Bug 698280

Summary: Bad permissions on image after VM is imported by vdsm22
Product: Red Hat Enterprise Linux 6 Reporter: Jakub Libosvar <jlibosva>
Component: vdsmAssignee: Dan Kenigsberg <danken>
Status: CLOSED ERRATA QA Contact: Jakub Libosvar <jlibosva>
Severity: high Docs Contact:
Priority: unspecified    
Version: 6.0CC: abaron, bazulay, danken, iheim, ilvovsky, tbenshos, ykaul
Target Milestone: rcKeywords: Regression, TestBlocker
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: vdsm-4.9-68.el6 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-12-06 07:14:50 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Attachments:
Description Flags
vdsm log none

Description Jakub Libosvar 2011-04-20 15:10:12 UTC
Description of problem:
Machines are imported with 740 permissions instead of 660 - this lead to impossibility of rhel6 host to run VMs.

Version-Release number of selected component (if applicable):
vdsm22-4.5-63.25.el5_6.x86_64

How reproducible:
Always

Steps to Reproduce:
1. Import VM to mixed DC with rhel5.6 SPM 
2. Run VM in 2.3 cluster
  
Actual results:
Run fails

Expected results:
VM runs

Additional info:
Attempt to run fails due to insufficient permissions for image file on storage (740 instead of 660).

Comment 1 Dan Kenigsberg 2011-04-23 18:37:01 UTC
vdsm-4.9 should behave well with images imported by vdsm22-4.5-63.25 or older.

Comment 2 Jakub Libosvar 2011-04-26 08:22:53 UTC
Another way to get to this state is creating snapshot of VM's disk while SPM is host with vdsm22, then start VM on host with vdsm.

Comment 4 Jakub Libosvar 2011-04-26 08:53:45 UTC
Created attachment 494836 [details]
vdsm log

Note that the last two lines are current snapshot that is run
877c881a-6102-4c13-abda-ec781916db24:
total 3487232
-r--r-----. 1 vdsm kvm  349634560 Apr 26 10:17 39e64f31-cb21-4c22-b246-6ef95d55fad3
-rw-rw----. 1 vdsm kvm        356 Apr 26 10:48 39e64f31-cb21-4c22-b246-6ef95d55fad3.meta
-rw-rw----. 1 vdsm kvm 2147483648 Apr 26 09:36 6df175a6-f4c2-442e-b039-b6ab5050b50a
-rw-rw----. 1 vdsm kvm        355 Apr 26 09:36 6df175a6-f4c2-442e-b039-b6ab5050b50a.meta
-rw-rw----. 1 vdsm kvm 1073741824 Apr 26 09:40 d5c5d986-9bfc-49f8-891e-5264984c2fc0
-rw-rw----. 1 vdsm kvm        355 Apr 26 09:47 d5c5d986-9bfc-49f8-891e-5264984c2fc0.meta
-rwxr-----. 1 vdsm kvm     262144 Apr 26 10:48 e15ba7f8-1933-456d-8860-92e2a1126351
-rw-rw----. 1 vdsm kvm        352 Apr 26 10:48 e15ba7f8-1933-456d-8860-92e2a1126351.meta



Thread-17097::ERROR::2011-04-26 10:54:05,692::vm::618::vm.Vm::(_startUnderlyingVm) vmId=`6e273e33-f299-4d88-9906-64b9058f31cd`::Traceback (most recent call last):
  File "/usr/share/vdsm/vm.py", line 588, in _startUnderlyingVm
    self._run()
  File "/usr/share/vdsm/libvirtvm.py", line 815, in _run
    self._connection.createXML(domxml, flags),
  File "/usr/share/vdsm/libvirtconnection.py", line 59, in wrapper
    ret = f(*args, **kwargs)
  File "/usr/lib64/python2.6/site-packages/libvirt.py", line 1353, in createXML
    if ret is None:raise libvirtError('virDomainCreateXML() failed', conn=self)
libvirtError: internal error process exited while connecting to monitor: qemu: could not open disk image /rhev/data-center/3a0599fa-e8fc-4cd2-be47-f2d5f8139af8/d61bcc76-5365-427b-8482-1d43b39bfdf0/images/877c881a-6102-4c13-abda-ec781916db24/e15ba7f8-1933-456d-8860-92e2a1126351: Permission denied

Comment 5 Tomer 2011-05-16 12:11:43 UTC
Scenario to reproduce the bug:

1. Add new cluster(2.3) to existing data center(2.2).
2. Create VM on new cluster.
3. try to run the VM.

VM fails to run due to permission denied when trying to access to snapshot image.

Comment 6 Dan Kenigsberg 2011-05-18 16:25:01 UTC
http://gerrit.usersys.redhat.com/427

Comment 8 Jakub Libosvar 2011-05-26 14:00:47 UTC
Verified using vdsm-4.9-70.el6.x86_64

Comment 9 errata-xmlrpc 2011-12-06 07:14:50 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHEA-2011-1782.html