Bug 2278889 - Running qemu session VMs is not working if swtpm is used and SELinux is enabled
Summary: Running qemu session VMs is not working if swtpm is used and SELinux is enabled
Keywords:
Status: CLOSED DUPLICATE of bug 2278905
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 40
Hardware: x86_64
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-05-03 13:50 UTC by Jason Montleon
Modified: 2024-05-05 00:15 UTC (History)
9 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2024-05-05 00:15:48 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Jason Montleon 2024-05-03 13:50:42 UTC
It looks like these packages were updated in the last few days:
selinux-policy-targeted-40.17-1.fc40.noarch
swtpm-0.8.1-7.fc40.x86_64
swtpm-selinux-0.8.1-7.fc40.noarch

I have been running three VMs almost daily for months and this morning I could suddenly not start them up.

Reproducible: Always

Steps to Reproduce:
1. Have a VM running under a user account using qemu://session 
2. Run virsh start to start it.
Actual Results:  
When running the virsh start I get the following message:
```
$ virsh start ocp-4
error: Failed to start domain 'ocp-4'
error: operation failed: swtpm died and reported: 

$
```

Expected Results:  
The VM runs

I saw bugs reported already that look similar, but not quite the same. I did not get the sense others were using qemu session and that the socket files in their case were under under $XDG_RUNTIME_DIR/libvirt/qemu/run/swtpm/ or that it manifested exactly the same.

If I misunderstood or it is close enough you want to track under another bug my apologies, and please feel free to mark as a duplicate.

audit.log AVCs:
type=AVC msg=audit(1714741945.528:295): avc:  denied  { create } for  pid=10933 comm="swtpm" name="1-ocp-3-swtpm.sock" scontext=unconfined_u:unconfined_r:svirt_t:s0:c786,c959 tcontext=unconfined_u:object_r:user_tmp_t:s0 tclass=sock_file permissive=0
type=AVC msg=audit(1714741946.202:319): avc:  denied  { create } for  pid=11046 comm="swtpm" name="2-ocp-4-swtpm.sock" scontext=unconfined_u:unconfined_r:svirt_t:s0:c579,c918 tcontext=unconfined_u:object_r:user_tmp_t:s0 tclass=sock_file permissive=0
type=AVC msg=audit(1714741946.897:343): avc:  denied  { create } for  pid=11180 comm="swtpm" name="3-ocp-4-dev-swtpm.sock" scontext=unconfined_u:unconfined_r:svirt_t:s0:c130,c256 tcontext=unconfined_u:object_r:user_tmp_t:s0 tclass=sock_file permissive=0
type=AVC msg=audit(1714742342.918:351): avc:  denied  { create } for  pid=16494 comm="swtpm" name="4-ocp-4-swtpm.sock" scontext=unconfined_u:unconfined_r:svirt_t:s0:c8,c745 tcontext=unconfined_u:object_r:user_tmp_t:s0 tclass=sock_file permissive=0
type=USER_MAC_STATUS msg=audit(1714742362.371:359): pid=2021 uid=81 auid=4294967295 ses=4294967295 subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 msg='avc:  op=setenforce lsm=selinux enforcing=0 res=1 exe="/usr/bin/dbus-broker" sauid=81 hostname=? addr=? terminal=?'UID="dbus" AUID="unset" SAUID="dbus"
type=AVC msg=audit(1714742362.980:360): avc:  denied  { create } for  pid=16810 comm="swtpm" name="5-ocp-4-swtpm.sock" scontext=unconfined_u:unconfined_r:svirt_t:s0:c97,c304 tcontext=unconfined_u:object_r:user_tmp_t:s0 tclass=sock_file permissive=1
type=AVC msg=audit(1714742362.980:361): avc:  denied  { setattr } for  pid=16810 comm="swtpm" name="5-ocp-4-swtpm.sock" dev="tmpfs" ino=416 scontext=unconfined_u:unconfined_r:svirt_t:s0:c97,c304 tcontext=unconfined_u:object_r:user_tmp_t:s0 tclass=sock_file permissive=1
type=AVC msg=audit(1714742366.494:364): avc:  denied  { create } for  pid=16906 comm="swtpm" name="6-ocp-4-dev-swtpm.sock" scontext=unconfined_u:unconfined_r:svirt_t:s0:c569,c969 tcontext=unconfined_u:object_r:user_tmp_t:s0 tclass=sock_file permissive=1
type=AVC msg=audit(1714742366.494:365): avc:  denied  { setattr } for  pid=16906 comm="swtpm" name="6-ocp-4-dev-swtpm.sock" dev="tmpfs" ino=431 scontext=unconfined_u:unconfined_r:svirt_t:s0:c569,c969 tcontext=unconfined_u:object_r:user_tmp_t:s0 tclass=sock_file permissive=1
type=AVC msg=audit(1714742369.708:367): avc:  denied  { create } for  pid=17004 comm="swtpm" name="7-ocp-3-swtpm.sock" scontext=unconfined_u:unconfined_r:svirt_t:s0:c656,c827 tcontext=unconfined_u:object_r:user_tmp_t:s0 tclass=sock_file permissive=1
type=AVC msg=audit(1714742369.708:368): avc:  denied  { setattr } for  pid=17004 comm="swtpm" name="7-ocp-3-swtpm.sock" dev="tmpfs" ino=447 scontext=unconfined_u:unconfined_r:svirt_t:s0:c656,c827 tcontext=unconfined_u:object_r:user_tmp_t:s0 tclass=sock_file permissive=1

Comment 1 Jason Montleon 2024-05-05 00:15:48 UTC
Fixed after installing swtpm-*0.8.1-8.fc40.x86_64

*** This bug has been marked as a duplicate of bug 2278905 ***


Note You need to log in before you can comment on or make changes to this bug.