Bug 896706
| Summary: | Openstack-nova-compute is unable to mount image for data injection when selinux is "Enforcing". | ||
|---|---|---|---|
| Product: | Red Hat OpenStack | Reporter: | Perry Myers <pmyers> |
| Component: | openstack-selinux | Assignee: | Lon Hohberger <lhh> |
| Status: | CLOSED DUPLICATE | QA Contact: | Yaniv Kaul <ykaul> |
| Severity: | urgent | Docs Contact: | |
| Priority: | high | ||
| Version: | 2.0 (Folsom) | CC: | alexander.sakhnov, apevec, belmiro.moreira, bfilippov, bloch, breu, d.busby, dwalsh, Jan.van.Eldik, jkt, jliberma, jonathansteffan, jose.castro.leon, markmc, matt_domsch, mgrepl, mlvov, mmalik, ndipanov, pbrady, p, rkukura |
| Target Milestone: | snapshot4 | Keywords: | Triaged |
| Target Release: | 2.1 | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | 876452 | Environment: | |
| Last Closed: | 2013-02-18 20:25:57 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 876452 | ||
| Bug Blocks: | |||
|
Description
Perry Myers
2013-01-17 19:50:05 UTC
We need to see AVC msgs with # setenforce 1 # echo "-w /etc/shadow -p w" >> /etc/audit/audit.rules # service auditd restart # chcon -R -t virt_image_t /var/lib/nova/instances # chcon -R -t ssh_home_t /var/lib/nova/.ssh # setenforce 0 re-test it and # ausearch -m avc -ts recent This #============= svirt_t ============== allow svirt_t self:tun_socket relabelto; allow svirt_t virtd_t:tun_socket relabelfrom; seems strange. Yep, nothing running under 'svirt_t' should be allowed to relabel, nor should it need to either. Let's wait for AVC msgs. Hi Miroslav, please see below and let me know if smth else is needed.
[root@rhel-test ~(keystone_admin)]$ ausearch -m avc -ts recent
----
time->Fri Jan 18 18:33:22 2013
type=PATH msg=audit(1358530402.404:10585): item=0 name="/var/lib/nova/instances/instance-00000003/disk
" inode=396015 dev=fd:00 mode=0100644 ouid=162 ogid=162 rdev=00:00 obj=unconfined_u:object_r:virt_imag
e_t:s0
type=CWD msg=audit(1358530402.404:10585): cwd="/"
type=SYSCALL msg=audit(1358530402.404:10585): arch=c000003e syscall=2 success=yes exit=9 a0=7f5a524e2e
00 a1=84002 a2=0 a3=40 items=1 ppid=16679 pid=16688 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sg
id=0 fsgid=0 tty=(none) ses=193 comm="qemu-kvm" exe="/usr/libexec/qemu-kvm" subj=unconfined_u:system_r
:qemu_t:s0-s0:c0.c1023 key=(null)
type=AVC msg=audit(1358530402.404:10585): avc: denied { dac_override } for pid=16688 comm="qemu-kvm
" capability=1 scontext=unconfined_u:system_r:qemu_t:s0-s0:c0.c1023 tcontext=unconfined_u:system_r:qe
mu_t:s0-s0:c0.c1023 tclass=capability
----
time->Fri Jan 18 18:33:48 2013
type=PATH msg=audit(1358530428.883:10672): item=0 name="/var/lib/nova/instances/_base/c490d5e02656039b
51f0d56fda0d66d200a83c26" inode=395971 dev=fd:00 mode=0100644 ouid=162 ogid=162 rdev=00:00 obj=unconfi
ned_u:object_r:virt_image_t:s0
type=CWD msg=audit(1358530428.883:10672): cwd="/"
type=SYSCALL msg=audit(1358530428.883:10672): arch=c000003e syscall=2 success=yes exit=10 a0=7fff35ab1
cc0 a1=800 a2=0 a3=0 items=1 ppid=1 pid=16969 auid=0 uid=107 gid=107 euid=107 suid=107 fsuid=107 egid=
107 sgid=107 fsgid=107 tty=(none) ses=193 comm="qemu-system-x86" exe="/usr/libexec/qemu-kvm" subj=unco
nfined_u:system_r:svirt_t:s0:c198,c309 key=(null)
type=AVC msg=audit(1358530428.883:10672): avc: denied { open } for pid=16969 comm="qemu-system-x86"
name="c490d5e02656039b51f0d56fda0d66d200a83c26" dev=dm-0 ino=395971 scontext=unconfined_u:system_r:sv
irt_t:s0:c198,c309 tcontext=unconfined_u:object_r:virt_image_t:s0 tclass=file
type=AVC msg=audit(1358530428.883:10672): avc: denied { read } for pid=16969 comm="qemu-system-x86"
