Description of problem: When configuring a virtual machine (using virt-manager) and adding /dev/ttyS0 to this virtual machine, there always comes a SELinux-Error not removeable. Version-Release number of selected component (if applicable): kvm.x86_64 74-10.fc10 installed libselinux.x86_64 2.0.78-1.fc10 installed selinux-policy-minimum.noarch 3.5.13-59.fc10 updates selinux-policy-mls.noarch 3.5.13-59.fc10 updates How reproducible: each time Steps to Reproduce: 1. configuring a virtual machine, 2. adding /dev/ttyS0 to this machine 3. start the machine Sniplet of /etc/libvirt/qemu/<virtual-machine-config>: <serial type="dev"> <source path="/dev/ttyS0"/> <target port="0"/> </serial> Actual results: The SELinux-Alerting-Monitor tells me that I should do a sudo setsebool -P allow_daemons_use_tty=1 But this changes nothing. Each time I start the virutal machine, I got the error. The Virtual Machine also cannot connect to /dev/ttyS0 When doing a "getsebool allow_daemons_use_tty" it tells me "allowed" ??? Expected results: Additional info:
Please include the full SELinux error - e.g. try "ausearch -m AVC -ts recent" Also, please include ~/.virt-manager/virt-manager.log and the log file for the guest from /var/log/libvirt/qemu
Created attachment 346629 [details] Output of the ausearch-command
Created attachment 346630 [details] output of the getsebool-command (you can see, it should be allowed!)
Created attachment 346631 [details] the full selinux-alert entry
Created attachment 346632 [details] virtmanager log (I don't know, but this entries are all completely old??)
Created attachment 346634 [details] logfile of the virtual-machine (/var/log/libvirt/qemu/...)
Thanks Rene dwalsh: this is F10; do we need an init_system_domain(qemu_t) ?
Try # setsebool -P qemu_use_comm 1 setroubleshoot is suggesting the incorrect boolean. I will update the setroubleshoot plugins to report the correct boolean.
Fixed in setroubleshoot-plugins-2.0.18-1
dwalsh: setsebool -P qemu_use_comm 1 worked perfect. Now no error rises (otherwise, /dev/ttyS0 is not available from the virtual-machine, but I guess there is anythink not configured perfect). Regards Rene