Red Hat Bugzilla – Bug 1027076
Fail to start lxc with disabled selinux due to the existed empty /selinux
Last modified: 2015-03-05 02:25:43 EST
Description of problem:
Fail to start lxc with disabled selinux due to the existed empaty /selinux
Version-Release number of selected component (if applicable):
Steps to Reproduce:
There is a dir /selinux , generated by the system
# cat /etc/selinux/config | grep disabled
# disabled - No SELinux policy is loaded.
3.After that , the selinux DOESN't remove the dir /selinux but clean all content in it.
#ll -a /selinux/
drwxr-xr-x. 2 root root 4096 Oct 12 11:28 .
dr-xr-xr-x. 25 root root 4096 Oct 12 13:52 ..
4.This lead to lxc fail to start:
#virsh -c lxc:/// start toy
error: Failed to start domain toy
error: internal error guest failed to start: PATH=/bin:/sbin TERM=linux container=lxc-libvirt container_uuid=bb428983-cb9f-4702-0f8d-7d4e143d9aad LIBVIRT_LXC_UUID=bb428983-cb9f-4702-0f8d-7d4e143d9aad LIBVIRT_LXC_NAME=toy /bin/sh
error receiving signal from container: Input/output error
If remove the dir , everthing will be fine.
And on rhel7 , there is no /selinux , so it has not effect.
Please attach both daemon and machine logs, thanks.
This should be fixed upstream with commit v1.1.4-22-g9ecbd38:
Author: Daniel P. Berrange <email@example.com>
Date: Mon Oct 7 13:12:15 2013 +0100
Skip any files which are not mounted on the host
Created attachment 867312 [details]
Created attachment 867313 [details]
Created attachment 867314 [details]
logs generated basing on
Thank you very much, that confirms my hypothesis.
This bug was not selected to be addressed in Red Hat Enterprise Linux 6. We will look at it again within the Red Hat Enterprise Linux 7 product.
In RHEL7 this can't be reproduced. So, I would change this to verified status
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.