Skip to content

cloudutils: Do not configure selinux/apparmor and security_driver when setup cloudstack agent - #13281

Open
weizhouapache wants to merge 6 commits into
apache:mainfrom
weizhouapache:4.23-not-config-selinux-apparmor
Open

weizhouapache wants to merge 6 commits into
apache:mainfrom
weizhouapache:4.23-not-config-selinux-apparmor

Conversation

@weizhouapache

Copy link
Copy Markdown
Member

Description

This PR disables security configurations during CloudStack agent setup:

  • On Ubuntu, it disables AppArmor restrictions for libvirt
  • On EL-based systems, it sets SELinux to permissive mode

However, users have different security and hardening requirements, and these decisions should not be enforced by the agent setup. For example:

  • Some environments may require SELinux/AppArmor to remain in enforcing mode for stronger security hardening, and the system should still support such configurations.

  • Some users may prefer to explicitly configure the libvirt security driver in /etc/libvirt/qemu.conf, replacing security_driver="none" with:

security_driver="selinux"
security_driver="apparmor"

Note that this configuration may not be compatible with certain VM or volume features and could require additional changes. If so, those cases are outside the scope of this PR and can be addressed in future improvements.

Types of changes

  • Breaking change (fix or feature that would cause existing functionality to change)
  • New feature (non-breaking change which adds functionality)
  • Bug fix (non-breaking change which fixes an issue)
  • Enhancement (improves an existing feature and functionality)
  • Cleanup (Code refactoring and cleanup, that may add test cases)
  • Build/CI
  • Test (unit or integration test code)

Feature/Enhancement Scale or Bug Severity

Feature/Enhancement Scale

  • Major
  • Minor

Bug Severity

  • BLOCKER
  • Critical
  • Major
  • Minor
  • Trivial

Screenshots (if appropriate):

How Has This Been Tested?

How did you try to break this feature and the system with this change?

@boring-cyborg boring-cyborg Bot added component:kvm Python Warning... Python code Ahead! labels May 29, 2026
@weizhouapache

Copy link
Copy Markdown
Member Author

@blueorangutan package

@codecov

codecov Bot commented May 29, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 3.70%. Comparing base (ed1db53) to head (322e188).
⚠️ Report is 2 commits behind head on main.

❗ There is a different number of reports uploaded between BASE (ed1db53) and HEAD (322e188). Click for more details.

HEAD has 1 upload less than BASE
Flag BASE (ed1db53) HEAD (322e188)
unittests 1 0
Additional details and impacted files
@@              Coverage Diff              @@
##               main   #13281       +/-   ##
=============================================
- Coverage     19.91%    3.70%   -16.21%     
=============================================
  Files          6373      487     -5886     
  Lines        577230    41996   -535234     
  Branches      70696     7942    -62754     
=============================================
- Hits         114958     1558   -113400     
+ Misses       449703    40212   -409491     
+ Partials      12569      226    -12343     
Flag Coverage Δ
uitests 3.70% <ø> (-0.01%) ⬇️
unittests ?

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@weizhouapache

Copy link
Copy Markdown
Member Author

@blueorangutan package

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR stops CloudStack KVM agent setup from actively disabling host security policy mechanisms during setup, leaving SELinux/AppArmor posture to operators.

Changes:

  • Makes AppArmor and SELinux setup configuration methods return without modifying host policy.
  • Removes the legacy setup_agent.sh script that also forced SELinux permissive mode.
  • Removes stale Java comments referencing the deleted setup script.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.

File Description
python/lib/cloudutils/serviceConfig.py No-ops AppArmor/SELinux configuration during agent setup.
scripts/vm/hypervisor/kvm/setup_agent.sh Deletes obsolete KVM agent setup helper script.
server/src/main/java/com/cloud/hypervisor/kvm/discoverer/LibvirtServerDiscoverer.java Removes stale commented reference to setup_agent.sh.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread python/lib/cloudutils/serviceConfig.py Outdated
Comment thread python/lib/cloudutils/serviceConfig.py Outdated
Comment thread python/lib/cloudutils/serviceConfig.py Outdated
Comment thread python/lib/cloudutils/serviceConfig.py Outdated
Comment thread python/lib/cloudutils/serviceConfig.py Outdated
@weizhouapache

Copy link
Copy Markdown
Member Author

@blueorangutan package

@weizhouapache

Copy link
Copy Markdown
Member Author

@DaanHoogland
yes, they are dead code.
I am running some tests, they will be removed after verification

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.