name="c490d5e02656039b51f0d56fda0d66d200a83c26" dev=dm-0 ino=395971 scontext=unconfined_u:system_r:sv
irt_t:s0:c198,c309 tcontext=unconfined_u:object_r:virt_image_t:s0 tclass=file
----
time->Fri Jan 18 18:33:48 2013
type=SYSCALL msg=audit(1358530428.883:10673): arch=c000003e syscall=16 success=no exit=-25 a0=a a1=532
6 a2=7fffffff a3=0 items=0 ppid=1 pid=16969 auid=0 uid=107 gid=107 euid=107 suid=107 fsuid=107 egid=10
7 sgid=107 fsgid=107 tty=(none) ses=193 comm="qemu-system-x86" exe="/usr/libexec/qemu-kvm" subj=unconf
ined_u:system_r:svirt_t:s0:c198,c309 key=(null)
type=AVC msg=audit(1358530428.883:10673): avc: denied { ioctl } for pid=16969 comm="qemu-system-x86
" path="/var/lib/nova/instances/_base/c490d5e02656039b51f0d56fda0d66d200a83c26" dev=dm-0 ino=395971 sc
ontext=unconfined_u:system_r:svirt_t:s0:c198,c309 tcontext=unconfined_u:object_r:virt_image_t:s0 tclas
s=file
----
time->Fri Jan 18 18:33:48 2013
type=PATH msg=audit(1358530428.883:10674): item=0 name="/var/lib/nova/instances/_base/c490d5e02656039b
51f0d56fda0d66d200a83c26" inode=395971 dev=fd:00 mode=0100644 ouid=162 ogid=162 rdev=00:00 obj=unconfi
ned_u:object_r:virt_image_t:s0
type=CWD msg=audit(1358530428.883:10674): cwd="/"
type=SYSCALL msg=audit(1358530428.883:10674): arch=c000003e syscall=4 success=yes exit=0 a0=7fff35ab1c
c0 a1=7fff35aafa70 a2=7fff35aafa70 a3=0 items=1 ppid=1 pid=16969 auid=0 uid=107 gid=107 euid=107 suid=
107 fsuid=107 egid=107 sgid=107 fsgid=107 tty=(none) ses=193 comm="qemu-system-x86" exe="/usr/libexec/
qemu-kvm" subj=unconfined_u:system_r:svirt_t:s0:c198,c309 key=(null)
type=AVC msg=audit(1358530428.883:10674): avc: denied { getattr } for pid=16969 comm="qemu-system-x
86" path="/var/lib/nova/instances/_base/c490d5e02656039b51f0d56fda0d66d200a83c26" dev=dm-0 ino=395971
scontext=unconfined_u:system_r:svirt_t:s0:c198,c309 tcontext=unconfined_u:object_r:virt_image_t:s0 tcl
ass=file
Ok, the virt_content_t label will be better # chcon -R -t virt_content_t /var/lib/nova/instances Also are images located in /var/lib/nova? Then "dac_override" is caused by permissions on /var/lib/nova/instances/_base/c490d5e02656039b51f0d56fda0d66d200a83c26 A qemu process does not have permissions (DAC) to access it. Images are in /var/lib/nova/instances (and it's subdirectories, basically every domain (instances) get's it's own subdir). So we have images in subdirs together with random files which are handled to a confined virtual machine. Did/could you test virt_content_t labeling? [root@rhos2 nova(keystone_refarch_user)]$ chcon -R -t virt_content_t /var/lib/nova/instances [root@rhos2 nova(keystone_refarch_user)]$ ls -lZ drwxr-xr-x. nova nova system_u:object_r:nova_var_lib_t:s0 buckets drwxr-xr-x. nova nova system_u:object_r:nova_var_lib_t:s0 CA drwxr-xr-x. nova nova system_u:object_r:nova_var_lib_t:s0 images drwxr-xr-x. nova nova system_u:object_r:virt_content_t:s0 instances drwxr-xr-x. nova nova system_u:object_r:nova_var_lib_t:s0 keys drwxr-xr-x. nova nova system_u:object_r:nova_var_lib_t:s0 networks drwxr-xr-x. nova nova system_u:object_r:nova_var_lib_t:s0 tmp [root@rhos2 ~(keystone_refarch_user)]$ nova boot --flavor 2 --key_name rhos2key --image 1610f2af-f927-4f85-b153-1840d7093756 rhel2d [root@rhos2 ~(keystone_refarch_user)]$ cat /var/log/nova/compute.log [snip] 2013-01-24 17:03:18 INFO nova.virt.libvirt.driver [req-773e48cb-07f7-46c8-8339-623767c16ca8 cdddd81ff8b54c72b928c4f7a47cdb94 59a8a05b07224d889e6149d9f826939d] [instance: 74dd6da7-0a99-417a-951e-20e429c5c0fa] Creating image 2013-01-24 17:03:18 INFO nova.virt.libvirt.driver [req-773e48cb-07f7-46c8-8339-623767c16ca8 cdddd81ff8b54c72b928c4f7a47cdb94 59a8a05b07224d889e6149d9f826939d] [instance: 