bots icon indicating copy to clipboard operation
bots copied to clipboard

SELinux denial when virtqemu is stopped: avc: denied { search } for comm="rpc-virtproxyd" dev="proc"

Open martinpitt opened this issue 1 year ago • 1 comments

Downstream report: https://issues.redhat.com/browse/RHEL-37822

martinpitt avatar May 22 '24 12:05 martinpitt

centos-10 Ooops, it happened again


# ----------------------------------------------------------------------
# testLibvirt (__main__.TestMachinesVirtualization.testLibvirt)
[0522/144047.713165:WARNING:sandbox_linux.cc(420)] InitializeSandbox() called with multiple threads in process gpu-process.

DevTools listening on ws://127.0.0.1:9607/devtools/browser/bf83a271-e3eb-4fd3-9135-c2922ff4692d
[0522/144047.734714:WARNING:runtime_features.cc(730)] AttributionReportingCrossAppWeb cannot be enabled in this configuration. Use --enable-features=ConversionMeasurement,AttributionReportingCrossAppWeb in addition.
[0522/144048.379955:WARNING:runtime_features.cc(730)] AttributionReportingCrossAppWeb cannot be enabled in this configuration. Use --enable-features=ConversionMeasurement,AttributionReportingCrossAppWeb in addition.
CDP: {"source":"network","level":"error","text":"Failed to load resource: the server responded with a status of 404 (ERROR)","timestamp":1716388853769.026,"url":"http://127.0.0.2:9291/cockpit/@localhost/*/po.manifest.js","networkRequestId":"24532.19"}
CDP: {"source":"network","level":"error","text":"Failed to load resource: the server responded with a status of 404 (ERROR)","timestamp":1716388853776.76,"url":"http://127.0.0.2:9291/cockpit/@localhost/*/po.js","networkRequestId":"24532.20"}
CDP: {"source":"security","level":"error","text":"Refused to execute script from 'http://127.0.0.2:9291/cockpit/@localhost/*/po.manifest.js' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.","timestamp":1716388853839.837,"url":"http://127.0.0.2:9291/machines"}
CDP: {"source":"security","level":"error","text":"Refused to execute script from 'http://127.0.0.2:9291/cockpit/@localhost/*/po.js' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.","timestamp":1716388853840.055,"url":"http://127.0.0.2:9291/machines"}
> error: Scrollbar test exception: TypeError: Cannot read properties of null (reading 'appendChild')
> warning: failed to poll tuned {"problem":"disconnected","name":"null","message":"Server has closed the connection.","toString":""}
> warning: failed to poll tuned {"problem":"disconnected","name":"null","message":"Server has closed the connection.","toString":""}
CDP: {"source":"network","level":"error","text":"Failed to load resource: the server responded with a status of 404 (ERROR)","timestamp":1716388861238.948,"url":"http://127.0.0.2:9291/cockpit/@localhost/*/po.manifest.js","networkRequestId":"24532.170"}
CDP: {"source":"network","level":"error","text":"Failed to load resource: the server responded with a status of 404 (ERROR)","timestamp":1716388861241.306,"url":"http://127.0.0.2:9291/cockpit/@localhost/*/po.js","networkRequestId":"24532.171"}
CDP: {"source":"security","level":"error","text":"Refused to execute script from 'http://127.0.0.2:9291/cockpit/@localhost/*/po.manifest.js' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.","timestamp":1716388861299.725,"url":"http://127.0.0.2:9291/machines"}
CDP: {"source":"security","level":"error","text":"Refused to execute script from 'http://127.0.0.2:9291/cockpit/@localhost/*/po.js' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.","timestamp":1716388861299.875,"url":"http://127.0.0.2:9291/machines"}
> error: Scrollbar test exception: TypeError: Cannot read properties of null (reading 'appendChild')
> warning: failed to poll tuned {"problem":"disconnected","name":"null","message":"Server has closed the connection.","toString":""}
> warning: failed to poll tuned {"problem":"disconnected","name":"null","message":"Server has closed the connection.","toString":""}
> error: Failed to get libvirt version from the dbus API: {"problem":"null","name":"org.libvirt.Error","message":"internal error: Cannot find start time for pid 4613","toString":""}
> warning: transport closed: disconnected
CDP: {"source":"network","level":"error","text":"Failed to load resource: the server responded with a status of 404 (ERROR)","timestamp":1716388872884.281,"url":"http://127.0.0.2:9291/cockpit/@localhost/*/po.manifest.js","networkRequestId":"24532.334"}
CDP: {"source":"network","level":"error","text":"Failed to load resource: the server responded with a status of 404 (ERROR)","timestamp":1716388872900.553,"url":"http://127.0.0.2:9291/cockpit/@localhost/*/po.js","networkRequestId":"24532.335"}
CDP: {"source":"security","level":"error","text":"Refused to execute script from 'http://127.0.0.2:9291/cockpit/@localhost/*/po.manifest.js' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.","timestamp":1716388872903.711,"url":"http://127.0.0.2:9291/machines"}
CDP: {"source":"security","level":"error","text":"Refused to execute script from 'http://127.0.0.2:9291/cockpit/@localhost/*/po.js' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.","timestamp":1716388872903.838,"url":"http://127.0.0.2:9291/machines"}
> error: Scrollbar test exception: TypeError: Cannot read properties of null (reading 'appendChild')
> warning: failed to poll tuned {"problem":"disconnected","name":"null","message":"Server has closed the connection.","toString":""}
> warning: failed to poll tuned {"problem":"disconnected","name":"null","message":"Server has closed the connection.","toString":""}
> warning: transport closed: disconnected
Stopping 'virtstoraged.service', but its triggering units are still active:
virtstoraged.socket, virtstoraged-admin.socket, virtstoraged-ro.socket
Stopping 'virtnetworkd.service', but its triggering units are still active:
virtnetworkd-admin.socket, virtnetworkd-ro.socket, virtnetworkd.socket
Stopping 'virtqemud.service', but its triggering units are still active:
virtqemud-ro.socket, virtqemud-admin.socket, virtqemud.socket
Traceback (most recent call last):
  File "/work/make-checkout-workdir/test/machineslib.py", line 507, in tearDown
    super().tearDown()
  File "/work/make-checkout-workdir/test/common/testlib.py", line 1732, in tearDown
    self.check_browser_errors()
  File "/work/make-checkout-workdir/test/common/testlib.py", line 2038, in check_browser_errors
    raise Error(UNEXPECTED_MESSAGE + "browser errors:\n" + log)
testlib.Error: FAIL: Test completed, but found unexpected browser errors:
error: Failed to get libvirt version from the dbus API: {"problem":"null","name":"org.libvirt.Error","message":"internal error: Cannot find start time for pid 4613","toString":""}

