Repository navigation
cloudutils: Do not configure selinux/apparmor and security_driver when setup cloudstack agent - #13281
weizhouapache wants to merge 6 commits into
Conversation
|
@blueorangutan package |
Codecov Report✅ All modified and coverable lines are covered by tests.
Additional details and impacted files@@ Coverage Diff @@
## main #13281 +/- ##
=============================================
- Coverage 19.91% 3.70% -16.21%
=============================================
Files 6373 487 -5886
Lines 577230 41996 -535234
Branches 70696 7942 -62754
=============================================
- Hits 114958 1558 -113400
+ Misses 449703 40212 -409491
+ Partials 12569 226 -12343
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
@blueorangutan package |
There was a problem hiding this comment.
Pull request overview
This PR stops CloudStack KVM agent setup from actively disabling host security policy mechanisms during setup, leaving SELinux/AppArmor posture to operators.
Changes:
- Makes AppArmor and SELinux setup configuration methods return without modifying host policy.
- Removes the legacy
setup_agent.shscript that also forced SELinux permissive mode. - Removes stale Java comments referencing the deleted setup script.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
python/lib/cloudutils/serviceConfig.py |
No-ops AppArmor/SELinux configuration during agent setup. |
scripts/vm/hypervisor/kvm/setup_agent.sh |
Deletes obsolete KVM agent setup helper script. |
server/src/main/java/com/cloud/hypervisor/kvm/discoverer/LibvirtServerDiscoverer.java |
Removes stale commented reference to setup_agent.sh. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
@blueorangutan package |
|
@DaanHoogland |
|
with the changes ubuntu 24 debian12 oraclelinux 8 suse15 oraclelinux 9 |
|
@blueorangutan package |
1 similar comment
|
@blueorangutan package |
|
@blueorangutan help |
9458007 to
1325b34
Compare
|
@blueorangutan package |
|
@weizhouapache a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress. |
|
Packaging result [SF]: ✖️ el8 ✖️ el9 ✖️ debian ✖️ suse15. SL-JID 19452 |
|
Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19453 |
|
[SF] Trillian Build Failed (tid-17094) |
|
[SF] Trillian test result (tid-17085)
|
|
[SF] Trillian test result (tid-17084)
|
|
@blueorangutan package |
|
@weizhouapache a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress. |
There was a problem hiding this comment.
🟡 Changes recommended
The unrelated client packaging exclusions need to be removed, split, or independently justified and verified.
1 open finding
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
a246750 to
0e5420d
Compare
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Copilot review overview
4 open findings
The PR description focuses on disabling SELinux/AppArmor configuration during setup, but the PR… · New Removing the explicitsecurity_driverline changes libvirt behavior depending on distro defaults… · New With the security policy configurators removed from the provisioning pipeline, hosts that rely on… · New Unrelated packaging exclusions alter management-server classpath
🧠 Review effort: Lite
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
| self.svo = serviceOpsUbuntu() | ||
|
|
||
| self.services = [hostConfig(self), | ||
| securityPolicyConfigUbuntu(self), | ||
| networkConfigUbuntu(self), | ||
| libvirtConfigUbuntu(self), | ||
| firewallConfigUbuntu(self), |
|
[SF] Trillian Build Failed (tid-17097) |
|
@blueorangutan package |
|
@weizhouapache a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress. |
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Copilot review overview
2 open findings
3 resolved since last review
🧠 Review effort: Lite
| filename = "/etc/libvirt/qemu.conf" | ||
|
|
||
| cfo = configFileOps(filename, self) | ||
| cfo.addEntry("security_driver", "\"none\"") | ||
| cfo.addEntry("user", "\"root\"") | ||
| cfo.addEntry("group", "\"root\"") | ||
| cfo.addEntry("vnc_listen", "\"0.0.0.0\"") |

Description
This PR disables security configurations during CloudStack agent setup:
However, users have different security and hardening requirements, and these decisions should not be enforced by the agent setup. For example:
Some environments may require SELinux/AppArmor to remain in enforcing mode for stronger security hardening, and the system should still support such configurations.
Some users may prefer to explicitly configure the libvirt security driver in
/etc/libvirt/qemu.conf, replacingsecurity_driver="none"with:Note that this configuration may not be compatible with certain VM or volume features and could require additional changes. If so, those cases are outside the scope of this PR and can be addressed in future improvements.
Types of changes
Feature/Enhancement Scale or Bug Severity
Feature/Enhancement Scale
Bug Severity
Screenshots (if appropriate):
How Has This Been Tested?
How did you try to break this feature and the system with this change?