You are not logged in.

#1 2019-12-19 14:59:47

utiadenfgnuve
Member
Registered: 2018-11-20
Posts: 19

virsh Permission denied /dev/disk/by-id/

How can I enable virsh to access /dev/disk/by-id/?

I added a <disk>-entry in the xml file of my kvm, but when I start it, I get the following error

Could not open '/dev/disk/by-id/wwn-0x5000cca23dcdaadd': Permission denied

QEMU is run with the user kvm which is in the input and storage group. But I run virsh with sudo anyway.

I got it to work by changing ownership of /dev/disk/by-id/wwn-0x5000cca23dcdaadd, so it is owned by kvm, but that doesn't seem to be the right way.

Is there a "better" way?

Offline

#2 2019-12-19 17:53:53

Zod
Member
From: Hoosiertucky
Registered: 2019-03-10
Posts: 636

Re: virsh Permission denied /dev/disk/by-id/

Offline

#3 2019-12-19 19:42:48

utiadenfgnuve
Member
Registered: 2018-11-20
Posts: 19

Re: virsh Permission denied /dev/disk/by-id/

Thank you very much. Do you refer to the "Using polkit" paragraph, where they suggest to add a rule in /etc/polkit-1/rules.d/50-libvirt.rules?

I have that and still have the problem.

Offline

#4 2019-12-19 20:13:33

Zod
Member
From: Hoosiertucky
Registered: 2019-03-10
Posts: 636

Re: virsh Permission denied /dev/disk/by-id/

utiadenfgnuve wrote:

Thank you very much. Do you refer to the "Using polkit" paragraph, where they suggest to add a rule in /etc/polkit-1/rules.d/50-libvirt.rules?

No, I thought judging from your OP you should look at what groups are created and how they are used.

Offline

#5 2019-12-19 21:47:03

loqs
Member
Registered: 2014-03-06
Posts: 19,097

Re: virsh Permission denied /dev/disk/by-id/

utiadenfgnuve wrote:

How can I enable virsh to access /dev/disk/by-id/?

I added a <disk>-entry in the xml file of my kvm, but when I start it, I get the following error

Could not open '/dev/disk/by-id/wwn-0x5000cca23dcdaadd': Permission denied

QEMU is run with the user kvm which is in the input and storage group. But I run virsh with sudo anyway.

sudo would only apply to virsh not libvirt / qemu?
Why did you add the kvm user to the input and storage groups?
By default the /dev/disk/by-id/ symlinks should be owned root:root and systemd will add ACL entries for active user sessions.
The links themselves are created by the udev rules in /usr/lib/udev/rules.d/60-persistent-storage.rules

Two approaches I have not tried:
You could create an additional udev rule to change the owner or group or add an ACL rule allowing the kvm user or group access.
You could also use tmpfiles.d to create ACL rules allowing the kvm user or group access.

Offline

#6 2019-12-19 23:12:54

utiadenfgnuve
Member
Registered: 2018-11-20
Posts: 19

Re: virsh Permission denied /dev/disk/by-id/

loqs wrote:
utiadenfgnuve wrote:

How can I enable virsh to access /dev/disk/by-id/?

I added a <disk>-entry in the xml file of my kvm, but when I start it, I get the following error

Could not open '/dev/disk/by-id/wwn-0x5000cca23dcdaadd': Permission denied

QEMU is run with the user kvm which is in the input and storage group. But I run virsh with sudo anyway.

sudo would only apply to virsh not libvirt / qemu?

It does not seem to do that. Maybe because I set the user of QEMU to kvm?

loqs wrote:

Why did you add the kvm user to the input and storage groups?

I had the hope that adding the user to the storage group would solve my problem big_smile

loqs wrote:

By default the /dev/disk/by-id/ symlinks should be owned root:root and systemd will add ACL entries for active user sessions.
The links themselves are created by the udev rules in /usr/lib/udev/rules.d/60-persistent-storage.rules

Two approaches I have not tried:
You could create an additional udev rule to change the owner or group or add an ACL rule allowing the kvm user or group access.
You could also use tmpfiles.d to create ACL rules allowing the kvm user or group access.

Thank you very much. I will try that, but I first have to learn how to add an ACL rule. smile

Offline

#7 2019-12-19 23:47:45

loqs
Member
Registered: 2014-03-06
Posts: 19,097

Re: virsh Permission denied /dev/disk/by-id/

Users_and_groups#Pre-systemd_groups covers how arch uses systemd related groups I think you mixed up storage and disk.

tmpfiles.d snippet

a+ /dev/disk/by-uuid/ - - - - d:group:kvm:rw-
a+ /dev/disk/by-uuid/* - - - - group:kvm:rw-

First rule is intended to cover any new entry created in the directory /dev/disk/by-uuid/
The second rule is for existing entries.  You can inspect ACLs with getfacl.

Last edited by loqs (2019-12-19 23:48:02)

Offline

#8 2019-12-31 07:55:38

utiadenfgnuve
Member
Registered: 2018-11-20
Posts: 19

Re: virsh Permission denied /dev/disk/by-id/

loqs wrote:

Users_and_groups#Pre-systemd_groups covers how arch uses systemd related groups I think you mixed up storage and disk.

Think you very much!
It has been sufficient, adding the kvm user to the disk group. After that and a reboot, I was able to start with virsh.

Offline

Board footer

Powered by FluxBB