--Apple-Mail=_C012F580-CFC3-4D81-A6D3-CE81FC5FDC78
Content-Type: multipart/alternative;
boundary="Apple-Mail=_9BBC0E85-E36A-488F-8893-571F9F5963A1"
--Apple-Mail=_9BBC0E85-E36A-488F-8893-571F9F5963A1
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
charset=utf-8
This should work but that is a little strange (I=E2=80=99m copying from =
the suggested action)
-------------
If you believe that qemu-kvm should be allowed getattr access on the =
a3f29de7-c6b9-410e-b635-9b3016da7ba2 lnk_file by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# grep qemu-kvm /var/log/audit/audit.log | audit2allow -M mypol
# semodule -i mypol.pp
=E2=80=94=E2=80=94=E2=80=94=E2=80=94=E2=80=94=E2=80=94=E2=80=94=E2=80=94=E2=
=80=94=E2=80=94=E2=80=94
It looks like the qemu-kvm is having access issues on lnk files.
Could you try the above action on node69-02 and see if that resolves the =
issue? It may be a bug.
On Oct 12, 2016, at 9:27 AM,
=D0=9D=D0=B8=D0=BA=D0=BE=D0=BB=D0=B0=D0=B5=D0=
=B2
=D0=90=D0=BB=D0=B5=D0=BA=D1=81=D0=B5=D0=B9 =
<alexeynikolaev.post(a)yandex.ru> wrote:
=20
=20
=20
12.10.2016, 15:53, "Tom Gamull" <tgamull(a)redhat.com =
<mailto:tgamull@redhat.com>>:
> Can you set it to permissive and run
> sealart -a /var/log/audit/audit.log
=20
=20
Added logs to attachment.
=20
=20
=20
=20
=20
>=20
> you may need to install selinux tools
>=20
>> On Oct 12, 2016, at 4:49 AM, =D0=9A=D1=80=D0=B0=D1=81=D0=BD=D0=BE=D0=B1=
=D0=B0=D0=B5=D0=B2 =D0=9C=D0=B8=D1=85=D0=B0=D0=B8=D0=BB <milo1(a)ya.ru =
<mailto:milo1@ya.ru>> wrote:
>>=20
>> Good day,
>>=20
>> had a similar problem, disabling selinux helped.
>>=20
>> Best,
>> Mikhail
>>=20
>> 11.10.2016, 09:55, "=D0=9D=D0=B8=D0=BA=D0=BE=D0=BB=D0=B0=D0=B5=D0=B2 =
=D0=90=D0=BB=D0=B5=D0=BA=D1=81=D0=B5=D0=B9" =
<alexeynikolaev.post(a)yandex.ru <mailto:alexeynikolaev.post@yandex.ru>>:
>>> Hi community!
>>>=20
>>> I have 4 hosts: 2 old servers and 2 new servers
>>> I have this error trying to migrate VM from new host to old one.
>>>=20
>>> Oct 11 09:25:05 node69-06 journal: unsupported configuration: =
Unable
to find security driver for model selinux
>>> Oct 11 09:25:05 node69-06 journal: vdsm vm.Vm ERROR =
vmId=3D`a9473a99-32c6-4548-8b85-dafe4ce8f94f`::unsupported =
configuration: Unable to find security driver for model selinux
>>> Oct 11 09:25:05 node69-06 journal: vdsm vm.Vm ERROR =
vmId=3D`a9473a99-32c6-4548-8b85-dafe4ce8f94f`::Failed to =
migrate#012Traceback (most recent call last):#012 File =
"/usr/share/vdsm/virt/migration.py", line 246, in run#012 =
self._startUnderlyingMigration(time.time())#012 File =
"/usr/share/vdsm/virt/migration.py", line 335, in =
_startUnderlyingMigration#012 None, maxBandwidth)#012 File =
"/usr/share/vdsm/virt/vm.py", line 703, in f#012 ret =3D attr(*args, =
**kwargs)#012 File =
"/usr/lib/python2.7/site-packages/vdsm/libvirtconnection.py", line 119, =
in wrapper#012 ret =3D f(*args, **kwargs)#012 File =
"/usr/lib64/python2.7/site-packages/libvirt.py", line 1825, in =
migrateToURI2#012 if ret =3D=3D -1: raise libvirtError =
('virDomainMigrateToURI2() failed', dom=3Dself)#012libvirtError: =
unsupported configuration: Unable to find security driver for model =
selinux
>>>=20
>>> Migration from OLD host to another OLD host have not any problems.
