Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 1670337

Summary: Permission denied when change media for guest started with empty cdrom
Product: Red Hat Enterprise Linux 8 Reporter: Yanqiu Zhang <yanqzhan>
Component: libvirtAssignee: Peter Krempa <pkrempa>
Status: CLOSED CURRENTRELEASE QA Contact: Han Han <hhan>
Severity: high Docs Contact:
Priority: high    
Version: 8.0CC: dyuan, hhan, jdenemar, jsuchane, knoel, mzhan, pkrempa, rbalakri, wchadwic, xuzhang, yafu, yalzhang, yanqzhan
Target Milestone: rcKeywords: Automation, Regression
Target Release: 8.0Flags: rule-engine: mirror+
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: libvirt-4.5.0-21.el8 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 1672259 (view as bug list) Environment:
Last Closed: 2019-06-14 01:07:05 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1652753, 1672259    
Attachments:
Description Flags
libvirtd_qemu_audit_logs none

Description Yanqiu Zhang 2019-01-29 10:39:01 UTC
Description of problem:
If start guest with an empty cdrom, try to change media for it, will fail with 'Permission denied' error.

Version-Release number of selected component (if applicable):
libvirt-4.5.0-20.module+el8+2724+8292f19c.x86_64
qemu-kvm-2.12.0-60.module+el8+2725+0ab65287.x86_64
selinux-policy-3.14.1-52.el8.noarch

How reproducible:
100%

Steps to Reproduce:
1. Start a guest with an extra empty cdrom:
    <disk type='file' device='cdrom'>
      <driver name='qemu'/>
      <target dev='hdc' bus='scsi'/>
      <readonly/>
      <alias name='scsi0-0-0-2'/>
      <address type='drive' controller='0' bus='0' target='0' unit='2'/>
    </disk>

2. Change media for it:
# qemu-img create /var/lib/libvirt/images/test-sr0.img 50M
Formatting '/var/lib/libvirt/images/test-sr0.img', fmt=raw size=52428800

# virsh change-media avocado-vt-vm1 hdc  /var/lib/libvirt/images/test-sr0.img --insert
error: Failed to complete action insert on media
error: internal error: unable to execute QEMU command 'change': Could not open '/var/lib/libvirt/images/test-sr0.img': Permission denied

# cat avocado-vt-vm1.xml-update
    <disk type='file' device='cdrom'>
      <driver name='qemu' type='raw'/>
      <source file='/var/lib/libvirt/images/test-sr0.img'/>
      <backingStore/>
      <target dev='hdc' bus='scsi'/>
      <readonly/>
      <alias name='scsi0-0-0-2'/>
      <address type='drive' controller='0' bus='0' target='0' unit='2'/>
    </disk>
# virsh update-device avocado-vt-vm1 avocado-vt-vm1.xml-update --live
error: Failed to update device from avocado-vt-vm1.xml-update
error: internal error: unable to execute QEMU command 'change': Could not open '/var/lib/libvirt/images/test-sr0.img': Permission denied


Actual results:
As in step3, guest media device update failed with 'Permission denied' error. 

Expected results:
Guest media device should be successfully updated without any error.

Additional info:
1. Guest with the media inserted in cdrom can be started successfully. And then media eject or re-insert can be done successfully. So issue only happens when media change for the guest which was started with empty cdrom.
# virsh edit avocado-vt-vm1
Domain avocado-vt-vm1 XML configuration edited.

# virsh start avocado-vt-vm1
Domain avocado-vt-vm1 started

# virsh dumpxml avocado-vt-vm1|grep 'cdrom' -A8
    <disk type='file' device='cdrom'>
      <driver name='qemu' type='raw'/>
      <source file='/var/lib/libvirt/images/test-sr0.img'/>
      <backingStore/>
      <target dev='hdc' bus='scsi'/>
      <readonly/>
      <alias name='scsi0-0-0-2'/>
      <address type='drive' controller='0' bus='0' target='0' unit='2'/>
    </disk>

#  virsh change-media avocado-vt-vm1 hdc  /var/lib/libvirt/images/test-sr0.img --eject
Successfully ejected media.

#  virsh change-media avocado-vt-vm1 hdc  /var/lib/libvirt/images/test-sr0.img --insert
Successfully inserted media.

2.Not reproduced on following and previous version:
libvirt-4.5.0-18.module+el8+2691+dc742e5d.x86_64
qemu-kvm-2.12.0-58.module+el8+2707+d0d29961.x86_64
selinux-policy-3.14.1-51.el8.noarch

