[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [Xen-devel] unable to create domain after enabling XSM
I should add the xsm=policy option to the end of the xen.cfg instead of as an option. Sorry for the fault. However, another problem is that when I modified the policy and reload it using 'xl loadpolicy', the policy seemed not working. The policy I add is 'allow domU_t security_t:security check_context; allow domU_t domU_t_self:hvm gethvmc;', and it is successfully loaded. But executing XEN_DOMCTL_gethvmcontext_partial in domU_t would still cause the following violations: (XEN) avc: denied { gethvmc } for domid=1 scontext=system_u:system_r:domU_t tcontext=system_u:system_r:domU_t_self tclass=hvm Rebooting xen with the new policy doesn't work too. BTW, the domU_t I created is a HVM, I hope that is not the problem. 2016-05-17 16:33 GMT+08:00 Jan Beulich <JBeulich@xxxxxxxx>: >>> On 16.05.16 at 17:00, <fangtuo90@xxxxxxxxx> wrote: _______________________________________________ Xen-devel mailing list Xen-devel@xxxxxxxxxxxxx http://lists.xen.org/xen-devel
|
Lists.xenproject.org is hosted with RackSpace, monitoring our |