mirror of https://gitee.com/openkylin/libvirt.git
apparmor: Add openGraphicsFD rule for named profile
Commita3ab6d42
changed the libvirtd profile to a named profile but neglected to accommodate the change in the qemu profile ptrace and signal rules. Later on4ec3cf9a
fixed that for ptrace and signal but openGraphicsFD is still missing. As a result, libvirtd is unable to open UI on libvirt >=5.1 e.g. with virt-manager. Add openGraphicsFD rule that references the libvirtd profile by name in addition to full binary path. Fixes: https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1833040 Signed-off-by: Christian Ehrhardt <christian.ehrhardt@canonical.com>
This commit is contained in:
parent
7c570f06bd
commit
18ffb1670e
|
@ -208,6 +208,7 @@
|
|||
/sys/firmware/devicetree/** r,
|
||||
|
||||
# allow connect with openGraphicsFD to work
|
||||
unix (send, receive) type=stream addr=none peer=(label=libvirtd),
|
||||
unix (send, receive) type=stream addr=none peer=(label=/usr/sbin/libvirtd),
|
||||
|
||||
# for gathering information about available host resources
|
||||
|
|
Loading…
Reference in New Issue