3.Errors in logs:
(a)# cat libvirtd.log |grep error
2019-01-29 09:16:23.784+0000: 25770: debug : qemuMonitorJSONIOProcessLine:197 : Line [{"id": "libvirt-18", "error": {"class": "GenericError", "desc": "Could not open '/var/lib/libvirt/images/test-sr0.img': Permission denied"}}]
2019-01-29 09:16:23.784+0000: 25770: debug : virJSONValueFromString:1814 : string={"id": "libvirt-18", "error": {"class": "GenericError", "desc": "Could not open '/var/lib/libvirt/images/test-sr0.img': Permission denied"}}
2019-01-29 09:16:23.784+0000: 25770: info : qemuMonitorJSONIOProcessLine:217 : QEMU_MONITOR_RECV_REPLY: mon=0x7fe2f802f090 reply={"id": "libvirt-18", "error": {"class": "GenericError", "desc": "Could not open '/var/lib/libvirt/images/test-sr0.img': Permission denied"}}
2019-01-29 09:16:23.784+0000: 25775: debug : virJSONValueToString:2005 : result={"id":"libvirt-18","error":{"class":"GenericError","desc":"Could not open '/var/lib/libvirt/images/test-sr0.img': Permission denied"}}
2019-01-29 09:16:23.784+0000: 25775: debug : qemuMonitorJSONCheckError:385 : unable to execute QEMU command {"execute":"change","arguments":{"device":"drive-scsi0-0-0-2","target":"/var/lib/libvirt/images/test-sr0.img","arg":"raw"},"id":"libvirt-18"}: {"id":"libvirt-18","error":{"class":"GenericError","desc":"Could not open '/var/lib/libvirt/images/test-sr0.img': Permission denied"}}
2019-01-29 09:16:23.784+0000: 25775: error : qemuMonitorJSONCheckError:396 : internal error: unable to execute QEMU command 'change': Could not open '/var/lib/libvirt/images/test-sr0.img': Permission denied
(b)# cat audit.log |grep avc -i
type=AVC msg=audit(1548753383.783:12155): avc:  denied  { write } for  pid=26104 comm="qemu-kvm" name="test-sr0.img" dev="dm-0" ino=67920256 scontext=system_u:system_r:svirt_t:s0:c423,c1007 tcontext=system_u:object_r:virt_content_t:s0 tclass=file permissive=0
type=AVC msg=audit(1548753383.790:12159): avc:  denied  { net_admin } for  pid=26261 comm="dbus-daemon-lau" capability=12  scontext=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 tcontext=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 tclass=capability permissive=0
type=AVC msg=audit(1548753383.790:12160): avc:  denied  { net_admin } for  pid=26261 comm="dbus-daemon-lau" capability=12  scontext=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 tcontext=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 tclass=capability permissive=0
type=AVC msg=audit(1548753383.792:12161): avc:  denied  { noatsecure } for  pid=26261 comm="dbus-daemon-lau" scontext=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 tcontext=system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023 tclass=process permissive=0
type=AVC msg=audit(1548753383.792:12161): avc:  denied  { rlimitinh } for  pid=26261 comm="setroubleshootd" scontext=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 tcontext=system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023 tclass=process permissive=0
type=AVC msg=audit(1548753383.792:12161): avc:  denied  { siginh } for  pid=26261 comm="setroubleshootd" scontext=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 tcontext=system_u:system_r:setroubleshootd_t:s0-s0:c0.c1023 tclass=process permissive=0

Comment 1 Yanqiu Zhang 2019-01-29 10:45:16 UTC
Created attachment 1524559 [details]
libvirtd_qemu_audit_logs

Comment 2 Peter Krempa 2019-02-01 17:01:01 UTC
This is a regression from https://bugzilla.redhat.com/show_bug.cgi?id=1553255

Fix posted upstream:

https://www.redhat.com/archives/libvir-list/2019-February/msg00060.html

Comment 3 Han Han 2019-02-02 02:29:44 UTC
(In reply to Peter Krempa from comment #2)
> This is a regression from https://bugzilla.redhat.com/show_bug.cgi?id=1553255
> 
> Fix posted upstream:
> 
> https://www.redhat.com/archives/libvir-list/2019-February/msg00060.html

Peter, how about make a scratch build today? Chinese new year holiday will start the day after tomorrow... It's better to verify it before the holiday.

