Skip to content

Instantly share code, notes, and snippets.

@major
Last active August 29, 2015 14:04
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save major/b57dc7189d34f1253ea4 to your computer and use it in GitHub Desktop.
Save major/b57dc7189d34f1253ea4 to your computer and use it in GitHub Desktop.
libvirtd/apparmor on debian jessie
root@testing:~# libvirtd --verbose
2014-07-29 15:09:00.480+0000: 18967: info : libvirt version: 1.2.4
2014-07-29 15:09:00.480+0000: 18967: error : virSecurityDriverLookup:80 : unsupported configuration: Security driver apparmor not enabled
2014-07-29 15:09:00.480+0000: 18967: error : qemuSecurityInit:393 : Failed to initialize security drivers
2014-07-29 15:09:00.480+0000: 18967: error : virStateInitialize:749 : Initialization of QEMU state driver failed: unsupported configuration: Security driver apparmor not enabled
2014-07-29 15:09:00.480+0000: 18967: error : daemonRunStateInit:922 : Driver state initialization failed
root@testing:~# dpkg -L libvirt-bin | grep virt-aa
/usr/lib/libvirt/virt-aa-helper
/etc/apparmor.d/usr.lib.libvirt.virt-aa-helper
root@testing:~# aa-status
AppArmor available in kernel.
26 profiles are loaded.
3 profiles are in enforce mode.
/usr/lib/chromium-browser/chromium-browser//browser_java
/usr/lib/chromium-browser/chromium-browser//browser_openjdk
/usr/lib/chromium-browser/chromium-browser//sanitized_helper
23 profiles are in complain mode.
/bin/ping
/sbin/klogd
/sbin/syslog-ng
/sbin/syslogd
/usr/lib/chromium-browser/chromium-browser
/usr/lib/chromium-browser/chromium-browser//chromium_browser_sandbox
/usr/lib/chromium-browser/chromium-browser//xdgsettings
/usr/lib/dovecot/deliver
/usr/lib/dovecot/dovecot-auth
/usr/lib/dovecot/imap
/usr/lib/dovecot/imap-login
/usr/lib/dovecot/managesieve-login
/usr/lib/dovecot/pop3
/usr/lib/dovecot/pop3-login
/usr/sbin/avahi-daemon
/usr/sbin/dnsmasq
/usr/sbin/dovecot
/usr/sbin/identd
/usr/sbin/mdnsd
/usr/sbin/nmbd
/usr/sbin/nscd
/usr/sbin/smbd
/usr/{sbin/traceroute,bin/traceroute.db}
1 processes have profiles defined.
0 processes are in enforce mode.
1 processes are in complain mode.
/usr/sbin/dnsmasq (13868)
0 processes are unconfined but have a profile defined.
Jul 29 14:31:24 testing.mhtx.net libvirtd[14332]: unsupported configuration: Security driver apparmor not enabled
Jul 29 14:31:24 testing.mhtx.net libvirtd[14332]: Initialization of QEMU state driver failed: unsupported configuration: Security driver apparmor not enabled
Jul 29 14:34:07 testing.mhtx.net libvirtd[14702]: unsupported configuration: Security driver apparmor not enabled
Jul 29 14:34:07 testing.mhtx.net libvirtd[14702]: Initialization of QEMU state driver failed: unsupported configuration: Security driver apparmor not enabled
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment