Created attachment 1391577 [details] audit log compute-0 Description of problem: Live migration on OSPd10 DPDK environment works only when selinux disabled. type=AVC msg=audit(1517843158.974:783): avc: denied { read write } for pid=6944 comm="vhost_thread2" path=2F6D656D66643A76686F73742D6C6F67202864656C6574656429 dev="tmpfs" ino=375313 scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:svirt_tmpfs_t:s0 tclass=file type=SYSCALL msg=audit(1517843158.974:783): arch=c000003e syscall=47 success=yes exit=12 a0=45 a1=7f51ba6ca3b0 a2=0 a3=30 items=0 ppid=1 pid=6944 auid=4294967295 uid=0 gid=107 euid=0 suid=0 fsuid=0 egid=107 sgid=107 fsgid=107 tty=(none) ses=4294967295 comm="vhost_thread2" exe="/usr/sbin/ovs-vswitchd" subj=system_u:system_r:openvswitch_t:s0 key=(null) type=PROCTITLE msg=audit(1517843158.974:783): both audit.log from both compute nodes attached Version-Release number of selected component (if applicable): openstack-selinux-0.8.9-0.1.el7ost.noarch OSPd10 puddle: passed_phase1 - 03-Jan-2018 How reproducible: Always Steps to Reproduce: 1. Install ospd10 + dpdk 2. live migrate instance Actual results: Instance get into error state Expected results: Should migrate to selected hypervisor Additional info:
Created attachment 1391578 [details] audit log compute-1
https://github.com/redhat-openstack/openstack-selinux/commit/4e6703eb4f9e872a802a21c80dd703923e88def7
Live migration is working Run: https://github.com/redhat-openstack/nfv-tempest-plugin/blob/master/nfv_tempest_plugin/tests/scenario/test_nfv_dpdk_usecases.py#L350 No isolcpus
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2018:2102