Bug 1264641

Summary: SELinux is preventing xenconsoled from using the 'sys_resource' capabilities.
Product: [Fedora] Fedora Reporter: sudikeru
Component: selinux-policyAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED INSUFFICIENT_DATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: medium    
Version: 22CC: awilliam, crobinso, dominick.grift, dwalsh, lvrabec, mgrepl, plautrba, sudikeru
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Unspecified   
Whiteboard: abrt_hash:3ff159cffde86096f4eae7f07707a00e427469a2025ea4f88cde159436571c2d
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-04-14 15:51:34 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description sudikeru 2015-09-19 17:48:59 UTC
Description of problem:
Start Fedora 22 with Xen

Version-Release number of selected component:
selinux-policy-3.13.1-128.13.fc22.noarch

Additional info:
reporter:       libreport-2.6.2
hashmarkername: setroubleshoot
kernel:         4.1.6-201.fc22.x86_64
type:           libreport

Comment 1 Adam Williamson 2015-10-02 01:32:17 UTC
Description of problem:
Tried to browse local disks in virt-manager for a Xen guest.

Version-Release number of selected component:
selinux-policy-3.13.1-128.16.fc22.noarch

Additional info:
reporter:       libreport-2.6.2
hashmarkername: setroubleshoot
kernel:         4.1.8-200.fc22.x86_64
type:           libreport

Comment 2 sudikeru 2015-10-12 21:22:38 UTC
Description of problem:
Start Fedora 22 with xen

Version-Release number of selected component:
selinux-policy-3.13.1-128.16.fc22.noarch

Additional info:
reporter:       libreport-2.6.2
hashmarkername: setroubleshoot
kernel:         4.1.10-200.fc22.x86_64
type:           libreport

Comment 3 Miroslav Grepl 2015-10-13 11:41:05 UTC
Did it work?

Comment 4 sudikeru 2015-10-19 08:14:02 UTC
Description of problem:
Start virtual machine on Fedora 22 with xen

Version-Release number of selected component:
selinux-policy-3.13.1-128.16.fc22.noarch

Additional info:
reporter:       libreport-2.6.2
hashmarkername: setroubleshoot
kernel:         4.2.3-200.fc22.x86_64
type:           libreport

Comment 5 sudikeru 2015-10-19 08:41:25 UTC
Description of problem:
Start Fedora 22 with xen

Version-Release number of selected component:
selinux-policy-3.13.1-128.16.fc22.noarch

Additional info:
reporter:       libreport-2.6.2
hashmarkername: setroubleshoot
kernel:         4.2.3-200.fc22.x86_64
type:           libreport

Comment 6 sudikeru 2015-10-19 18:31:24 UTC
Description of problem:
Start virtual machine on Fedora with xen

Version-Release number of selected component:
selinux-policy-3.13.1-128.16.fc22.noarch

Additional info:
reporter:       libreport-2.6.2
hashmarkername: setroubleshoot
kernel:         4.2.3-200.fc22.x86_64
type:           libreport

Comment 7 Adam Williamson 2015-10-19 22:16:37 UTC
miroslav: er...did *what* work?

Comment 8 Adam Williamson 2015-10-19 22:16:53 UTC
oh, I see. No, no it didn't.

Comment 9 Miroslav Grepl 2015-11-10 08:55:59 UTC
Could you please attach AVC messages? Try to reproduce it and run

ausearch -m avc -ts recent

Comment 10 Cole Robinson 2016-04-14 15:51:34 UTC
freeletter.me is a temporary email domain; the users email bounces so we aren't going to get any NEEDINFO. I suggest we just close this