>>> Migration from NEW host to another NEW host have not any problems.
>>> Migration from OLD host to NEW host have not any problems.
>>>=20
>>> Migration is not work only from NEW to OLD.
>>>=20
>>> oVirt Engine Version: 3.5.6.2-1.el6
>>>=20
>>> All hosts:
>>> OS Version: RHEL - 7 - 2.1511.el7.centos.2.10
>>> Kernel Version: 3.10.0 - 327.36.1.el7.x86_64
>>> KVM Version: 2.3.0 - 29.1.el7
>>> LIBVIRT Version: libvirt-1.2.17-13.el7_2.5
>>> VDSM Version: vdsm-4.16.30-0.el7.centos
>>>=20
>>> Any ideas? Thx.
>>> ,
>>> _______________________________________________
>>> Users mailing list
>>> Users(a)ovirt.org <mailto:Users@ovirt.org>
>>>
http://lists.ovirt.org/mailman/listinfo/users =
<
http://lists.ovirt.org/mailman/listinfo/users>
>>=20
>>=20
>>=20
>> _______________________________________________
>> Users mailing list
>> Users(a)ovirt.org <mailto:Users@ovirt.org>
>>
http://lists.ovirt.org/mailman/listinfo/users =
<
http://lists.ovirt.org/mailman/listinfo/users><sealert_node69-02.tx...
lert_node69-06.txt>
--Apple-Mail=_9BBC0E85-E36A-488F-8893-571F9F5963A1
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
charset=utf-8
<html><head><meta http-equiv=3D"Content-Type"
content=3D"text/html =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D"">This should work but that is a little strange (I=E2=80=99m =
copying from the suggested action)<div class=3D"">-------------<br =
class=3D""><div class=3D""><div class=3D"">If
you believe that qemu-kvm =
should be allowed getattr access on the =
a3f29de7-c6b9-410e-b635-9b3016da7ba2 lnk_file by default.</div><div =
class=3D"">Then you should report this as a bug.</div><div
class=3D"">You =
can generate a local policy module to allow this access.</div><div =
class=3D"">Do</div><div class=3D"">allow this access
for now by =
executing:</div><div class=3D""><b class=3D""># grep
qemu-kvm =
/var/log/audit/audit.log | audit2allow -M mypol</b></div><div =
class=3D""><b class=3D""># semodule -i
mypol.pp</b></div>
=E2=80=94=E2=80=94=E2=80=94=E2=80=94=E2=80=94=E2=80=94=E2=80=94=E2=80=94=E2=
=80=94=E2=80=94=E2=80=94</div><div class=3D""><br
class=3D""></div><div =
class=3D"">It looks like the qemu-kvm is having access issues on lnk =
files.</div><div class=3D""><br
class=3D""></div><div class=3D"">Could =
you try the above action on node69-02 and see if that resolves the =
issue? It may be a bug.</div><div class=3D""><br =
class=3D""><div><blockquote type=3D"cite"
class=3D""><div class=3D"">On =
Oct 12, 2016, at 9:27 AM, =D0=9D=D0=B8=D0=BA=D0=BE=D0=BB=D0=B0=D0=B5=D0=B2=
=D0=90=D0=BB=D0=B5=D0=BA=D1=81=D0=B5=D0=B9 <<a =
href=3D"mailto:alexeynikolaev.post@yandex.ru" =
class=3D"">alexeynikolaev.post(a)yandex.ru</a>&gt;
wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><div
=
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-stroke-width: 0px;"
class=3D""> </div><div =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-stroke-width: 0px;"
class=3D""> </div><div =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-stroke-width: 0px;" class=3D"">12.10.2016, 15:53, "Tom
=
Gamull" <<a href=3D"mailto:tgamull@redhat.com" =
class=3D"">tgamull@redhat.com</a>>:</div><blockquote
type=3D"cite" =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-stroke-width: 0px;" class=3D""><div
class=3D"">Can you set =
it to permissive and run<div class=3D"">sealart -a =
/var/log/audit/audit.log</div></div></blockquote><div =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-stroke-width: 0px;"
class=3D""> </div><div =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-stroke-width: 0px;"
class=3D""> </div><div =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-stroke-width: 0px;" class=3D"">Added logs to =
attachment.</div><div style=3D"font-family: Helvetica; font-size: 12px; =
font-style: normal; font-variant-caps: normal; font-weight: normal; =
letter-spacing: normal; orphans: auto; text-align: start; text-indent: =
0px; text-transform: none; white-space: normal; widows: auto; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" =
class=3D""> </div><div style=3D"font-family:
Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; orphans: auto; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; widows: =
auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" =
class=3D""> </div><div style=3D"font-family:
Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; orphans: auto; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; widows: =
auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" =
class=3D""> </div><div style=3D"font-family:
Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; orphans: auto; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; widows: =
auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" =
class=3D""> </div><div style=3D"font-family:
Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; orphans: auto; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; widows: =
auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" =
class=3D""> </div><blockquote type=3D"cite"
style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; orphans: auto; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: =
0px;" class=3D""><div class=3D""><div
class=3D""> </div><div =
class=3D"">you may need to install selinux tools</div><div =
class=3D""> </div><div class=3D""><div
class=3D""><blockquote =
type=3D"cite" class=3D""><div class=3D"">On Oct 12,
2016, at 4:49 AM, =
=D0=9A=D1=80=D0=B0=D1=81=D0=BD=D0=BE=D0=B1=D0=B0=D0=B5=D0=B2 =
=D0=9C=D0=B8=D1=85=D0=B0=D0=B8=D0=BB <<a href=3D"mailto:milo1@ya.ru"
=
class=3D"">milo1(a)ya.ru</a>&gt; wrote:</div> <div
class=3D""><div =
class=3D"">Good day,</div><div
class=3D""> </div><div class=3D"">had =
a similar problem, disabling selinux helped.</div><div =
class=3D""> </div><div
class=3D"">Best,</div><div =
class=3D"">Mikhail</div><div
class=3D""> </div><div =
class=3D"">11.10.2016, 09:55,
"=D0=9D=D0=B8=D0=BA=D0=BE=D0=BB=D0=B0=D0=B5=D0=
=B2 =D0=90=D0=BB=D0=B5=D0=BA=D1=81=D0=B5=D0=B9" <<a =
href=3D"mailto:alexeynikolaev.post@yandex.ru" =
class=3D"">alexeynikolaev.post@yandex.ru</a>>:</div><blockquote
=
type=3D"cite" class=3D""><div class=3D"">Hi
community!</div><div =
class=3D""> </div><div class=3D"">I have 4
hosts: 2 old servers and =
2 new servers</div><div class=3D"">I have this error trying to
migrate =
VM from new host to old one.</div><div
class=3D""> </div><div =
class=3D""><div class=3D"">Oct 11 09:25:05 node69-06 journal:
=
unsupported configuration: Unable to find security driver for model =
selinux</div><div class=3D"">Oct 11 09:25:05 node69-06 journal: vdsm
=
vm.Vm ERROR vmId=3D`a9473a99-32c6-4548-8b85-dafe4ce8f94f`::unsupported =
configuration: Unable to find security driver for model =
selinux</div><div class=3D"">Oct 11 09:25:05 node69-06 journal: vdsm
=
vm.Vm ERROR vmId=3D`a9473a99-32c6-4548-8b85-dafe4ce8f94f`::Failed to =
migrate#012Traceback (most recent call last):#012 File =
"/usr/share/vdsm/virt/migration.py", line 246, in =
run#012 =
self._startUnderlyingMigration(time.time())#012 File =
"/usr/share/vdsm/virt/migration.py", line 335, in =
_startUnderlyingMigration#012 None, =
maxBandwidth)#012 File "/usr/share/vdsm/virt/vm.py", line 703, in =
f#012 ret =3D attr(*args, **kwargs)#012 File =
"/usr/lib/python2.7/site-packages/vdsm/libvirtconnection.py", line 119, =
in wrapper#012 ret =3D f(*args, **kwargs)#012 =
File "/usr/lib64/python2.7/site-packages/libvirt.py", line 1825, in =
migrateToURI2#012 if ret =3D=3D -1: raise libvirtError =
('virDomainMigrateToURI2() failed', dom=3Dself)#012libvirtError: =
unsupported configuration: Unable to find security driver for model =
selinux</div><div class=3D""> </div><div
class=3D"">Migration from =
OLD host to another OLD host have not any problems.</div><div =
class=3D"">Migration from NEW host to another NEW host have not any =
problems.</div><div class=3D"">Migration from OLD host to NEW host
have =
not any problems.</div><div class=3D""> </div><div
=
class=3D"">Migration is not work only from NEW to OLD.</div><div =
class=3D""> </div><div class=3D""><span
class=3D"">oVirt Engine =
Version: 3.5.6.2-1.el6</span></div><div
class=3D""> </div><div =
class=3D""><span class=3D"">All
hosts:</span></div><div class=3D"">OS =
Version: RHEL - 7 - 2.1511.el7.centos.2.10</div><div
class=3D"">Kernel =
Version: 3.10.0 - 327.36.1.el7.x86_64</div><div class=3D"">KVM
Version: =
2.3.0 - 29.1.el7</div><div class=3D"">LIBVIRT Version: =
libvirt-1.2.17-13.el7_2.5</div><div class=3D"">VDSM Version: =
vdsm-4.16.30-0.el7.centos</div><div
class=3D""> </div><div =
class=3D"">Any ideas? Thx.</div></div>,<p =
class=3D"">_______________________________________________<br =
class=3D"">Users mailing list<br class=3D""><a =
href=3D"mailto:Users@ovirt.org"
class=3D"">Users(a)ovirt.org</a><br =
class=3D""><a
href=3D"http://lists.ovirt.org/mailman/listinfo/users" =
class=3D"">http://lists.ovirt.org/mailman/listinfo/users<...
