Hide Forgot
libvirt in RHEL-7.3 is rebasing to version 1.3.1, so we'll want this upstream policy enhancement pulled into RHEL 7.3 too +++ This bug was initially created as a clone of Bug #1311576 +++ Description of problem: The virtlogd daemon is currently given the same context as libvirtd. This is essentially unrestricted host access which is not at all desirable. The virtlogd daemon is a small single purpose daemon whose only job is logging. It should have a dedicated context which strictly controls what it is permitted todo. I have written a policy that can do this and submitted upstream https://github.com/fedora-selinux/selinux-policy/pull/103
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2016-2283.html