Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1542107 - Live migration fails on OSPd10 DPDK env because of selinux denied
Live migration fails on OSPd10 DPDK env because of selinux denied
Status: CLOSED ERRATA
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-selinux (Show other bugs)
10.0 (Newton)
Unspecified Unspecified
high Severity high
: async
: 10.0 (Newton)
Assigned To: Lon Hohberger
Yariv
: TestOnly, Triaged, ZStream
Depends On:
Blocks: 1527532 1543165 1543166
  Show dependency treegraph
 
Reported: 2018-02-05 10:14 EST by Eyal Dannon
Modified: 2018-06-27 19:35 EDT (History)
14 users (show)

See Also:
Fixed In Version: openstack-selinux-0.8.13-2.el7ost
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 1543165 1543166 (view as bug list)
Environment:
Last Closed: 2018-06-27 19:33:21 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
audit log compute-0 (380.44 KB, text/plain)
2018-02-05 10:14 EST, Eyal Dannon
no flags Details
audit log compute-1 (336.17 KB, text/plain)
2018-02-05 10:15 EST, Eyal Dannon
no flags Details


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:2102 None None None 2018-06-27 19:35 EDT

  None (edit)
Description Eyal Dannon 2018-02-05 10:14:35 EST
Created attachment 1391577 [details]
audit log compute-0

Description of problem:

Live migration on OSPd10 DPDK environment works only when selinux disabled.

type=AVC msg=audit(1517843158.974:783): avc:  denied  { read write } for  pid=6944 comm="vhost_thread2" path=2F6D656D66643A76686F73742D6C6F67202864656C6574656429 dev="tmpfs" ino=375313 scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:svirt_tmpfs_t:s0 tclass=file
type=SYSCALL msg=audit(1517843158.974:783): arch=c000003e syscall=47 success=yes exit=12 a0=45 a1=7f51ba6ca3b0 a2=0 a3=30 items=0 ppid=1 pid=6944 auid=4294967295 uid=0 gid=107 euid=0 suid=0 fsuid=0 egid=107 sgid=107 fsgid=107 tty=(none) ses=4294967295 comm="vhost_thread2" exe="/usr/sbin/ovs-vswitchd" subj=system_u:system_r:openvswitch_t:s0 key=(null)
type=PROCTITLE msg=audit(1517843158.974:783): 

both audit.log from both compute nodes attached

Version-Release number of selected component (if applicable):
openstack-selinux-0.8.9-0.1.el7ost.noarch
OSPd10 puddle: passed_phase1 - 03-Jan-2018

How reproducible:
Always

Steps to Reproduce:
1. Install ospd10 + dpdk
2. live migrate instance

Actual results:
Instance get into error state

Expected results:
Should migrate to selected hypervisor

Additional info:
Comment 1 Eyal Dannon 2018-02-05 10:15 EST
Created attachment 1391578 [details]
audit log compute-1
Comment 20 errata-xmlrpc 2018-06-27 19:33:21 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2018:2102

Note You need to log in before you can comment on or make changes to this bug.