weizhouapache commented on PR #13281:
URL: https://github.com/apache/cloudstack/pull/13281#issuecomment-6034859400

   > Suggestion (nice-to-have, not a blocker): have agent setup detect and 
report the current state rather than change it. The detection calls already 
exist in the code being deleted bash("selinuxenabled") in 
securityPolicyConfigRedhat.config(), bash("service apparmor status") / 
bash("apparmor_status | grep libvirt") in securityPolicyConfigUbuntu.config() 
so keeping just the read half is close to zero risk. The value is diagnostic: 
when a policy blocks QEMU, the symptom in agent.log is a generic libvirt 
permission error while the real cause is an AVC denial in audit.log, a 
different layer entirely. One line at setup ("SELinux: enforcing", "AppArmor: 
libvirtd profile enforcing") shortens that path a lot, and it makes the 
leftover state on older hosts visible.
   
   Added some a note and some commands for reference in doc PR: 
https://github.com/apache/cloudstack-documentation/pull/662


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to