Description of problem:
trying to create new VM, with TPM2 enabled
SELinux is preventing rpc-virtqemud from 'relabelfrom' accesses on the diretório tpm2.
***** Plugin catchall (100. confidence) suggests **************************
Se você acredita nisso rpc-virtqemud deve ser permitido relabelfrom acesso no tpm2 directory por padrão.
Then você deve informar que este é um erro.
Você pode gerar um módulo de política local para permitir este acesso.
Do
permitir este acesso por agora executando:
# ausearch -c 'rpc-virtqemud' --raw | audit2allow -M my-rpcvirtqemud
# semodule -X 300 -i my-rpcvirtqemud.pp
Additional Information:
Source Context system_u:system_r:virtqemud_t:s0
Target Context system_u:object_r:virt_var_lib_t:s0
Target Objects tpm2 [ dir ]
Source rpc-virtqemud
Source Path rpc-virtqemud
Port <Desconhecido>
Host (removed)
Source RPM Packages
Target RPM Packages
SELinux Policy RPM selinux-policy-targeted-40.15-1.fc40.noarch
Local Policy RPM selinux-policy-targeted-40.15-1.fc40.noarch
Selinux Enabled True
Policy Type targeted
Enforcing Mode Enforcing
Host Name (removed)
Platform Linux (removed) 6.8.0-63.fc40.1.x86_64 #1 SMP
PREEMPT_DYNAMIC Tue Mar 12 20:12:53 UTC 2024
x86_64
Alert Count 37
First Seen 2024-02-21 11:18:55 -03
Last Seen 2024-03-19 02:14:54 -03
Local ID 39e3c603-edf4-4984-8110-e94d0a142a60
Raw Audit Messages
type=AVC msg=audit(1710825294.887:263): avc: denied { relabelfrom } for pid=6097 comm="rpc-virtqemud" name="tpm2" dev="sda2" ino=2719379 scontext=system_u:system_r:virtqemud_t:s0 tcontext=system_u:object_r:virt_var_lib_t:s0 tclass=dir permissive=1
Hash: rpc-virtqemud,virtqemud_t,virt_var_lib_t,dir,relabelfrom
Version-Release number of selected component:
selinux-policy-targeted-40.15-1.fc40.noarch
Additional info:
reporter: libreport-2.17.15
reason: SELinux is preventing rpc-virtqemud from 'relabelfrom' accesses on the diretório tpm2.
package: selinux-policy-targeted-40.15-1.fc40.noarch
component: selinux-policy
hashmarkername: setroubleshoot
type: libreport
kernel: 6.8.0-63.fc40.1.x86_64
comment: trying to create new VM, with TPM2 enabled
component: selinux-policy
Description of problem: trying to create new VM, with TPM2 enabled SELinux is preventing rpc-virtqemud from 'relabelfrom' accesses on the diretório tpm2. ***** Plugin catchall (100. confidence) suggests ************************** Se você acredita nisso rpc-virtqemud deve ser permitido relabelfrom acesso no tpm2 directory por padrão. Then você deve informar que este é um erro. Você pode gerar um módulo de política local para permitir este acesso. Do permitir este acesso por agora executando: # ausearch -c 'rpc-virtqemud' --raw | audit2allow -M my-rpcvirtqemud # semodule -X 300 -i my-rpcvirtqemud.pp Additional Information: Source Context system_u:system_r:virtqemud_t:s0 Target Context system_u:object_r:virt_var_lib_t:s0 Target Objects tpm2 [ dir ] Source rpc-virtqemud Source Path rpc-virtqemud Port <Desconhecido> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-40.15-1.fc40.noarch Local Policy RPM selinux-policy-targeted-40.15-1.fc40.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 6.8.0-63.fc40.1.x86_64 #1 SMP PREEMPT_DYNAMIC Tue Mar 12 20:12:53 UTC 2024 x86_64 Alert Count 37 First Seen 2024-02-21 11:18:55 -03 Last Seen 2024-03-19 02:14:54 -03 Local ID 39e3c603-edf4-4984-8110-e94d0a142a60 Raw Audit Messages type=AVC msg=audit(1710825294.887:263): avc: denied { relabelfrom } for pid=6097 comm="rpc-virtqemud" name="tpm2" dev="sda2" ino=2719379 scontext=system_u:system_r:virtqemud_t:s0 tcontext=system_u:object_r:virt_var_lib_t:s0 tclass=dir permissive=1 Hash: rpc-virtqemud,virtqemud_t,virt_var_lib_t,dir,relabelfrom Version-Release number of selected component: selinux-policy-targeted-40.15-1.fc40.noarch Additional info: reporter: libreport-2.17.15 reason: SELinux is preventing rpc-virtqemud from 'relabelfrom' accesses on the diretório tpm2. package: selinux-policy-targeted-40.15-1.fc40.noarch component: selinux-policy hashmarkername: setroubleshoot type: libreport kernel: 6.8.0-63.fc40.1.x86_64 comment: trying to create new VM, with TPM2 enabled component: selinux-policy