Uh oh!
There was an error while loading. Please reload this page.
cloudutils: Do not configure selinux/apparmor when setup cloudstack agent - #13281
cloudutils: Do not configure selinux/apparmor when setup cloudstack agent#13281weizhouapache wants to merge 6 commits into
Conversation
weizhouapache
commented
May 29, 2026
@blueorangutan package |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@## main #13281 +/- ##
============================================
+ Coverage 18.75% 18.89% +0.13% - Complexity 17966 18224 +258
============================================
Files 6160 6174 +14 Lines 552578 555226 +2648 Branches 67348 67774 +426 ============================================
+ Hits 103660 104885 +1225 - Misses 437512 438820 +1308 - Partials 11406 11521 +115
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
weizhouapache
commented
May 29, 2026
@blueorangutan package |
There was a problem hiding this comment.
Pull request overview
This PR stops CloudStack KVM agent setup from actively disabling host security policy mechanisms during setup, leaving SELinux/AppArmor posture to operators.
Changes:
- Makes AppArmor and SELinux setup configuration methods return without modifying host policy.
- Removes the legacy
setup_agent.shscript that also forced SELinux permissive mode. - Removes stale Java comments referencing the deleted setup script.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
python/lib/cloudutils/serviceConfig.py | No-ops AppArmor/SELinux configuration during agent setup. |
scripts/vm/hypervisor/kvm/setup_agent.sh | Deletes obsolete KVM agent setup helper script. |
server/src/main/java/com/cloud/hypervisor/kvm/discoverer/LibvirtServerDiscoverer.java | Removes stale commented reference to setup_agent.sh. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
weizhouapache
commented
May 29, 2026
@blueorangutan package |
weizhouapache
commented
May 29, 2026
@DaanHoogland |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
blueorangutan
commented
May 29, 2026
Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 18086 |
blueorangutan
commented
May 29, 2026
[SF] Trillian Build Failed (tid-16221) |
blueorangutan
commented
May 29, 2026
[SF] Trillian Build Failed (tid-16225) |
with the changes ubuntu 24 debian12 oraclelinux 8 suse15 oraclelinux 9 |
weizhouapache
commented
May 29, 2026
@blueorangutan package |
blueorangutan
commented
May 29, 2026
@weizhouapache a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress. |
blueorangutan
commented
May 29, 2026
Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 18093 |
blueorangutan
commented
May 29, 2026
[SF] Trillian test result (tid-16220)
|
blueorangutan
commented
May 30, 2026
[SF] Trillian test result (tid-16222)
|
blueorangutan
commented
May 30, 2026
[SF] Trillian test result (tid-16224)
|
blueorangutan
commented
May 30, 2026
[SF] Trillian test result (tid-16223)
|
blueorangutan
commented
May 30, 2026
[SF] Trillian test result (tid-16227)
|
blueorangutan
commented
May 30, 2026
[SF] Trillian test result (tid-16228)
|
blueorangutan
commented
Jun 1, 2026
[SF] Trillian Build Failed (tid-16233) |
blueorangutan
commented
Jun 17, 2026
[SF] Trillian test result (tid-16331)
|
blueorangutan
commented
Jun 17, 2026
[SF] Trillian Build Failed (tid-16341) |
blueorangutan
commented
Jun 17, 2026
[SF] Trillian test result (tid-16338)
|
blueorangutan
commented
Jun 17, 2026
[SF] Trillian test result (tid-16340)
|
blueorangutan
commented
Jun 18, 2026
[SF] Trillian test result (tid-16342)
|
weizhouapache
commented
Jun 18, 2026
@blueorangutan package |
blueorangutan
commented
Jun 18, 2026
@weizhouapache a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress. |
blueorangutan
commented
Jun 18, 2026
Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 18297 |
blueorangutan
commented
Jun 18, 2026
[SF] Trillian Build Failed (tid-16363) |
blueorangutan
commented
Jun 19, 2026
[SF] Trillian test result (tid-16367)
|
blueorangutan
commented
Jun 19, 2026
[SF] Trillian test result (tid-16364)
|
blueorangutan
commented
Jun 19, 2026
[SF] Trillian test result (tid-16362)
|
0c323ce to
1325b34Compareweizhouapache
commented
Jun 19, 2026
@blueorangutan package |
blueorangutan
commented
Jun 19, 2026
@weizhouapache a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress. |
blueorangutan
commented
Jun 19, 2026
Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✖️ debian ✔️ suse15. SL-JID 18309 |
blueorangutan
commented
Jun 19, 2026
[SF] Trillian test result (tid-16372)
|
blueorangutan
commented
Jun 20, 2026
[SF] Trillian test result (tid-16373)
|
weizhouapache
commented
Jul 7, 2026
moving to 4.24.0 milestone |
Description
This PR disables security configurations during CloudStack agent setup:
However, users have different security and hardening requirements, and these decisions should not be enforced by the agent setup. For example:
Some environments may require SELinux/AppArmor to remain in enforcing mode for stronger security hardening, and the system should still support such configurations.
Some users may prefer to explicitly configure the libvirt security driver in
/etc/libvirt/qemu.conf, replacingsecurity_driver="none"with:Note that this configuration may not be compatible with certain VM or volume features and could require additional changes. If so, those cases are outside the scope of this PR and can be addressed in future improvements.
Types of changes
Feature/Enhancement Scale or Bug Severity
Feature/Enhancement Scale
Bug Severity
Screenshots (if appropriate):
How Has This Been Tested?
How did you try to break this feature and the system with this change?