Comment 5 for bug 696318

Revision history for this message
Serge Hallyn (serge-hallyn) wrote :

A-ha! It's not the dac driver. It's the apparmor driver. 'grep apparmor /var/log/syslog | tail' gives me a bunch of:

Jan 3 19:04:06 localhost kernel: [11904.438804] type=1400 audit(1294103046.071:33): apparmor="DENIED" operation="open" parent=1 profile="libvirt-e58d045d-d4ed-39eb-09d2-c884173ff64c" name="/tmp/level1.img" pid=15084 comm="kvm" requested_mask="r" denied_mask="r" fsuid=117 ouid=117

The apparmor libvirt driver isn't writing policy to allow access to level1.img.