Bugzilla (bugzilla.redhat.com) will be under maintenance for infrastructure upgrades and will not be available on July 31st between 12:30 AM - 05:30 AM UTC. We appreciate your understanding and patience. You can follow status.redhat.com for details.
Bug 1884276 - Pod with kata-runtime won't start, QEMU: "vhost_user_dev init failed, Operation not permitted" [mkdtemp failing in sandboxing]
Summary: Pod with kata-runtime won't start, QEMU: "vhost_user_dev init failed, Operati...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux Advanced Virtualization
Classification: Red Hat
Component: qemu-kvm
Version: 8.3
Hardware: x86_64
OS: Linux
high
high
Target Milestone: rc
: 8.3
Assignee: Dr. David Alan Gilbert
QA Contact: menli@redhat.com
URL:
Whiteboard:
: 1890718 (view as bug list)
Depends On: 1880932
Blocks: 1889306
TreeView+ depends on / blocked
 
Reported: 2020-10-01 14:13 UTC by Jens Freimann
Modified: 2020-11-17 17:52 UTC (History)
18 users (show)

Fixed In Version: qemu-kvm-5.1.0-14.module+el8.3.0+8438+644aff69
Doc Type: If docs needed, set a value
Doc Text:
Clone Of: 1880932
: 1889306 (view as bug list)
Environment:
Last Closed: 2020-11-17 17:51:44 UTC
Type: Bug
Target Upstream Version:


Attachments (Terms of Use)

Comment 1 Jens Freimann 2020-10-06 14:10:20 UTC
A patch was posted by stefanha on qemu-devel, subject "[PATCH] virtiofsd: avoid /proc/self/fd tempdir"

It gets rid of the temporary directy, this means it fixes our problem and we don't
need an additonal fix of the SELinux rules.

Fabiano and I tested it and verified that it solves the problem we see here.

Comment 4 Danilo Cesar Lemes de Paula 2020-10-08 14:02:54 UTC
Moving it back to ASSIGNED.
This is targeting av-8.3.0, no patch has been posted in the downstream list.

Comment 6 Cameron Meadors 2020-10-08 14:49:15 UTC
I will be verifying this from through my kata conntainers testing with openshift.

Comment 8 Danilo Cesar Lemes de Paula 2020-10-08 18:16:31 UTC
Since there's commitment to get this done, and since Jens is already working to backport the ptach, I believe we can grant devel+ on that premise.

Comment 9 Cameron Meadors 2020-10-09 14:57:11 UTC
I have verified the fix works on scratch build.  Pods can stop and start.

Cluster version is 4.6.0-0.nightly-2020-10-06-122805

One the nodes:
# rpm -qa qemu*
qemu-kvm-core-4.2.0-32.module+el8.2.1+6815+1c792dc8.1.jfreiman202010081315.x86_64
qemu-img-4.2.0-32.module+el8.2.1+6815+1c792dc8.1.jfreiman202010081315.x86_64
qemu-kvm-common-4.2.0-32.module+el8.2.1+6815+1c792dc8.1.jfreiman202010081315.x86_64

From a quick scan, I don't see any obvious errors or warning in logs.

Will retest on official builds with openshift rc when available.

Comment 10 Dr. David Alan Gilbert 2020-10-12 15:46:15 UTC
Commit just landed upstream:

ebf101955ce8f8d72fba virtiofsd: avoid /proc/self/fd tempdir

Comment 11 Dr. David Alan Gilbert 2020-10-12 18:40:06 UTC
Taking this

Comment 16 menli@redhat.com 2020-10-19 07:21:46 UTC
Test regular regression testing on qemu-kvm-5.1.0-14.module+el8.3.0+8438+644aff69 , the change not break normal operation.

change status to verified.

Comment 18 Qian Cai 2020-10-22 21:35:54 UTC
*** Bug 1890718 has been marked as a duplicate of this bug. ***

Comment 20 errata-xmlrpc 2020-11-17 17:51:44 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (virt:8.3 bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2020:5137


Note You need to log in before you can comment on or make changes to this bug.