Bug 196474 - xend fails to start : x86_64, avc denied errors
xend fails to start : x86_64, avc denied errors
Status: CLOSED DUPLICATE of bug 192813
Product: Fedora
Classification: Fedora
Component: xen (Show other bugs)
6
All Linux
medium Severity medium
: ---
: ---
Assigned To: James Antill
Brian Brock
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2006-06-23 12:18 EDT by Mark McLoughlin
Modified: 2007-11-30 17:11 EST (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2006-07-14 12:57:55 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)

  None (edit)
Description Mark McLoughlin 2006-06-23 12:18:31 EDT
With FC6 test1, on x86_64, with selinux enabled, xend fails to start at boot.

Seeing these selinux errors repeated every time xend start/status runs:

---
avc:  denied  { read write } for  pid=2668 comm="xend" name="0" dev=devpts ino=2
scontext=system_u:system_r:xend_t:s0
tcontext=system_u:object_r:initrc_devpts_t:s0 tclass=chr_file
avc:  denied  { read write } for  pid=2668 comm="xend" name="0" dev=devpts ino=2
scontext=system_u:system_r:xend_t:s0
tcontext=system_u:object_r:initrc_devpts_t:s0 tclass=chr_file
avc:  denied  { read write } for  pid=2668 comm="xend" name="0" dev=devpts ino=2
scontext=system_u:system_r:xend_t:s0
tcontext=system_u:object_r:initrc_devpts_t:s0 tclass=chr_file
avc:  denied  { append } for  pid=2668 comm="python" name="xend.log" dev=dm-0
ino=27690085 scontext=system_u:system_r:xend_t:s0
tcontext=root:object_r:var_log_t:s0 tclass=file
avc:  denied  { search } for  pid=2668 comm="python" name="tmp" dev=dm-0
ino=26705921 scontext=system_u:system_r:xend_t:s0
tcontext=system_u:object_r:tmp_t:s0 tclass=dir
avc:  denied  { search } for  pid=2668 comm="python" name="tmp" dev=dm-0
ino=27688964 scontext=system_u:system_r:xend_t:s0
tcontext=system_u:object_r:tmp_t:s0 tclass=dir
avc:  denied  { read } for  pid=2668 comm="python" name="tmp" dev=dm-0
ino=7635012 scontext=system_u:system_r:xend_t:s0
tcontext=system_u:object_r:usr_t:s0 tclass=lnk_file
avc:  denied  { write } for  pid=2668 comm="python" name="/" dev=dm-0 ino=2
scontext=system_u:system_r:xend_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=dir
---

When trying to debug it by starting it manually (either with service xend start,
/etc/rc.d/init.d/xend start or /usr/sbin/xend start) it eventually works after a
while ... not sure what actually causes it to start working, though.
Comment 1 James Antill 2006-07-14 12:57:55 EDT
 Note that currently I can't get xen+SELinux to work on x86-64 anyway due to
BZ#194292

*** This bug has been marked as a duplicate of 192813 ***

Note You need to log in before you can comment on or make changes to this bug.