Comment thread python/lib/cloudutils/serviceConfig.py Outdated
Comment thread python/lib/cloudutils/serviceConfig.py Outdated
@weizhouapache

weizhouapache commented May 29, 2026 •

Copy link
Copy Markdown
Member Author

with the changes

ubuntu 24

root@pr13281-t16222-kvm-ubuntu24-kvm1:~# aa-status 
apparmor module is loaded.
113 profiles are loaded.
113 profiles are in enforce mode.
   /usr/bin/man
   /usr/lib/snapd/snap-confine
   /usr/lib/snapd/snap-confine//mount-namespace-capture-helper
   /usr/sbin/chronyd
   1password
   Discord
   MongoDB Compass
   QtWebEngineProcess
   balena-etcher
   brave
   buildah
   cam
   ch-checkns
   ch-run
   chrome
   crun
   devhelp
   element-desktop
   epiphany
   evolution
   firefox
   flatpak
   foliate
   geary
   github-desktop
   goldendict
   ipa_verify
   kchmviewer
   keybase
   lc-compliance
   libcamerify
   libvirtd
   libvirtd//qemu_bridge_helper
   linux-sandbox
   loupe
   lsb_release
   lxc-attach
   lxc-create
   lxc-destroy
   lxc-execute
   lxc-stop
   lxc-unshare
   lxc-usernsexec
   man_filter
   man_groff
   mmdebstrap
   msedge
   notepadqq
   nvidia_modprobe
   nvidia_modprobe//kmod
   obsidian
   opam
   opera
   pageedit
   plasmashell
   plasmashell//QtWebEngineProcess
   podman
   polypane
   privacybrowser
   qcam
   qmapshack
   qutebrowser
   rootlesskit
   rpm
   rssguard
   rsyslogd
   runc
   sbuild
   sbuild-abort
   sbuild-adduser
   sbuild-apt
   sbuild-checkpackages
   sbuild-clean
   sbuild-createchroot
   sbuild-destroychroot
   sbuild-distupgrade
   sbuild-hold
   sbuild-shell
   sbuild-unhold
   sbuild-update
   sbuild-upgrade
   scide
   signal-desktop
   slack
   slirp4netns
   steam
   stress-ng
   surfshark
   swtpm
   systemd-coredump
   tcpdump
   thunderbird
   toybox
   transmission-cli
   transmission-daemon
   transmission-gtk
   transmission-qt
   trinity
   tup
   tuxedo-control-center
   ubuntu_pro_apt_news
   unix-chkpwd
   unprivileged_userns
   userbindmount
   uwsgi-core
   vdens
   virt-aa-helper
   virtiofsd
   vivaldi-bin
   vpnns
   vscode
   wike
   wpcom
0 profiles are in complain mode.
0 profiles are in prompt mode.
0 profiles are in kill mode.
0 profiles are in unconfined mode.
4 processes have profiles defined.
4 processes are in enforce mode.
   /usr/sbin/chronyd (949) 
   /usr/sbin/chronyd (957) 
   /usr/sbin/libvirtd (13184) libvirtd
   /usr/sbin/rsyslogd (927) rsyslogd
0 processes are in complain mode.
0 processes are in prompt mode.
0 processes are in kill mode.
0 processes are unconfined but have a profile defined.
0 processes are in mixed mode.

root@pr13281-t16222-kvm-ubuntu24-kvm1:~# grep ^security /etc/libvirt/qemu.conf 
security_driver="none"

debian12

root@pr13281-t16223-kvm-debian12-kvm1:~# aa-status 
apparmor module is loaded.
15 profiles are loaded.
15 profiles are in enforce mode.
   /usr/bin/man
   /usr/lib/NetworkManager/nm-dhcp-client.action
   /usr/lib/NetworkManager/nm-dhcp-helper
   /usr/lib/connman/scripts/dhclient-script
   /usr/sbin/chronyd
   /{,usr/}sbin/dhclient
   libvirtd
   libvirtd//qemu_bridge_helper
   lsb_release
   man_filter
   man_groff
   nvidia_modprobe
   nvidia_modprobe//kmod
   tcpdump
   virt-aa-helper
0 profiles are in complain mode.
0 profiles are in kill mode.
0 profiles are in unconfined mode.
3 processes have profiles defined.
3 processes are in enforce mode.
   /usr/sbin/chronyd (1818) 
   /usr/sbin/chronyd (1819) 
   /usr/sbin/libvirtd (44766) libvirtd
0 processes are in complain mode.
0 processes are unconfined but have a profile defined.
0 processes are in mixed mode.
0 processes are in kill mode.

