Created attachment 867185 [details, diff] Patch to add /usr/share/edk2-ovmf/ to the valid path list of virt-aa-helper This issue was best described in https://github.com/void-linux/void-packages/issues/32562 short summary: virt-aa-helper autogenerates apparmor profiles for VMs, with valid paths of UEFI firmware images hardcoded into the virt-aa-helper.c file. The UEFI firmware files shipped with sys-firmware/edk2-ovmf-bin reside in /usr/share/edk2-ovmf/ which is not part of the valid-path-list hardcoded in virt-aa-helper.c As a workaround i currently use the attached patch in /etc/portage/patches/app-emulation/libvirt/apparmor-uefi.patch