Bug 1824375
| Summary: | Unable to create lockspace /var/lib/libvirt/lockd/files: Permission denied | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux Advanced Virtualization | Reporter: | yafu <yafu> |
| Component: | libvirt | Assignee: | Daniel Berrangé <berrange> |
| Status: | CLOSED WONTFIX | QA Contact: | yafu <yafu> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 8.2 | CC: | berrange, chhu, jdenemar, jsuchane, lmen, virt-maint, xuzhang, yalzhang |
| Target Milestone: | rc | Keywords: | TestOnly, Triaged |
| Target Release: | 8.3 | Flags: | pm-rhel:
mirror+
|
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2021-10-16 07:27:06 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1832756 | ||
| Bug Blocks: | |||
(In reply to yafu from comment #0) > # ausearch -m AVC -ts boot | grep -i lockd > type=AVC msg=audit(1587006887.874:515): avc: denied { write } for > pid=1515 comm="virtlockd" name="libvirt" dev="dm-0" ino=4428423 > scontext=system_u:system_r:virtlogd_t:s0-s0:c0.c1023 > tcontext=system_u:object_r:virt_var_lib_t:s0 tclass=dir permissive=0 This is odd - it seems to say "virtlockd" is running with "virtlogd_t" context. Can you run "ps -axuZ" to show the context of the virtlockd process and also of the virlogd process. (In reply to Daniel Berrangé from comment #1) > (In reply to yafu from comment #0) > > # ausearch -m AVC -ts boot | grep -i lockd > > type=AVC msg=audit(1587006887.874:515): avc: denied { write } for > > pid=1515 comm="virtlockd" name="libvirt" dev="dm-0" ino=4428423 > > scontext=system_u:system_r:virtlogd_t:s0-s0:c0.c1023 > > tcontext=system_u:object_r:virt_var_lib_t:s0 tclass=dir permissive=0 > > This is odd - it seems to say "virtlockd" is running with "virtlogd_t" > context. > > Can you run "ps -axuZ" to show the context of the virtlockd process and also > of the virlogd process. It seems "virtlockd" is running with "virtlogd_t" context indeed: # ps auxZ | grep -i virtlockd system_u:system_r:virtlogd_t:s0-s0:c0.c1023 root 121706 0.0 0.2 403220 16148 ? Ss 04:05 0:00 /usr/sbin/virtlockd Thanks, this is indeed an SELinux policy bug, I have filed as bug 1832756 After evaluating this issue, there are no plans to address it further or fix it in an upcoming release. Therefore, it is being closed. If plans change such that this issue will be fixed in an upcoming release, then the bug can be reopened. |
Description of problem: Unable to create lockspace /var/lib/libvirt/lockd/files: Permission denied Version-Release number of selected component (if applicable): libvirt-daemon-6.0.0-17.el8.x86_64 selinux-policy-3.14.3-41.el8_2.1.noarch How reproducible: 100% Steps to Reproduce: 1. Set qemu.conf: lock_manager = "lockd" 2.Set qemu-lockd.conf file_lockspace_dir = "/var/lib/libvirt/lockd/files" 3.Restart libvirtd service #systemctl restart libvirtd 4.Connect to libvirtd: #virsh list error: failed to connect to the hypervisor error: Cannot recv data: Connection reset by peer 5.Check syslog: #cat /var/log/messages Apr 16 11:18:13 yafu-1 journal[2220]: Unable to create lockspace /var/lib/libvirt/lockd/files: Permission denied Apr 16 11:18:13 yafu-1 journal[2220]: Initialization of QEMU state driver failed: Unable to create lockspace /var/lib/libvirt/lockd/files: Permission denied Apr 16 11:18:13 yafu-1 journal[2220]: Driver state initialization failed ... Apr 16 11:18:13 yafu-1 systemd[1]: Starting Virtualization daemon... Apr 16 11:18:13 yafu-1 systemd[1]: Started Virtualization daemon. Apr 16 11:18:14 yafu-1 setroubleshoot[2238]: SELinux is preventing virtlockd from write access on the directory libvirt. For complete SELinux messages run: sealert -l 237a638c-1807-42b2-97fc-c243169b7e8f Apr 16 11:18:14 yafu-1 platform-python[2238]: SELinux is preventing virtlockd from write access on the directory libvirt.#012#012***** Plugin catchall (100. confidence) suggests **************************#012#012If you believe that virtlockd should be allowed write access on the libvirt directory by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'virtlockd' --raw | audit2allow -M my-virtlockd#012# semodule -X 300 -i my-virtlockd.pp#012 ... Actual results: Permission denied when creating lockspace /var/lib/libvirt/lockd/files Expected results: Create lockspace /var/lib/libvirt/lockd/files successfully. Additional info: # ausearch -m AVC -ts boot | grep -i lockd type=AVC msg=audit(1587006887.874:515): avc: denied { write } for pid=1515 comm="virtlockd" name="libvirt" dev="dm-0" ino=4428423 scontext=system_u:system_r:virtlogd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:virt_var_lib_t:s0 tclass=dir permissive=0