74dd6da7-0a99-417a-951e-20e429c5c0fa] Injecting key into image 1610f2af-f927-4f85-b153-1840d7093756 2013-01-24 17:03:18 WARNING nova.virt.libvirt.driver [req-773e48cb-07f7-46c8-8339-623767c16ca8 cdddd81ff8b54c72b928c4f7a47cdb94 59a8a05b07224d889e6149d9f826939d] [instance: 74dd6da7-0a99-417a-951e-20e429c5c0fa] Ignoring error injecting data into image 1610f2af-f927-4f85-b153-1840d7093756 ( -- nbd unavailable: module not loaded -- Failed to mount filesystem: Unexpected error while running command. Command: sudo nova-rootwrap /etc/nova/rootwrap.conf guestmount --rw -a /var/lib/nova/instances/instance-00000010/disk -i /tmp/openstack-disk-mount-tmpIQrHo3 Exit code: 1 Stdout: '' Stderr: "libguestfs: error: guestfs_launch failed.\nSee http://libguestfs.org/guestfs-faq.1.html#debugging-libguestfs\nand/or run 'libguestfs-test-tool'.\n") > Failed to mount filesystem: Unexpected error while running command. > Command: sudo nova-rootwrap /etc/nova/rootwrap.conf guestmount --rw -a /var/lib/nova/instances/instance-00000010/disk -i /tmp/openstack-disk-mount-tmpIQrHo3 > Exit code: 1 > Stderr: "libguestfs: error: guestfs_launch failed So even though the instance-$id/ directory is created dynamically it should inherit the context from its parent by default. So given libguestfs is failing (don't mind the nbd error), perhaps it does need virt_image_t. If that doesn't work then I'd run the guestmount command in comment 9 with debugging enabled as per the URL above, which should give better indication as to why it's failing exactly (maybe it's not selinux in this case) Yes, we should have virt_image_t for drwxr-xr-x. nova nova system_u:object_r:nova_var_lib_t:s0 images drwxr-xr-x. nova nova system_u:object_r:virt_content_t:s0 instances images/ is to support a long since removed local image service in nova. I'll remove that from nova packaging to avoid confusion. jliberma and ndipanov have indicated to me that they tried virt_image_t on /var/lib/nova/instances, but it didn't help. Re the DAC issue: $ namei -l /var/lib/nova/instances/instance-00000807/disk f: /var/lib/nova/instances/instance-00000807/disk dr-xr-xr-x root root / drwxr-xr-x root root var drwxr-xr-x root root lib drwxr-xr-x nova nova nova drwxr-xr-x nova nova instances drwxr-xr-x nova nova instance-00000807 -rw-r--r-- root root disk (In reply to comment #10) > > Failed to mount filesystem: Unexpected error while running command. > > Command: sudo nova-rootwrap /etc/nova/rootwrap.conf guestmount --rw -a /var/lib/nova/instances/instance-00000010/disk -i /tmp/openstack-disk-mount-tmpIQrHo3 > > Exit code: 1 > > Stderr: "libguestfs: error: guestfs_launch failed > > So even though the instance-$id/ directory is created dynamically > it should inherit the context from its parent by default. > So given libguestfs is failing (don't mind the nbd error), > perhaps it does need virt_image_t. > > If that doesn't work then I'd run the guestmount command in comment 9 with > debugging enabled as per the URL above, which should give better indication > as to why it's failing exactly (maybe it's not selinux in this case) Something is getting mixed up here. In RHEL-6, libguestfs started QEMU instances are *NOT* confined by sVirt at all. So the AVCs quoted earlier, have nothing todo with this libguestfs failure and thus changing labelling won't affect this. Only the actual VMs started by libvirt are confined by sVirt & has have relevance for labelling. This isn't resolved by the existing openstack-selinux package? Is this a duplicate of bug 896013 ? After rereading the AVCs and talking with Miroslav, I'm pretty sure this is a duplicate. *** This bug has been marked as a duplicate of bug 896013 *** |