Red Hat Bugzilla – Bug 250452
SElinux prevents brctl (called from libvirtd init script) setting up virbr0
Last modified: 2007-11-30 17:12:12 EST
Description of problem:
On current up to date F7 the virbr0 interface for virtual machines is not
created with selinux in enforcing mode.
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1. Boot F7 system, starting libvirtd
2. Inspect list of network interfaces.
Also, 'service libvirtd restart' also generates the same error.
No virbr0 appears
libvirtd sets up virbr0
Booting the system with enforcing=0 works as expected, and the virbr0 bridge
interface is created. With selinux in enforcing mode the interface is not
created (though libvirtd otherwise starts up), and se-troubleshoot reports:
"SELinux is preventing /usr/sbin/brctl (brctl_t) "getattr" to /sys/class/net
/virbr0/bridge/forward_delay (sysfs_t)." (corresponding sealert output
Created attachment 160444 [details]
sealert output corresponding to the quoted setroubleshoot log message
Fixed in selinux-policy-2.6.4-30.fc7
I've retried with selinux-policy-2.6.4-30.fc7 from updates-testing, and it has
indeed fixed it; thanks.