Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 622739 - SELinux /usr/bin/qemu-kvm on /dev/net/t
SELinux /usr/bin/qemu-kvm on /dev/net/t
Product: Fedora
Classification: Fedora
Component: selinux-policy-mls (Show other bugs)
x86_64 Linux
low Severity low
: ---
: ---
Assigned To: Miroslav Grepl
Ben Levenson
: 622746 (view as bug list)
Depends On:
  Show dependency treegraph
Reported: 2010-08-10 06:15 EDT by Romain Ferrari
Modified: 2010-08-25 20:57 EDT (History)
2 users (show)

See Also:
Fixed In Version: selinux-policy-3.6.32-121.fc12
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2010-08-25 20:57:11 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Romain Ferrari 2010-08-10 06:15:11 EDT
Contexte source               system_u:system_r:svirt_t:s0:c773,c790
Contexte cible                system_u:system_r:virtd_t:s0-s15:c0.c1023
Objets du contexte            /dev/net/tun [ fd ]
source                        qemu-kvm
Chemin de la source           /usr/bin/qemu-kvm
Port                          <Inconnu>
Hôte                         host01
Paquetages RPM source         qemu-system-x86-0.11.0-13.fc12
Paquetages RPM cible          
Politique RPM                 selinux-policy-3.6.32-118.fc12
Selinux activé               True
Type de politique             mls
Mode strict                   Permissive
Nom du plugin                 catchall
Nom de l'hôte                host01
Plateforme                    Linux host01 #1 SMP Sat
                              Jul 24 05:19:12 UTC 2010 x86_64 x86_64
Compteur d'alertes            1
Première alerte              Tue Aug 10 12:09:04 2010
Dernière alerte              Tue Aug 10 12:09:04 2010
ID local                      829a4f2e-e89f-4d1e-a7ac-5dc998db88ed
Numéros des lignes           

Messages d'audit bruts        

node=host01 type=AVC msg=audit(1281434944.801:37734): avc:  denied  { use } for  pid=2476 comm="qemu-kvm" path="/dev/net/tun" dev=devtmpfs ino=10476 scontext=system_u:system_r:svirt_t:s0:c773,c790 tcontext=system_u:system_r:virtd_t:s0-s15:c0.c1023 tclass=fd

node=host01 type=SYSCALL msg=audit(1281434944.801:37734): arch=c000003e syscall=0 success=yes exit=62 a0=14 a1=134443c a2=11000 a3=7fff62abcff0 items=0 ppid=1 pid=2476 auid=4294967295 uid=107 gid=107 euid=107 suid=107 fsuid=107 egid=107 sgid=107 fsgid=107 tty=(none) ses=4294967295 comm="qemu-kvm" exe="/usr/bin/qemu-kvm" subj=system_u:system_r:svirt_t:s0:c773,c790 key=(null)
Comment 1 Daniel Walsh 2010-08-10 08:25:55 EDT
Miroslav, grab the mls calls out of virt.te in F13.
Comment 2 Daniel Walsh 2010-08-10 08:28:27 EDT
*** Bug 622746 has been marked as a duplicate of this bug. ***
Comment 3 Miroslav Grepl 2010-08-17 06:45:49 EDT
Fixed in selinux-policy-3.6.32-121.fc12
Comment 4 Fedora Update System 2010-08-20 06:27:56 EDT
selinux-policy-3.6.32-121.fc12 has been submitted as an update for Fedora 12.
Comment 5 Fedora Update System 2010-08-21 00:31:40 EDT
selinux-policy-3.6.32-121.fc12 has been pushed to the Fedora 12 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update selinux-policy'.  You can provide feedback for this update here: http://admin.fedoraproject.org/updates/selinux-policy-3.6.32-121.fc12
Comment 6 Fedora Update System 2010-08-25 20:56:34 EDT
selinux-policy-3.6.32-121.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.