All of lore.kernel.org
 help / color / mirror / Atom feed
* XSM: new set of "avc denied"
@ 2015-05-25  9:40 Wei Liu
  2015-05-26  9:13 ` Ian Campbell
  2015-05-26  9:34 ` Jan Beulich
  0 siblings, 2 replies; 4+ messages in thread
From: Wei Liu @ 2015-05-25  9:40 UTC (permalink / raw)
  To: xen-devel; +Cc: Daniel De Graaf, wei.liu2, Ian Campbell

I had a look at Osstest's latest xen-unstable run [0]. With Ian's patch
series we finally passed the point of guest creation on x86.

We now have a new set of "avc denied".

May 24 20:18:05.945118 (XEN) avc:  denied  { get_vnumainfo } for domid=1 scontext=system_u:system_r:domU_t tcontext=system_u:system_r:domU_t_self tclass=domain2

This is HVM loader trying to call get_vnumainfo

May 24 20:28:50.593013 (XEN) avc:  denied  { logdirty } for domid=0 target=3 scontext=system_u:system_r:dom0_t tcontext=system_u:system_r:domU_t tclass=shadow
May 24 20:29:20.721085 (XEN) avc:  denied  { disable } for domid=0 target=3 scontext=system_u:system_r:dom0_t tcontext=system_u:system_r:domU_t tclass=shadow
May 24 20:29:20.737023 (XEN) avc:  denied  { disable } for domid=0 target=3 scontext=system_u:system_r:dom0_t tcontext=system_u:system_r:domU_t tclass=shadow

The above failures made guest local migration test fail for both PV and HVM
guests.

May 24 14:36:47.541016 (XEN) avc:  denied  { writeconsole } for domid=1 scontext=system_u:system_r:domU_t tcontext=system_u:system_r:xen_t tclass=xen

This is PV specific, I think it was due to PV guest was configured to write to
console and XSM (rightfully?) rejected that. My guess is that HVM is not
configured to write to console so I don't see that in HVM test cases.

Wei.

[0] http://logs.test-lab.xenproject.org/osstest/logs/57005/

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2015-05-26 18:20 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-05-25  9:40 XSM: new set of "avc denied" Wei Liu
2015-05-26  9:13 ` Ian Campbell
2015-05-26  9:34 ` Jan Beulich
2015-05-26 18:19   ` Daniel De Graaf

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.