You are not logged in.
Pages: 1
How can I enable virsh to access /dev/disk/by-id/?
I added a <disk>-entry in the xml file of my kvm, but when I start it, I get the following error
Could not open '/dev/disk/by-id/wwn-0x5000cca23dcdaadd': Permission deniedQEMU is run with the user kvm which is in the input and storage group. But I run virsh with sudo anyway.
I got it to work by changing ownership of /dev/disk/by-id/wwn-0x5000cca23dcdaadd, so it is owned by kvm, but that doesn't seem to be the right way.
Is there a "better" way?
Offline
Offline
Thank you very much. Do you refer to the "Using polkit" paragraph, where they suggest to add a rule in /etc/polkit-1/rules.d/50-libvirt.rules?
I have that and still have the problem.
Offline
Thank you very much. Do you refer to the "Using polkit" paragraph, where they suggest to add a rule in /etc/polkit-1/rules.d/50-libvirt.rules?
No, I thought judging from your OP you should look at what groups are created and how they are used.
Offline
How can I enable virsh to access /dev/disk/by-id/?
I added a <disk>-entry in the xml file of my kvm, but when I start it, I get the following error
Could not open '/dev/disk/by-id/wwn-0x5000cca23dcdaadd': Permission deniedQEMU is run with the user kvm which is in the input and storage group. But I run virsh with sudo anyway.
sudo would only apply to virsh not libvirt / qemu?
Why did you add the kvm user to the input and storage groups?
By default the /dev/disk/by-id/ symlinks should be owned root:root and systemd will add ACL entries for active user sessions.
The links themselves are created by the udev rules in /usr/lib/udev/rules.d/60-persistent-storage.rules
Two approaches I have not tried:
You could create an additional udev rule to change the owner or group or add an ACL rule allowing the kvm user or group access.
You could also use tmpfiles.d to create ACL rules allowing the kvm user or group access.
Offline
utiadenfgnuve wrote:How can I enable virsh to access /dev/disk/by-id/?
I added a <disk>-entry in the xml file of my kvm, but when I start it, I get the following error
Could not open '/dev/disk/by-id/wwn-0x5000cca23dcdaadd': Permission deniedQEMU is run with the user kvm which is in the input and storage group. But I run virsh with sudo anyway.
sudo would only apply to virsh not libvirt / qemu?
It does not seem to do that. Maybe because I set the user of QEMU to kvm?
Why did you add the kvm user to the input and storage groups?
I had the hope that adding the user to the storage group would solve my problem ![]()
By default the /dev/disk/by-id/ symlinks should be owned root:root and systemd will add ACL entries for active user sessions.
The links themselves are created by the udev rules in /usr/lib/udev/rules.d/60-persistent-storage.rulesTwo approaches I have not tried:
You could create an additional udev rule to change the owner or group or add an ACL rule allowing the kvm user or group access.
You could also use tmpfiles.d to create ACL rules allowing the kvm user or group access.
Thank you very much. I will try that, but I first have to learn how to add an ACL rule. ![]()
Offline
Users_and_groups#Pre-systemd_groups covers how arch uses systemd related groups I think you mixed up storage and disk.
tmpfiles.d snippet
a+ /dev/disk/by-uuid/ - - - - d:group:kvm:rw-
a+ /dev/disk/by-uuid/* - - - - group:kvm:rw-First rule is intended to cover any new entry created in the directory /dev/disk/by-uuid/
The second rule is for existing entries. You can inspect ACLs with getfacl.
Last edited by loqs (2019-12-19 23:48:02)
Offline
Users_and_groups#Pre-systemd_groups covers how arch uses systemd related groups I think you mixed up storage and disk.
Think you very much!
It has been sufficient, adding the kvm user to the disk group. After that and a reboot, I was able to start with virsh.
Offline
Pages: 1