All of lore.kernel.org
 help / color / mirror / Atom feed
From: Ian Campbell <ian.campbell@citrix.com>
To: George Dunlap <George.Dunlap@eu.citrix.com>
Cc: Ian Jackson <Ian.Jackson@eu.citrix.com>,
	Daniel De Graaf <dgdegra@tycho.nsa.gov>,
	Wei Liu <wei.liu2@citrix.com>,
	xen-devel <xen-devel@lists.xen.org>
Subject: Re: stubdom migration failure on merlot* XSM related (Was: [adhoc test] 65682: tolerable FAIL])
Date: Mon, 14 Dec 2015 11:30:10 +0000	[thread overview]
Message-ID: <1450092610.16856.39.camel@citrix.com> (raw)
In-Reply-To: <CAFLBxZZk1_afRh2XoTixBHsqLZ2d-tr-0NY6uCkEg2yn2ve0=g@mail.gmail.com>

On Mon, 2015-12-14 at 11:11 +0000, George Dunlap wrote:
> On Mon, Dec 14, 2015 at 10:14 AM, Ian Campbell <ian.campbell@citrix.com>
> wrote:
> > On Fri, 2015-12-11 at 15:16 +0000, Ian Campbell wrote:
> > > 
> > > I have a new flight going on (65755) with flask=permissive instead of
> > > flask=enforcing (assuming I didn't botch the osstest modifications to
> > > support that setting via a runvar).
> > 
> > I did botch the mods, but luckily permissive is the default, so I got
> > what
> > I wanted ;-)
> > 
> > > If that test passes, prints the AVC message but not the missing IRQ
> > > message
> > > then I think that would be our smoking gun.
> > 
> > http://logs.test-lab.xenproject.org/osstest/logs/65758/
> > 
> > From serial-merlot1.log:
> > 
> > Dec 11 18:01:57.001037 (XEN) Flask: 64 avtab hash slots, 236 rules.
> > Dec 11 18:01:57.009023 (XEN) Flask: 64 avtab hash slots, 236 rules.
> > Dec 11 18:01:57.017004 (XEN) Flask:  3 users, 3 roles, 36 types, 2
> > bools
> > Dec 11 18:01:57.017038 (XEN) Flask:  12 classes, 236 rules
> > Dec 11 18:01:57.025015 (XEN) Flask:  Starting in permissive mode.
> > [...]
> > Dec 11 18:06:01.229194 (XEN) avc:  denied  { pcilevel } for domid=2
> > target=1 scontext=system_u:system_r:dm_dom_t
> > tcontext=system_u:system_r:domU_t_target tclass=hvm
> > 
> > http://logs.test-lab.xenproject.org/osstest/logs/65758/test-amd64-amd64
> > -xl-qemut-stubdom-debianhvm-amd64-xsm/merlot1---var-log-xen-qemu-dm-
> > debianhvm.guest.osstest--incoming.log.10
> 
> So wait -- does flask not report denials when in enforcing mode?

It does, I'm not sure what made you think otherwise, earlier in the thread
I quoted such a denial and it was that which lead me down this path.

Ian.

_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xen.org
http://lists.xen.org/xen-devel

  reply	other threads:[~2015-12-14 11:30 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <E1a77eF-00049f-Er@osstest.test-lab.xenproject.org>
2015-12-11 12:12 ` stubdom migration failure on merlot* XSM related (Was: [adhoc test] 65682: tolerable FAIL]) Ian Campbell
2015-12-11 14:05   ` Ian Campbell
2015-12-11 15:12     ` Ian Campbell
2015-12-11 15:16       ` Ian Campbell
2015-12-14 10:14         ` Ian Campbell
2015-12-14 11:11           ` George Dunlap
2015-12-14 11:30             ` Ian Campbell [this message]
2015-12-14 11:55           ` Ian Campbell

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1450092610.16856.39.camel@citrix.com \
    --to=ian.campbell@citrix.com \
    --cc=George.Dunlap@eu.citrix.com \
    --cc=Ian.Jackson@eu.citrix.com \
    --cc=dgdegra@tycho.nsa.gov \
    --cc=wei.liu2@citrix.com \
    --cc=xen-devel@lists.xen.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.