Uploaded image for project: 'OpenShift Virtualization'
  1. OpenShift Virtualization
  2. CNV-16585

[2057310] qemu-guest-agent does not report information due to selinux denials

XMLWordPrintable

    • False
    • False
    • CLOSED
    • Release Notes
    • CNV-16370 - cnv-4.12.0 Release Feature
    • Hide
      The QEMU guest agent on a Fedora 35 virtual machine is blocked by SELinux and does not report data. Other Fedora versions might be affected. (BZ#2028762)

      As a workaround, disable SELinux on the virtual machine, run the QEMU guest agent commands, and then re-enable SELinux.
      Show
      The QEMU guest agent on a Fedora 35 virtual machine is blocked by SELinux and does not report data. Other Fedora versions might be affected. (BZ#2028762) As a workaround, disable SELinux on the virtual machine, run the QEMU guest agent commands, and then re-enable SELinux.
    • Known Issue
    • Done
    • High
    • None

      +++ This bug was initially created as a clone of Bug #2028762 +++

      Reason of cloning: we would like to follow this bug from CNV side since CNV should support fedora 35 fully.

      Description of problem:

      Version-Release number of selected component (if applicable):

      > qemu-guest-agent.x86_64 2:6.1.0-5.fc35 @anaconda

      How reproducible:

      Create a fedora 35 VM and query through qemu for information

      Query the guest-agent through libvirt/qemu.

      Steps to Reproduce:
      1. Create a fedora 35 VM
      2. Execute on virt_launcher_pod "virsh qemu-agent-command <vm_namespace>_<pod_name> guest-get-fsinfo

      Actual results:

      The guest agent is missing data due to selinux issues: https://github.com/kubevirt/kubevirt/issues/6857#issuecomment-985109786

      Disabling selinux makes it work again.

      Expected results:

      qemu-guest-agent should be able to report all data by default without getting denies by selinux.

              sjhala@redhat.com Shikha Jhala
              rhn-support-rkishner Roni Kishner
              Roni Kishner Roni Kishner
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: