Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 1143834

Summary: [graphical buffers]start guest failed when graphics defaultMode='secure', meanwhile add eight different channels mode='insecure'
Product: Red Hat Enterprise Linux 6 Reporter: vivian zhang <vivianzhang>
Component: libvirtAssignee: Pavel Hrdina <phrdina>
Status: CLOSED WONTFIX QA Contact: Virtualization Bugs <virt-bugs>
Severity: medium Docs Contact:
Priority: medium    
Version: 6.6CC: dyuan, hliu, libvirt-maint, mzhan, rbalakri, virt-bugs, ydu, zhwang, zpeng
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: 1143832 Environment:
Last Closed: 2015-01-20 12:47:02 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1143832    
Bug Blocks:    

Description vivian zhang 2014-09-18 05:59:09 UTC
+++ This bug was initially created as a clone of Bug #1143832 +++

Description of problem:
[graphical buffers]start guest failed when graphics defaultMode='secure', meanwhile add eight different channels mode='insecure'.

Version-Release number of selected component (if applicable):
libvirt-1.2.8-2.el7.x86_64
qemu-kvm-rhev-2.1.0-3.el7.x86_64
kernel-3.10.0-150.el7.x86_64


How reproducible:
100%

Steps to Reproduce:

1. Prepare a guest with the following content

#virsh dumpxml win7

<graphics type='spice' autoport='yes' listen='0.0.0.0' keymap='en-us' defaultMode='secure'>
      <listen type='address' address='0.0.0.0'/>
      <channel name='main' mode='insecure'/>
      <channel name='display' mode='insecure'/>
      <channel name='inputs' mode='insecure'/>
      <channel name='cursor' mode='insecure'/>
      <channel name='playback' mode='insecure'/>
      <channel name='record' mode='insecure'/>
      <channel name='smartcard' mode='insecure'/>
      <channel name='usbredir' mode='insecure'/>
    </graphics>
2. configure host to tls env for spice ssl connection,restart libvirtd service.

3. start the guest failed, there is an error reported.

## virsh start win7
error: Failed to start domain win7
error: internal error: process exited while connecting to monitor: 2014-09-18T05:18:28.616213Z qemu-kvm: spice: tried to setup tls-channel without specifying a TLS port

4.when delete any one of the channels, start guest again, it will be successful.

#virsh dumpxml win7

<graphics type='spice' autoport='yes' listen='0.0.0.0' keymap='en-us' defaultMode='secure'>
      <listen type='address' address='0.0.0.0'/>
      <channel name='main' mode='insecure'/>
      <channel name='inputs' mode='insecure'/>
      <channel name='cursor' mode='insecure'/>
      <channel name='playback' mode='insecure'/>
      <channel name='record' mode='insecure'/>
      <channel name='smartcard' mode='insecure'/>
      <channel name='usbredir' mode='insecure'/>
    </graphics>

# virsh start win7
Domain win7 started

5. the issue also hit on RHEL6.6

Actual results:
when configure graphics defaultMode='secure', meanwhile add eight different channel mode='insecure', start guest failed with error.


Expected results:
when configure graphics defaultMode='secure', meanwhile add eight different channel mode='insecure', start guest success.

Additional info:
reference the libvirt org about defaultMode:
The defaultMode attribute sets the default channel security policy, valid values are secure, insecure and the default any (which is secure if possible, but falls back to insecure rather than erroring out if no secure path is available). "defaultMode" since 0.9.12.
When SPICE has both a normal and TLS secured TCP port configured, it can be desirable to restrict what channels can be run on each port. This is achieved by adding one or more <channel> elements inside the main <graphics> element and setting the mode attribute to either secure or insecure. Setting the mode attribute overrides the default value as set by the defaultMode attribute. (Note that specifying any as mode discards the entry as the channel would inherit the default mode anyways) Valid channel names include main, display, inputs, cursor, playback, record (all since 0.8.6); smartcard (since 0.8.8); and usbredir (since 0.9.12).