Debian Bug report logs - #736909
LXC selinux support not working

version graph

Package: selinux-policy-default; Maintainer for selinux-policy-default is Debian SELinux maintainers <[email protected]>; Source for selinux-policy-default is src:refpolicy (PTS, buildd, popcon).

Affects: libvirt-bin, libvirt

Reported by: Laurent Bigonville <[email protected]>

Date: Wed, 19 Sep 2012 22:54:02 UTC

Severity: important

Found in version refpolicy/2:2.20131214-1

Forwarded to [email protected]

Full log


🔗 View this message in rfc822 format

X-Loop: [email protected]
Subject: Bug#688179: [Pkg-libvirt-maintainers] Bug#688179: libvirt: Please enable selinux security driver
Reply-To: Laurent Bigonville <[email protected]>, [email protected]
Resent-From: Laurent Bigonville <[email protected]>
Resent-To: [email protected]
Resent-CC: Debian Libvirt Maintainers <[email protected]>
X-Loop: [email protected]
Resent-Date: Thu, 26 Dec 2013 21:54:01 +0000
Resent-Message-ID: <[email protected]>
Resent-Sender: [email protected]
X-Debian-PR-Message: followup 688179
X-Debian-PR-Package: src:libvirt
X-Debian-PR-Keywords: patch
X-Debian-PR-Source: libvirt
Received: via spool by [email protected] id=B688179.13880946618553
          (code B ref 688179); Thu, 26 Dec 2013 21:54:01 +0000
Received: (at 688179) by bugs.debian.org; 26 Dec 2013 21:51:01 +0000
X-Spam-Checker-Version: SpamAssassin 3.3.2-bugs.debian.org_2005_01_02
	(2011-06-06) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-8.9 required=4.0 tests=BAYES_00,FOURLA,FROMDEVELOPER,
	HAS_BUG_NUMBER,MURPHY_DRUGS_REL8,SPF_HELO_PASS autolearn=ham
	version=3.3.2-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 10; hammy, 151; neutral, 52; spammy,
	0. spammytokens: hammytokens:0.000-+--H*UA:sk:x86_64-,
	0.000-+--H*x:sk:x86_64-, 0.000-+--H*r:TLSv1.2, 0.000-+--H*F:U*bigon,
	0.000-+--bigonville
Received: from anor.bigon.be ([91.121.173.99] ident=postfix)
	by buxtehude.debian.org with esmtps (TLS1.2:DHE_RSA_AES_256_CBC_SHA256:256)
	(Exim 4.80)
	(envelope-from <[email protected]>)
	id 1VwIpY-0002Dd-WD
	for [email protected]; Thu, 26 Dec 2013 21:51:01 +0000
Received: from anor.bigon.be (localhost.localdomain [127.0.0.1])
	by anor.bigon.be (Postfix) with ESMTP id AC5A01A054;
	Thu, 26 Dec 2013 22:50:57 +0100 (CET)
X-Virus-Scanned: Debian amavisd-new at bigon.be
Received: from anor.bigon.be ([127.0.0.1])
	by anor.bigon.be (anor.bigon.be [127.0.0.1]) (amavisd-new, port 10026)
	with ESMTP id MztoMFL35-hW; Thu, 26 Dec 2013 22:50:55 +0100 (CET)
Received: from fornost.bigon.be (unknown [IPv6:2a02:578:85fc:1:226:18ff:fe08:6073])
	(using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits))
	(Client did not present a certificate)
	(Authenticated sender: bigon)
	by anor.bigon.be (Postfix) with ESMTPSA id B6B201A00F;
	Thu, 26 Dec 2013 22:50:55 +0100 (CET)
Date: Thu, 26 Dec 2013 22:50:47 +0100
From: Laurent Bigonville <[email protected]>
To: Guido Günther <[email protected]>
Cc: [email protected]
Message-ID: <[email protected]>
In-Reply-To: <[email protected]>
References: <[email protected]>
	<[email protected]>
X-Mailer: Claws Mail 3.9.3 (GTK+ 2.24.22; x86_64-pc-linux-gnu)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
Le Thu, 26 Dec 2013 22:04:07 +0100,
Guido Günther <[email protected]> a écrit :

> On Thu, Dec 26, 2013 at 04:36:52PM +0100, Laurent Bigonville wrote:
> > tag 688179 + patch
> > thanks
> > 
> > Hi,
> > 
> > Please apply the attached patch.
> > 
> > I've just tested again and the VM's (using qemu) are starting
> > properly and run in the expected context.
> 
> The main reason for not enabling this upfront was that it triggered
> buts when selinux was not available. Did you by any chance test this
> as well? Cheers,

IIRC the main issue was the fact that the selinux policy was too old.

Anyway, I just retired and I can confirm that with selinux security
driver compiled in libvirt and selinux disabled on the machine, I can
still start VM's

So I guess it's OK

Cheers,

Laurent Bigonville

Send a report that this bug log contains spam.


Debian bug tracking system administrator <[email protected]>. Last modified: Thu May 15 15:35:01 2025; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU General Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.