with an AppArmor DENIED message and QEMU aborts with: s390_ccw_realize: Failed to build initial schib: Invalid argument Add narrowly-scoped read rules for these three files so vfio-ccw passthrough works without granting broad access to /sys/devices/css*. Signed-off-by: Hector Cao Reviewed-by: Peter Krempa --- src/security/apparmor/libvirt-qemu | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/src/security/apparmor/libvirt-qemu b/src/security/apparmor/lib= virt-qemu index e4aceacd70..428f9a9731 100644 --- a/src/security/apparmor/libvirt-qemu +++ b/src/security/apparmor/libvirt-qemu @@ -50,6 +50,16 @@ /run/udev/data/c16[6,7]* r, /run/udev/data/c18[0,8,9]* r, =20 + # For vfio-ccw (s390x channel subsystem) hostdev passthrough. QEMU reads + # the channel-path masks, CHPID list and CHPID type of the passed-through + # subchannel from sysfs when building the guest SCHIB. The chpids and + # pimpampom files are opened via /sys/bus/css/devices// symlinks that + # AppArmor resolves to /sys/devices/cssN//; the CHPID type is read + # directly from /sys/devices/cssN/chp0./. + /sys/devices/css[0-9]*/*/chpids r, + /sys/devices/css[0-9]*/*/pimpampom r, + /sys/devices/css[0-9]*/chp0.*/type r, + # WARNING: this gives the guest direct access to host hardware and speci= fic # portions of shared memory. This is required for sound using ALSA with = kvm, # but may constitute a security risk. If your environment does not requi= re --=20 2.43.0