Bug 980542
Summary: | SELinux is preventing /usr/bin/qemu-system-x86_64 from 'getattr' accesses on the file /home/crobinso/.cache/libvirt-sandbox/sandbox/config/mounts.cfg. | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Cole Robinson <crobinso> |
Component: | libvirt-sandbox | Assignee: | Daniel Berrangé <berrange> |
Status: | CLOSED DUPLICATE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | unspecified | Docs Contact: | |
Priority: | unspecified | ||
Version: | 19 | CC: | berrange, dominick.grift, dwalsh, mgrepl, virt-maint |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | x86_64 | ||
OS: | Unspecified | ||
Whiteboard: | abrt_hash:3d1d95843354f67d233b2f90248853f0a6056fd341843460c29274b631b09bc2 | ||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2013-10-01 15:29:56 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Cole Robinson
2013-07-02 16:23:46 UTC
I think we need libvirt-sandbox to launch qemu guests with some label other then svirt_t. svirt_t really will only work well with full qemu guest os on an image, not on a pss through file system. That being said we should probaly label ~/.cache/libvirt-sandbox with something like virt_home_t. 1c18f0e8996586f98eefef5b6314bd16a1c116a1 adds labeling for ~/.cache/libvirt-sandbox as virt_home_t. Which would solve this avc. sesearch -A -s svirt_t -t virt_home_t -c file Found 1 semantic av rules: allow virt_domain virt_home_t : file { ioctl getattr lock append open } ; *** This bug has been marked as a duplicate of bug 1000813 *** |