Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-48236

fail to start vm with encrypted tpm-emulator in rhel10

    • Yes
    • Important
    • Regression
    • rhel-sst-security-selinux
    • ssg_security
    • 3
    • QE ack
    • False
    • Hide

      None

      Show
      None
    • No
    • None
    • Hide

      The reproducer does not trigger SELinux denials.

      Show
      The reproducer does not trigger SELinux denials.
    • None
    • None
    • Unspecified Release Note Type - Unknown
    • All
    • None

      What were you trying to do that didn't work?

      found in gating test

      fail to start vm with tpm-emulator

      Please provide the package NVR for which bug is seen:

      qemu-kvm-9.0.0-1.el10.x86_64

      libvirt-10.4.0-1.el10.x86_64

      swtpm-0.8.1-5.el10+5.x86_64

      libtpms-0.9.6-6.el10+5.x86_64

      edk2-ovmf-20240214-1.el10.noarch

      kernel-6.9.0-7.el10.x86_64

      How reproducible:

      100%

      Steps to reproduce

      1. prepare a tpm secret
        # vim secret.xml
         <secret ephemeral="no" private="yes">
        <description>sample vTPM secret</description>
        <usage type="vtpm">
        <name>VTPM_example</name>
        </usage>
        </secret> 
        # virsh secret-define secret.xml
        Secret 1367e80d-f426-40c3-8269-dd5419a991e8 created
        
        # MYSECRET=`printf %s "open sesame" | base64`
        
        # virsh secret-set-value --secret 1367e80d-f426-40c3-8269-dd5419a991e8 $MYSECRET
        error: Passing secret value as command-line argument is insecure!
        Secret value set
        
        # virsh secret-list
         UUID                                   Usage
        -----------------------------------------------------------
         1367e80d-f426-40c3-8269-dd5419a991e8   vtpm VTPM_example
        
        
      1. define a vm with tpm device
        # virsh edit avocado-vt-vm1 
        ...
         <tpm model='tpm-crb'>
              <backend type='emulator' version='2.0'>
                <encryption secret='1367e80d-f426-40c3-8269-dd5419a991e8'/>
              </backend>
            </tpm>
        ...
      1. start vm
        # virsh start avocado-vt-vm1 
        error: Failed to start domain 'avocado-vt-vm1'
        error: internal error: QEMU unexpectedly closed the monitor (vm='avocado-vt-vm1'): 2024-06-06T07:27:01.321719Z qemu-kvm: tpm-emulator: TPM result for CMD_INIT: 0x101 operation failed
         

      Expected results

      Can start guest

      Actual results

      Start the guest failed

              rhn-support-zpytela Zdenek Pytela
              rhn-support-zhetang Zhen Tang
              Zdenek Pytela Zdenek Pytela
              Milos Malik Milos Malik
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: