Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
https://rhn.redhat.com/errata/RHBA-2015-0904.html
ok selinux-policy-targeted >= 3.12.1-153.el7_0.13 selinux-policy-targeted-3.13.1-23.el7.noarch selinux-policy-targeted-3.7.19-260.el6_6.2.noarch selinux-policy-targeted >= 3.7.19-260.el6_6.2 # sesearch -s logrotate_t -c file -Ad | grep virt_cache_t allow logrotate_t virt_cache_t : file { ioctl read write create getattr setattr lock append unlink link rename open } ; # rpm --scripts -q vdsm | sed -n '39,42p' # hack until we replace core dump with abrt if /usr/sbin/selinuxenabled; then /usr/sbin/semanage fcontext -a -t virt_cache_t '/var/log/core(/.*)?' fi # ls -ldZ /var/log/core drwxrwxrwt. root root system_u:object_r:virt_cache_t:s0 /var/log/core # grep logrotate /var/log/audit/audit.log after `pkill -ABRT qemu-kvm' # ls -ltZ /var/log/core/ -rw-------. qemu qemu system_u:object_r:virt_cache_t:s0:c224,c555 core.13354.1426079856.dump after running vdsm logrotate "script": # ls -lZ /var/log/core/ -rw-------. qemu qemu system_u:object_r:virt_cache_t:s0:c224,c555 core.13354.1426079856.dump.1.xz