On Debian 13 ARM `virsh list --all` does not return any virtual machine, while `sudo virsh list --all` returns a virtual machine, while the user is in `libvirt` group. What is the issue?
Aug 12, 10:14pm
The issue you're encountering on Debian 13 ARM where virsh list --all returns no virtual machines, but sudo virsh list --all does, is likely related to permissions or group membership not being properly applied. Here’s how to diagnose and fix it:
Root Cause
Group Membership:
The libvirt group grants access to manage virtual machines via virsh without sudo.
Even if your user is in the libvirt group, the group permissions might not be applied to the current session.
Session Refresh:
Group changes (e.g., adding a user to libvirt) require a new login session to take effect.
If you added your user to the libvirt group recently, you may need to log out and log back in or restart your terminal session.
Polkit Rules:
On some systems, virsh requires Polkit (PolicyKit) permissions to allow non-root users to interact with libvirtd.
If Polkit is misconfigured, it may block access even for users in the libvirt group.
AppArmor/SELinux:
If AppArmor or SELinux is enabled, it might restrict access to libvirtd for non-root users.
Libvirt Socket Permissions:
The Unix socket used by libvirtd (typically /var/run/libvirt/libvirt-sock) must be accessible by the libvirt group.
If libvirtd is confined, try temporarily disabling AppArmor:
bash
sudo systemctl stop apparmor
Test if virsh list --all works. If it does, adjust the AppArmor profile for libvirtd.
For SELinux (less common on Debian):
bash
sudo sestatus
If enabled, check for denials:
bash
sudo ausearch -m avc -ts recent
Temporarily set SELinux to permissive mode to test:
bash
sudo setenforce 0
6. Test with LIBVIRT_DEFAULT_URI
Explicitly set the URI for virsh to use the system connection:
bash
export LIBVIRT_DEFAULT_URI="qemu:///system"
virsh list --all
If this works, add the export line to your ~/.bashrc or ~/.profile.
7. Check libvirtd Logs
Look for errors in:
bash
journalctl -u libvirtd --no-pager -n 50
Summary of Commands to Run
bash
# 1. Verify group membership
groups
# 2. Fix group membership if needed
sudo usermod -aG libvirt $USER
# Log out and back in
# 3. Check socket permissions
ls -l /var/run/libvirt/libvirt-sock
sudo chown root:libvirt /var/run/libvirt/libvirt-sock
sudo chmod 660 /var/run/libvirt/libvirt-sock
# 4. Restart libvirtd
sudo systemctl restart libvirtd
# 5. Test with URI
export LIBVIRT_DEFAULT_URI="qemu:///system"
virsh list --all
Expected Outcome
After applying these fixes, virsh list --all should work without sudo. If the issue persists, the problem might be specific to your Debian 13 ARM setup (e.g., a bug or missing package).
Aug 12, 10:14pm
This is a shared conversation and may include unverified content that doesn't reflect Mistral AI's views. Login to resume chatting.