Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1824375

Summary: Unable to create lockspace /var/lib/libvirt/lockd/files: Permission denied
Product: Red Hat Enterprise Linux Advanced Virtualization Reporter: yafu <yafu>
Component: libvirtAssignee: Daniel Berrangé <berrange>
Status: CLOSED WONTFIX QA Contact: yafu <yafu>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 8.2CC: berrange, chhu, jdenemar, jsuchane, lmen, virt-maint, xuzhang, yalzhang
Target Milestone: rcKeywords: TestOnly, Triaged
Target Release: 8.3Flags: pm-rhel: mirror+
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-16 07:27:06 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1832756    
Bug Blocks:    

Description yafu 2020-04-16 03:35:46 UTC
Description of problem:
Unable to create lockspace /var/lib/libvirt/lockd/files: Permission denied

Version-Release number of selected component (if applicable):
libvirt-daemon-6.0.0-17.el8.x86_64
selinux-policy-3.14.3-41.el8_2.1.noarch

How reproducible:
100%

Steps to Reproduce:
1. Set qemu.conf:
lock_manager = "lockd"

2.Set qemu-lockd.conf
file_lockspace_dir = "/var/lib/libvirt/lockd/files"

3.Restart libvirtd service
#systemctl restart libvirtd

4.Connect to libvirtd:
#virsh list
error: failed to connect to the hypervisor
error: Cannot recv data: Connection reset by peer

5.Check syslog:
#cat /var/log/messages
Apr 16 11:18:13 yafu-1 journal[2220]: Unable to create lockspace /var/lib/libvirt/lockd/files: Permission denied
Apr 16 11:18:13 yafu-1 journal[2220]: Initialization of QEMU state driver failed: Unable to create lockspace /var/lib/libvirt/lockd/files: Permission denied
Apr 16 11:18:13 yafu-1 journal[2220]: Driver state initialization failed
...
Apr 16 11:18:13 yafu-1 systemd[1]: Starting Virtualization daemon...
Apr 16 11:18:13 yafu-1 systemd[1]: Started Virtualization daemon.
Apr 16 11:18:14 yafu-1 setroubleshoot[2238]: SELinux is preventing virtlockd from write access on the directory libvirt. For complete SELinux messages run: sealert -l 237a638c-1807-42b2-97fc-c243169b7e8f
Apr 16 11:18:14 yafu-1 platform-python[2238]: SELinux is preventing virtlockd from write access on the directory libvirt.#012#012*****  Plugin catchall (100. confidence) suggests   **************************#012#012If you believe that virtlockd should be allowed write access on the libvirt directory by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'virtlockd' --raw | audit2allow -M my-virtlockd#012# semodule -X 300 -i my-virtlockd.pp#012
...


Actual results:
Permission denied when creating lockspace /var/lib/libvirt/lockd/files

Expected results:
Create lockspace /var/lib/libvirt/lockd/files successfully.

Additional info:
#  ausearch -m AVC -ts boot  | grep -i lockd
type=AVC msg=audit(1587006887.874:515): avc:  denied  { write } for  pid=1515 comm="virtlockd" name="libvirt" dev="dm-0" ino=4428423 scontext=system_u:system_r:virtlogd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:virt_var_lib_t:s0 tclass=dir permissive=0

Comment 1 Daniel Berrangé 2020-05-06 12:28:54 UTC
(In reply to yafu from comment #0)
> #  ausearch -m AVC -ts boot  | grep -i lockd
> type=AVC msg=audit(1587006887.874:515): avc:  denied  { write } for 
> pid=1515 comm="virtlockd" name="libvirt" dev="dm-0" ino=4428423
> scontext=system_u:system_r:virtlogd_t:s0-s0:c0.c1023
> tcontext=system_u:object_r:virt_var_lib_t:s0 tclass=dir permissive=0

This is odd - it seems to say  "virtlockd" is running with "virtlogd_t" context.

Can you run "ps -axuZ" to show the context of the virtlockd process and also of the virlogd process.

Comment 2 yafu 2020-05-07 08:08:48 UTC
(In reply to Daniel Berrangé from comment #1)
> (In reply to yafu from comment #0)
> > #  ausearch -m AVC -ts boot  | grep -i lockd
> > type=AVC msg=audit(1587006887.874:515): avc:  denied  { write } for 
> > pid=1515 comm="virtlockd" name="libvirt" dev="dm-0" ino=4428423
> > scontext=system_u:system_r:virtlogd_t:s0-s0:c0.c1023
> > tcontext=system_u:object_r:virt_var_lib_t:s0 tclass=dir permissive=0
> 
> This is odd - it seems to say  "virtlockd" is running with "virtlogd_t"
> context.
> 
> Can you run "ps -axuZ" to show the context of the virtlockd process and also
> of the virlogd process.

It seems "virtlockd" is running with "virtlogd_t" context indeed:
# ps auxZ | grep -i virtlockd
system_u:system_r:virtlogd_t:s0-s0:c0.c1023 root 121706 0.0  0.2 403220 16148 ?  Ss   04:05   0:00 /usr/sbin/virtlockd

Comment 3 Daniel Berrangé 2020-05-07 09:01:09 UTC
Thanks, this is indeed an SELinux policy bug, I have filed as bug 1832756

Comment 9 RHEL Program Management 2021-10-16 07:27:06 UTC
After evaluating this issue, there are no plans to address it further or fix it in an upcoming release.  Therefore, it is being closed.  If plans change such that this issue will be fixed in an upcoming release, then the bug can be reopened.