# Result testLibvirt (__main__.TestMachinesVirtualization.testLibvirt) failed
# 1 TEST FAILED [46s on 2988a08c7135]
not ok 61 /work/make-checkout-workdir/test/check-machines-virtualization TestMachinesVirtualization.testLibvirt [ND@2]

First occurrence: 2024-05-22T14:41:26.524711+00:00 | revision 49763df1a545c33b7451260fa0a0714f6380625a Times recorded: 1 Latest occurrences:

  • 2024-05-22T14:41:26.524711+00:00 | revision 49763df1a545c33b7451260fa0a0714f6380625a

# ----------------------------------------------------------------------
# testLibvirt (__main__.TestMachinesVirtualization.testLibvirt)
[0621/051657.586026:WARNING:sandbox_linux.cc(436)] InitializeSandbox() called with multiple threads in process gpu-process.

DevTools listening on ws://127.0.0.1:9532/devtools/browser/55bba157-f9ad-4ce1-b981-fcb8a01fdf75
CDP: {"source":"network","level":"error","text":"Failed to load resource: the server responded with a status of 404 (ERROR)","timestamp":1718947023490.964,"url":"http://127.0.0.2:9891/cockpit/@localhost/*/po.manifest.js","networkRequestId":"25805.19"}
CDP: {"source":"network","level":"error","text":"Failed to load resource: the server responded with a status of 404 (ERROR)","timestamp":1718947023493.171,"url":"http://127.0.0.2:9891/cockpit/@localhost/*/po.js","networkRequestId":"25805.20"}
CDP: {"source":"security","level":"error","text":"Refused to execute script from 'http://127.0.0.2:9891/cockpit/@localhost/*/po.manifest.js' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.","timestamp":1718947023549.265,"url":"http://127.0.0.2:9891/machines"}
CDP: {"source":"security","level":"error","text":"Refused to execute script from 'http://127.0.0.2:9891/cockpit/@localhost/*/po.js' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.","timestamp":1718947023549.408,"url":"http://127.0.0.2:9891/machines"}
> error: Scrollbar test exception: TypeError: Cannot read properties of null (reading 'appendChild')
> warning: failed to poll tuned {"problem":"disconnected","name":"null","message":"Server has closed the connection.","toString":""}
> warning: failed to poll tuned {"problem":"disconnected","name":"null","message":"Server has closed the connection.","toString":""}
CDP: {"source":"network","level":"error","text":"Failed to load resource: the server responded with a status of 404 (ERROR)","timestamp":1718947030780.345,"url":"http://127.0.0.2:9891/cockpit/@localhost/*/po.manifest.js","networkRequestId":"25805.170"}
CDP: {"source":"network","level":"error","text":"Failed to load resource: the server responded with a status of 404 (ERROR)","timestamp":1718947030813.843,"url":"http://127.0.0.2:9891/cockpit/@localhost/*/po.js","networkRequestId":"25805.171"}
CDP: {"source":"security","level":"error","text":"Refused to execute script from 'http://127.0.0.2:9891/cockpit/@localhost/*/po.manifest.js' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.","timestamp":1718947030845.681,"url":"http://127.0.0.2:9891/machines"}
CDP: {"source":"security","level":"error","text":"Refused to execute script from 'http://127.0.0.2:9891/cockpit/@localhost/*/po.js' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.","timestamp":1718947030845.791,"url":"http://127.0.0.2:9891/machines"}
> error: Scrollbar test exception: TypeError: Cannot read properties of null (reading 'appendChild')
> warning: failed to poll tuned {"problem":"disconnected","name":"null","message":"Server has closed the connection.","toString":""}
