Description of problem: Trying to create a Xen domain with "xm create" using a boot.iso underneath an autofs mount point fails with AVC denials. Version-Release number of selected component (if applicable): xen-3.0.3-8.el5 kernel-xen-2.6.18-1.2746.el5 selinux-policy-targeted-2.4.3-6.el5 How reproducible: 100% Steps to Reproduce: 1. Run "xm create" with a xen config file specifying a cdrom on an autofs mount point, ie. something like --- disk = [ 'phy:/dev/spectre/xentmp2,hda,w', 'file:/net/nfshost/redhat/rhel5/x86_64/images/boot.iso,hdc:cdrom,r', ] Actual results: # xm create -c xentmp2 Using config file "/etc/xen/xentmp2". Error: Disk image does not exist: /mnt/m1/disk/new/redhat/rhel5/x86_64/images/boot.iso # aureport -a ... 395. 11/09/2006 04:51:22 PM python system_u:system_r:xend_t:s0 4 dir search system_u:object_r:autofs_t:s0 denied 49 396. 11/09/2006 04:51:26 PM python system_u:system_r:xend_t:s0 4 dir search system_u:object_r:autofs_t:s0 denied 50 Expected results: Xen guest should be created, install should proceed. Additional info: Using a direct NFS mount rather than autofs seems to work fine.
Fixed in selinux-policy-2.4.3-8
Gets a little further, then fails with: 399. 11/09/2006 08:39:50 PM python system_u:system_r:xend_t:s0 4 dir read system_u:object_r:autofs_t:s0 denied 86
Stephen can you run in permissive mode and grab all the avc messages?
Fixed in selinux-policy-2.4.3-10.el5
A package has been built which should help the problem described in this bug report. This report is therefore being closed with a resolution of CURRENTRELEASE. You may reopen this bug report if the solution does not work for you.