Comment 4 Peter Krempa 2019-02-04 08:55:31 UTC
Fixed upstream:

commit 6db0d033839807aec885e10b5a45748da016e261
Author: Peter Krempa <pkrempa>
Date:   Fri Feb 1 17:54:46 2019 +0100

    qemu: command: Don't skip 'readonly' and throttling info for empty drive
    
    In commit f80eae8c2ae I was too agresive in removing properties of
    -drive for empty drives. It turns out that qemu actually persists the
    state of 'readonly' and the throttling information even for the empty
    drive.
    
    Removing 'readonly' thus made qemu open any subsequent images added via
    the 'change' command as RW which was forbidden by selinux thanks to the
    restrictive sVirt label for readonly media.
    
    Fix this by formating the property again and bump the tests and leave a
    note detailing why the rest of the properties needs to be skipped.

Comment 11 Han Han 2019-02-11 02:17:50 UTC
Verified on:
libvirt-4.5.0-21.module+el8+2782+6dbaa538.x86_64
qemu-kvm-2.12.0-60.module+el8+2749+88f75c21.x86_64


1. Start a VM with following disk xml:
    <disk type='file' device='cdrom'>
      <driver name='qemu' type='raw' rerror_policy='stop'/>
      <target dev='sdc' bus='scsi' tray='open'/>
      <readonly/>
      <alias name='scsi0-0-0-2'/>
      <address type='drive' controller='0' bus='0' target='0' unit='2'/>
    </disk>

2. Update disk xml with disk source:
# cat /tmp/scsi.xml
    <disk type='file' device='cdrom'>
      <driver name='qemu' type='raw'/>
      <source file='/var/lib/libvirt/images/test-sr0.img'/>
      <target dev='sdc' bus='scsi'/>
      <readonly/>
<address type='drive' controller='0' bus='0' target='0' unit='2'/>
    </disk>

# virsh update-device q35 /tmp/scsi.xml
Device updated successfully


# virsh dumpxml q35 | awk '/<disk/,/<\/disk/'
    <disk type='file' device='cdrom'>
      <driver name='qemu' type='raw' rerror_policy='stop'/>
      <source file='/var/lib/libvirt/images/test-sr0.img'/>
      <backingStore/>
      <target dev='sdc' bus='scsi'/>
      <readonly/>
      <alias name='scsi0-0-0-2'/>
      <address type='drive' controller='0' bus='0' target='0' unit='2'/>
    </disk>


3. Eject the cdrom media:
# cat /tmp/scsi-empty.xml
    <disk type='file' device='cdrom'>
      <driver name='qemu' type='raw'/>
      <target dev='sdc' bus='scsi'/>
      <readonly/>
      <address type='drive' controller='0' bus='0' target='0' unit='2'/>
    </disk>

# virsh update-device q35 /tmp/scsi-empty.xml
Device updated successfully

# virsh dumpxml q35 | awk '/<disk/,/<\/disk/'
    <disk type='file' device='cdrom'>
      <driver name='qemu' type='raw' rerror_policy='stop'/>
      <target dev='sdc' bus='scsi' tray='open'/>
      <readonly/>
      <alias name='scsi0-0-0-2'/>
      <address type='drive' controller='0' bus='0' target='0' unit='2'/>
    </disk>

Works as expected.

Covered by auto cases:
rhel.virsh.change_media.cdrom_test.scsi_.positive_test.insert.none.running_guest
rhel.virsh.change_media.cdrom_test.scsi_.positive_test.insert.current.running_guest
rhel.virsh.change_media.cdrom_test.scsi_.positive_test.insert.live.running_guest
rhel.virsh.change_media.cdrom_test.scsi_.positive_test.insert.force.running_guest
rhel.virsh.change_media.cdrom_test.scsi_.positive_test.update.none.running_guest
rhel.virsh.change_media.cdrom_test.scsi_.positive_test.update.current.running_guest
rhel.virsh.change_media.cdrom_test.scsi_.positive_test.update.live.running_guest
rhel.virsh.change_media.cdrom_test.scsi_.positive_test.update.force.running_guest