te><div class=3D""> </div><div
class=3D""> </div><div =
class=3D""> <div =
class=3D""> </div></div>_____________________________________________=
__<br class=3D"">Users mailing list<br class=3D""><a =
href=3D"mailto:Users@ovirt.org"
class=3D"">Users(a)ovirt.org</a><br =
class=3D""><a
href=3D"http://lists.ovirt.org/mailman/listinfo/users" =
class=3D"">http://lists.ovirt.org/mailman/listinfo/users<...
uote></div></div></div></blockquote><span =
id=3D"cid:273113FB-D482-49C0-957F-4203E7943E93@gamull.com"><sealert_nod=
e69-02.txt></span><span =
id=3D"cid:DCE50362-542D-44C6-A780-5204315C880C@gamull.com"><sealert_nod=
e69-06.txt></span></div></blockquote></div><br =
class=3D""></div></div></body></html>=
--Apple-Mail=_9BBC0E85-E36A-488F-8893-571F9F5963A1--
--Apple-Mail=_C012F580-CFC3-4D81-A6D3-CE81FC5FDC78
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
filename=signature.asc
Content-Type: application/pgp-signature;
name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools -
https://gpgtools.org
iQIcBAEBCgAGBQJX/jwHAAoJEO2TmglRQu3E3BkP+wX2a21Y3nyaO7d/upLtO6qb
SI8k9O9dgfw75NnGsR21i4+4A98RrEfRvRhX2neNBLops/5WCW/9H/nw5dtlzQEU
45HTZJ6oYnYOjZ8XjIYlu99Xs1/SUivGW9euF8aPWP9ZPu3OARi9wzGFPU51ooON
Jssbo5KASa1A94/IiNnbO1cOldZcCZoHJ+1bRRah5ZwEjIhiy5b2vdoc06CJPr7Q
HADed/5bXsupo5pKXsCnE2sXnkhWvYEIG/hwbnlbEZm+VKJLanTz2AAN7xq4Xr0c
avwLwTX+57HHB28ddCcOSUSyW0RD9R7MFfAptiuMcSxj7IRDfw1EBks/WvZuOw4a
rZinlQLzH7LMX+/Ylav+MrCXUMlEbHtZSN+jioOk5vfPUD9DZHSYxrxP+KnU3Noi
4ltEWA5cOt38HRjIy6DCjmI4fK1j6rqX97d7DvqFgyOhAUi4dEFvZBshssJ6ajy0
hAkVGY5uT4Lr3tyx+MAMpOAF0w2BBHs+76aHb+UU3LHB5ycMV6vrnPRclEpws4xM
K4CtmZchjoxYxhiC0RSbP0v5aeZYe3NUzmleB/5G9eQdpFkveQkI7q7xRW255BD7
8fRx6tgJ+vY8b7J/WLF4r1+ZKpigcea+Jtb1Xc72NeKu9F22qEKZH/qiUNKgiB19
zz8rP0FZlSWP/IBo5fIj
=eai7
-----END PGP SIGNATURE-----
--Apple-Mail=_C012F580-CFC3-4D81-A6D3-CE81FC5FDC78--