/usr/libexec/qemu-bridge-helper is intended (as documented in http://wiki.qemu.org/Features-Done/HelperNetworking ) to be installed setuid. It allows non-privileged qemu instances to connect to an existing bridge. It is currently missing its setuid bit: $ ls -la /usr/libexec/qemu-bridge-helper -rwx--x--x 1 root root 14120 Mar 15 14:50 /usr/libexec/qemu-bridge-helper Reproducible: Always
Invalid: the intended functionality is provided via filesystem capabilities. Sorry for the noise! $ getcap /usr/libexec/qemu-bridge-helper /usr/libexec/qemu-bridge-helper = cap_net_admin+ep