root@pr13281-t16223-kvm-debian12-kvm1:~# grep ^security /etc/libvirt/qemu.conf 
security_driver="none"

oraclelinux 8

[root@pr13281-t16220-kvm-ol8-kvm1 ~]# sestatus 
SELinux status:                 enabled
SELinuxfs mount:                /sys/fs/selinux
SELinux root directory:         /etc/selinux
Loaded policy name:             targeted
Current mode:                   enforcing
Mode from config file:          enforcing
Policy MLS status:              enabled
Policy deny_unknown status:     allowed
Memory protection checking:     actual (secure)
Max kernel policy version:      31

[root@pr13281-t16220-kvm-ol8-kvm1 ~]# grep ^security /etc/libvirt/qemu.conf 
security_driver="none"

suse15

pr13281-t16224-kvm-suse15-kvm1:~ # aa-status 
apparmor module is loaded.
64 profiles are loaded.
64 profiles are in enforce mode.
   /usr/bin/lessopen.sh
   apache2
   apache2//DEFAULT_URI
   apache2//HANDLING_UNTRUSTED_INPUT
   apache2//phpsysinfo
   avahi-daemon
   dnsmasq
   dnsmasq//libvirt_leaseshelper
   dovecot
   dovecot-anvil
   dovecot-auth
   dovecot-config
   dovecot-deliver
   dovecot-dict
   dovecot-director
   dovecot-doveadm-server
   dovecot-dovecot-auth
   dovecot-dovecot-lda
   dovecot-dovecot-lda//sendmail
   dovecot-imap
   dovecot-imap-login
   dovecot-lmtp
   dovecot-log
   dovecot-managesieve
   dovecot-managesieve-login
   dovecot-pop3
   dovecot-pop3-login
   dovecot-replicator
   dovecot-script-login
   dovecot-ssl-params
   dovecot-stats
   identd
   klogd
   libvirtd
   libvirtd//qemu_bridge_helper
   lsb_release
   mdnsd
   nmbd
   nscd
   ntpd
   nvidia_modprobe
   nvidia_modprobe//kmod
   php-fpm
   ping
   samba-bgqd
   samba-dcerpcd
   samba-rpcd
   samba-rpcd-classic
   samba-rpcd-spoolss
   smbd
   smbldap-useradd
   smbldap-useradd///etc/init.d/nscd
   syslog-ng
   syslogd
   traceroute
   unix-chkpwd
   virt-aa-helper
   virtqemud
   virtqemud//qemu_bridge_helper
   virtxend
   winbindd
   zgrep
   zgrep//helper
   zgrep//sed
0 profiles are in complain mode.
0 profiles are in kill mode.
0 profiles are in unconfined mode.
2 processes have profiles defined.
2 processes are in enforce mode.
   /usr/sbin/libvirtd (8137) libvirtd
   /usr/sbin/nscd (862) nscd
0 processes are in complain mode.
0 processes are unconfined but have a profile defined.
0 processes are in mixed mode.
0 processes are in kill mode.

pr13281-t16224-kvm-suse15-kvm1:~ # grep ^security /etc/libvirt/qemu.conf 
security_driver="none"

oraclelinux 9

[root@pr13281-t16227-kvm-ol9-kvm1 ~]# grep ^security /etc/libvirt/qemu.conf 
security_driver="none"
[root@pr13281-t16227-kvm-ol9-kvm1 ~]# 
[root@pr13281-t16227-kvm-ol9-kvm1 ~]# sestatus 
SELinux status:                 enabled
SELinuxfs mount:                /sys/fs/selinux
SELinux root directory:         /etc/selinux
Loaded policy name:             targeted
Current mode:                   enforcing
Mode from config file:          enforcing
Policy MLS status:              enabled
Policy deny_unknown status:     allowed
Memory protection checking:     actual (secure)
Max kernel policy version:      33
[root@pr13281-t16227-kvm-ol9-kvm1 ~]# 

