Qemu function hdev_get_max_segments reads this. Access is to: /sys/dev/block/%u:%u/queue/max_segments with O_RDONLY So yeah, the rule "/sys/dev/block/*/queue/max_segments r," should be good.
This is since qemu 2.9: commit 9103f1ceb46614b150bcbc3c9a4fbc72b47fedcc Author: Fam Zheng <f...@redhat.com> Date: Wed Mar 8 20:08:14 2017 +0800 file-posix: Consider max_segments for BlockLimits.max_transfer This is a fix for a rare bug, that due to the rule does not yet "fix" it. Prio is low enough to not need any SRU, but it shall be fixed. I'll create a fix to the upstream apparmor profiles and get them back on next merge. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1729626 Title: AppArmor denies access to /sys/block/*/queue/max_segments To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1729626/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs