[Bug 849524] New: Xen doesn't start domain with AppArmor
https://bugzilla.novell.com/show_bug.cgi?id=849524 https://bugzilla.novell.com/show_bug.cgi?id=849524#c0 Summary: Xen doesn't start domain with AppArmor Classification: openSUSE Product: openSUSE 13.1 Version: RC 2 Platform: x86-64 OS/Version: Other Status: NEW Severity: Normal Priority: P5 - None Component: AppArmor AssignedTo: suse-beta@cboltz.de ReportedBy: vbotka@suse.com QAContact: qa-bugs@suse.de Found By: Product Management Blocker: --- # uname -a Linux probook 3.11.6-4-xen #1 SMP Wed Oct 30 18:04:56 UTC 2013 (e6d4a27) x86_64 x86_64 x86_64 GNU/Linux # virsh start SUSEManager error: Failed to start domain SUSEManager error: internal error: libxenlight failed to create new domain 'SUSEManager' # cat /var/log/xen/bootloader.4.log libxl: cannot execute /usr/lib64/xen/bin/pygrub: Permission denied With AppArmor disabled the domain starts. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=849524 https://bugzilla.novell.com/show_bug.cgi?id=849524#c1 Christian Boltz <suse-beta@cboltz.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |NEEDINFO InfoProvider| |vbotka@suse.com AssignedTo|suse-beta@cboltz.de |jfehlig@suse.com --- Comment #1 from Christian Boltz <suse-beta@cboltz.de> 2013-11-08 12:53:24 CET --- Sounds like libvirt - handing over to Jim ;-) Vladimir, please attach your /var/log/audit/audit.log - it should contain details what exactly was denied. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=849524 https://bugzilla.novell.com/show_bug.cgi?id=849524#c2 Vladimir Botka <vbotka@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEEDINFO |NEW InfoProvider|vbotka@suse.com | --- Comment #2 from Vladimir Botka <vbotka@suse.com> 2013-11-08 13:53:02 UTC --- Sorry guys, I'm traveling and I'll a have access to the box in 2 weeks again. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=849524 https://bugzilla.novell.com/show_bug.cgi?id=849524#c3 James Fehlig <jfehlig@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED CC| |jdouglas@suse.com Resolution| |FIXED --- Comment #3 from James Fehlig <jfehlig@suse.com> 2013-11-19 21:38:56 UTC --- Sorry for the delay - I too have been traveling a bit lately... I missed this since all of my PV test cases use <bootloader>/usr/bin/pygrub</bootloader> which was allowed by the libvirtd apparmor profile. When specifying only 'pygrub', which is now preferred, /usr/lib64/xen/bin/pygrub is used. I've changed the profile to allow executing all the xen tools under /usr/lib{,64}/bin/xen, since these tools are needed for PV bootloader, save/restore, etc. Fix has been queued for a 13.1 maintenance update and will be applied to the Factory libvirt package as well. Thanks for the report. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=849524 https://bugzilla.novell.com/show_bug.cgi?id=849524#c4 --- Comment #4 from Swamp Workflow Management <swamp@suse.de> 2013-12-16 14:08:32 UTC --- openSUSE-RU-2013:1888-1: An update that has three recommended fixes can now be installed. Category: recommended (important) Bug References: 848918,849524,850882 CVE References: Sources used: openSUSE 13.1 (src): libvirt-1.1.2-2.10.2 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com