@weizhouapache

Copy link
Copy Markdown
Member Author

@blueorangutan package

1 similar comment
@weizhouapache

Copy link
Copy Markdown
Member Author

@blueorangutan package

@weizhouapache

Copy link
Copy Markdown
Member Author

@blueorangutan help

@weizhouapache
weizhouapache force-pushed the 4.23-not-config-selinux-apparmor branch from 9458007 to 1325b34 Compare June 8, 2026 09:20
@weizhouapache

Copy link
Copy Markdown
Member Author

@blueorangutan package

@weizhouapache weizhouapache changed the title Do not configure selinux/apparmor when setup cloudstack agent cloudutils: Do not configure selinux/apparmor when setup cloudstack agent Jun 8, 2026
@apache apache deleted a comment from blueorangutan Jun 17, 2026
@apache apache deleted a comment from blueorangutan Jun 17, 2026
@apache apache deleted a comment from blueorangutan Jun 17, 2026
@apache apache deleted a comment from blueorangutan Jun 17, 2026
@blueorangutan

Copy link
Copy Markdown

@weizhouapache a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✖️ el8 ✖️ el9 ✖️ debian ✖️ suse15. SL-JID 19452

@blueorangutan

Copy link
Copy Markdown

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19453

@blueorangutan

Copy link
Copy Markdown

[SF] Trillian Build Failed (tid-17094)

@blueorangutan

Copy link
Copy Markdown

[SF] Trillian test result (tid-17085)
Environment: kvm-ol8 (x2), zone: Advanced Networking with Mgmt server ol8
Total time taken: 57593 seconds
Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr13281-t17085-kvm-ol8.zip
Smoke tests completed. 155 look OK, 1 have errors, 0 did not run
Only failed and skipped tests results shown below:

Test Result Time (s) Test File
test_01_ssl_offloading_isolated_network Failure 249.61 test_ssl_offloading.py

@blueorangutan

Copy link
Copy Markdown

[SF] Trillian test result (tid-17084)
Environment: kvm-ol8 (x2), zone: Advanced Networking with Mgmt server ol8
Total time taken: 65405 seconds
Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr13281-t17084-kvm-ol8.zip
Smoke tests completed. 156 look OK, 0 have errors, 0 did not run
Only failed and skipped tests results shown below:

Test Result Time (s) Test File

Copilot AI balanced review requested due to automatic review settings October 8, 2026 07:48
@weizhouapache

Copy link
Copy Markdown
Member Author

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@weizhouapache a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The unrelated client packaging exclusions need to be removed, split, or independently justified and verified.

1 open finding

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread client/pom.xml Outdated
Copilot AI balanced review requested due to automatic review settings October 8, 2026 08:31
@weizhouapache
weizhouapache force-pushed the 4.23-not-config-selinux-apparmor branch from a246750 to 0e5420d Compare October 8, 2026 08:31

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Copilot review overview

4 open findings

🧠 Review effort: Lite


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread python/lib/cloudutils/serviceConfig.py
Comment thread python/lib/cloudutils/serviceConfig.py
Comment on lines 167 to 172
self.svo = serviceOpsUbuntu()

self.services = [hostConfig(self),
securityPolicyConfigUbuntu(self),
networkConfigUbuntu(self),
libvirtConfigUbuntu(self),
firewallConfigUbuntu(self),
@weizhouapache weizhouapache changed the title cloudutils: Do not configure selinux/apparmor when setup cloudstack agent cloudutils: Do not configure selinux/apparmor and security_driver when setup cloudstack agent Oct 8, 2026
@blueorangutan

Copy link
Copy Markdown

[SF] Trillian Build Failed (tid-17097)

Copilot AI balanced review requested due to automatic review settings October 8, 2026 16:32
@weizhouapache

Copy link
Copy Markdown
Member Author

@blueorangutan package

@blueorangutan

Copy link
Copy Markdown

@weizhouapache a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Copilot review overview

2 open findings
3 resolved since last review

🧠 Review effort: Lite

Comment on lines 583 to 588
filename = "/etc/libvirt/qemu.conf"

cfo = configFileOps(filename, self)
cfo.addEntry("security_driver", "\"none\"")
cfo.addEntry("user", "\"root\"")
cfo.addEntry("group", "\"root\"")
cfo.addEntry("vnc_listen", "\"0.0.0.0\"")

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: Ready

Development

Successfully merging this pull request may close these issues.

7 participants