RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Bug 592382 - Small typo: xend mentioned instead of kvm in RHEL 6 beta Virtualization Guide
Summary: Small typo: xend mentioned instead of kvm in RHEL 6 beta Virtualization Guide
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: doc-Virtualization_Administration_Guide
Version: 6.1
Hardware: All
OS: Linux
low
medium
Target Milestone: rc
: ---
Assignee: Christopher Curran
QA Contact: ecs-bugs
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-05-14 17:46 UTC by Justin Clift
Modified: 2011-12-06 01:04 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2010-08-31 04:23:30 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Justin Clift 2010-05-14 17:46:08 UTC
Description of problem:

"xend" is mentioned in the RHEL 6 beta (April 2010) Virtualization Guide where it should probably say KVM instead:

  http://www.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6-Beta/html/Virtualization/sect-Virtualization-Troubleshooting_Xen-Troubleshooting_with_serial_consoles.html

  29.3. Troubleshooting with serial consoles
  "logging output with xend is unavailable"

Comment 2 Christopher Curran 2010-05-19 01:02:19 UTC
Fixed in build 21. This fix should be live soon.

Chris

Comment 3 Justin Clift 2010-05-21 10:52:16 UTC
Hi Chris,

Same problem here:

  http://www.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6-Beta/html/Virtualization/chap-Virtualization-Security_for_virtualization.html

Mentions of Xen and dom0:

  The host, in the Xen hypervisor, is a privileged domain that handles system
  management and manages all virtual machines. If the host is insecure, all
  other domains in the system are vulnerable.

  + Use a firewall to restrict traffic to dom0. You can setup a firewall with
    default-reject rules that will help secure attacks on dom0. It is also
    important to limit network facing services.

  + Do not allow normal users to access dom0. If you do permit normal users dom0
    access, you run the risk of rendering dom0 vulnerable. Remember, dom0 is
    privileged, and granting unprivileged accounts may compromise the level of
    security. 

Do you want this filed as a separate bug, or is here ok?

Comment 4 Justin Clift 2010-05-21 11:04:00 UTC
Similar here:

  http://www.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6-Beta/html/Virtualization/sect-Virtualization-Security_for_virtualization-SELinux_and_virtualization.html

  5. Set the correct SELinux type for the Xen folder.

     semanage fcontext -a -t xen_image_t "/virtualization(/.*)?"

     Alternatively, set the correct SELinux type for a KVM folder.

     semanage fcontext -a -t virt_image_t "/virtualization(/.*)?"


Is it worth swapping the Xen and KVM entries around, for first emphasis on KVM?

Comment 5 Justin Clift 2010-05-21 12:01:52 UTC
This looks like a carry over from RHEL 5 as well:

  http://www.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6-Beta/html/Virtualization/sect-Virtualization-Security_for_virtualization-SELinux_considerations.html

  "The Boolean parameter xend_disable_t can set the xend to unconfined mode after restarting the daemon. It is better to disable protection for a single daemon than the whole system. It is advisable that you should not re-label directories as xen_image_t that you will use elsewhere."

Comment 6 RHEL Program Management 2010-06-07 15:54:24 UTC
This request was evaluated by Red Hat Product Management for inclusion in a Red
Hat Enterprise Linux major release.  Product Management has requested further
review of this request by Red Hat Engineering, for potential inclusion in a Red
Hat Enterprise Linux Major release.  This request is not yet committed for
inclusion.


Note You need to log in before you can comment on or make changes to this bug.