Bug 517618
| Summary: | SELinux is preventing qemu-kvm (svirt_t) "setrlimit" svirt_t. | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Sascha Thomas Spreitzer <sascha> |
| Component: | kvm | Assignee: | Glauber Costa <gcosta> |
| Status: | CLOSED DUPLICATE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | high | Docs Contact: | |
| Priority: | low | ||
| Version: | 11 | CC: | berrange, clalance, ehabkost, gcosta, markmc, quintela, virt-maint |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2009-08-18 10:47:13 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
Thanks for the report Please try https://admin.fedoraproject.org/updates/F11/FEDORA-2009-8536 from updates-testing *** This bug has been marked as a duplicate of bug 515521 *** |
Description of problem: SELinux is preventing qemu-kvm (svirt_t) "setrlimit" svirt_t. SELinux denied access requested by qemu-kvm. It is not expected that this access is required by qemu-kvm and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. Version-Release number of selected component (if applicable): [~]$ rpm -qa|grep -i kvm qemu-kvm-0.10.5-3.fc11.x86_64 etherboot-zroms-kvm-5.4.4-16.fc11.noarch [~]$ rpm -qa|grep -i virt libvirt-0.6.2-13.fc11.x86_64 virt-viewer-0.0.3-6.fc11.x86_64 python-virtinst-0.400.3-8.fc11.noarch virt-manager-0.7.0-5.fc11.x86_64 virt-top-1.0.3-4.fc11.x86_64 libvirt-python-0.6.2-13.fc11.x86_64 [~]$ rpm -qa|grep -i selinux libselinux-2.0.80-1.fc11.x86_64 libselinux-debuginfo-2.0.80-1.fc11.x86_64 libselinux-2.0.80-1.fc11.i586 libselinux-devel-2.0.80-1.fc11.x86_64 selinux-policy-3.6.12-72.fc11.noarch libselinux-python-2.0.80-1.fc11.x86_64 libselinux-utils-2.0.80-1.fc11.x86_64 selinux-policy-targeted-3.6.12-72.fc11.noarch How reproducible: Everytime powering on a VM. Steps to Reproduce: 1. Start libvirtd 2. Open virt-manager 3. Open VM 4. Start VM Actual results: SElinux preventing VM to run. Expected results: VM should start. Additional info: Switching SElinux into permissive mode allows vm to start. audit.log: node=badcat type=AVC msg=audit(1250325927.403:46): avc: denied { setrlimit } for pid=6193 comm="qemu-kvm" scontext=system_u:system_r:svirt_t:s0:c52,c941 tcontext=system_u:system_r:svirt_t:s0:c52,c941 tclass=process node=badcat type=SYSCALL msg=audit(1250325927.403:46): arch=c000003e syscall=160 success=no exit=-35930152 a0=4 a1=7fff9b4d1810 a2=0 a3=3819217220 items=0 ppid=6188 pid=6193 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm="qemu-kvm" exe="/usr/bin/qemu-kvm" subj=system_u:system_r:svirt_t:s0:c52,c941 key=(null)