> warning: failed to poll tuned {"problem":"disconnected","name":"null","message":"Server has closed the connection.","toString":""}
> error: Failed to get libvirt version from the dbus API: {"problem":"null","name":"org.libvirt.Error","message":"internal error: Cannot find start time for pid 6973","toString":""}
> warning: transport closed: disconnected
CDP: {"source":"network","level":"error","text":"Failed to load resource: the server responded with a status of 404 (ERROR)","timestamp":1718947041596.788,"url":"http://127.0.0.2:9891/cockpit/@localhost/*/po.manifest.js","networkRequestId":"25805.334"}
CDP: {"source":"network","level":"error","text":"Failed to load resource: the server responded with a status of 404 (ERROR)","timestamp":1718947041606.525,"url":"http://127.0.0.2:9891/cockpit/@localhost/*/po.js","networkRequestId":"25805.335"}
CDP: {"source":"security","level":"error","text":"Refused to execute script from 'http://127.0.0.2:9891/cockpit/@localhost/*/po.manifest.js' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.","timestamp":1718947041630.162,"url":"http://127.0.0.2:9891/machines"}
CDP: {"source":"security","level":"error","text":"Refused to execute script from 'http://127.0.0.2:9891/cockpit/@localhost/*/po.js' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.","timestamp":1718947041630.293,"url":"http://127.0.0.2:9891/machines"}
> error: Scrollbar test exception: TypeError: Cannot read properties of null (reading 'appendChild')
> warning: failed to poll tuned {"problem":"disconnected","name":"null","message":"Server has closed the connection.","toString":""}
> warning: failed to poll tuned {"problem":"disconnected","name":"null","message":"Server has closed the connection.","toString":""}
> warning: transport closed: disconnected
Stopping 'virtstoraged.service', but its triggering units are still active:
virtstoraged-ro.socket, virtstoraged.socket, virtstoraged-admin.socket
Stopping 'virtnetworkd.service', but its triggering units are still active:
virtnetworkd-ro.socket, virtnetworkd.socket, virtnetworkd-admin.socket
Stopping 'virtqemud.service', but its triggering units are still active:
virtqemud-ro.socket, virtqemud-admin.socket, virtqemud.socket
Traceback (most recent call last):
  File "/work/make-checkout-workdir/test/machineslib.py", line 515, in tearDown
    super().tearDown()
  File "/work/make-checkout-workdir/test/common/testlib.py", line 1722, in tearDown
    self.check_browser_errors()
  File "/work/make-checkout-workdir/test/common/testlib.py", line 2029, in check_browser_errors
    raise Error(UNEXPECTED_MESSAGE + "browser errors:\n" + log)
testlib.Error: FAIL: Test completed, but found unexpected browser errors:
error: Failed to get libvirt version from the dbus API: {"problem":"null","name":"org.libvirt.Error","message":"internal error: Cannot find start time for pid 6973","toString":""}

# Result testLibvirt (__main__.TestMachinesVirtualization.testLibvirt) failed
# 1 TEST FAILED [45s on a7682b5b5b93]
not ok 87 /work/make-checkout-workdir/test/check-machines-virtualization TestMachinesVirtualization.testLibvirt [ND@7]

First occurrence: 2024-06-21T05:17:34.959711+00:00 | revision 424c5f62f5598be2619a303a1a236dc53c9ee856 Times recorded: 1 Latest occurrences:

  • 2024-06-21T05:17:34.959711+00:00 | revision 424c5f62f5598be2619a303a1a236dc53c9ee856

cockpituous avatar May 22 '24 14:05 cockpituous

This is still current, we just stopped testing c-machines on centos-10 for the time being. So we need to manually bump this.

martinpitt avatar Jun 16 '24 07:06 martinpitt