On 10/31/2014 08:12 PM, Jonathan Billings wrote: > SELinux should not be preventing you from loading the kvm_intel > module. Something is wrong somewhere else. Is there an AVC entry in > the audit logs for when you try to load the module? There are many: messages:Oct 30 15:54:47 cd dbus: avc: received policyload notice (seqno=2) messages:Oct 30 15:54:47 cd dbus: avc: received policyload notice (seqno=2) messages:Oct 31 06:45:57 cd kernel: type=1400 audit(1414734345.936:3): avc: denied { write } for pid=1529 comm="prelink" name="/" dev=tmpfs ino=5771 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=dir messages:Oct 31 06:45:57 cd kernel: type=1400 audit(1414734345.936:4): avc: denied { add_name } for pid=1529 comm="prelink" name="#prelink#.508OFB" scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=dir messages:Oct 31 06:45:57 cd kernel: type=1400 audit(1414734345.937:5): avc: denied { create } for pid=1529 comm="prelink" name="#prelink#.508OFB" scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 06:45:57 cd kernel: type=1400 audit(1414734345.937:6): avc: denied { open } for pid=1529 comm="prelink" name="#prelink#.508OFB" dev=tmpfs ino=12231 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 06:45:57 cd kernel: type=1400 audit(1414734345.938:7): avc: denied { setattr } for pid=1530 comm="prelink" name="#prelink#.hDVBGB" dev=tmpfs ino=12232 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 06:45:57 cd kernel: type=1400 audit(1414734345.939:9): avc: denied { relabelfrom } for pid=1529 comm="prelink" name="#prelink#.508OFB" dev=tmpfs ino=12231 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 06:52:06 cd kernel: type=1400 audit(1414734715.889:3): avc: denied { write } for pid=1530 comm="prelink" name="/" dev=tmpfs ino=5771 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=dir messages:Oct 31 06:52:06 cd kernel: type=1400 audit(1414734715.889:4): avc: denied { add_name } for pid=1530 comm="prelink" name="#prelink#.jepEMr" scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=dir messages:Oct 31 06:52:06 cd kernel: type=1400 audit(1414734715.889:5): avc: denied { create } for pid=1530 comm="prelink" name="#prelink#.jepEMr" scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 06:52:06 cd kernel: type=1400 audit(1414734715.889:6): avc: denied { open } for pid=1530 comm="prelink" name="#prelink#.jepEMr" dev=tmpfs ino=12240 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 06:52:06 cd kernel: type=1400 audit(1414734715.889:7): avc: denied { write } for pid=1529 comm="prelink" name="/" dev=tmpfs ino=5771 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=dir messages:Oct 31 06:52:06 cd kernel: type=1400 audit(1414734715.891:8): avc: denied { setattr } for pid=1529 comm="prelink" name="#prelink#.SI8xMr" dev=tmpfs ino=12241 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 06:52:06 cd kernel: type=1400 audit(1414734715.893:9): avc: denied { relabelfrom } for pid=1530 comm="prelink" name="#prelink#.jepEMr" dev=tmpfs ino=12240 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 06:52:06 cd kernel: type=1400 audit(1414734715.896:10): avc: denied { remove_name } for pid=1530 comm="prelink" name="#prelink#.jepEMr" dev=tmpfs ino=12240 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=dir messages:Oct 31 08:03:36 cd kernel: type=1400 audit(1414739004.471:3): avc: denied { write } for pid=1536 comm="prelink" name="/" dev=tmpfs ino=5693 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=dir messages:Oct 31 08:03:36 cd kernel: type=1400 audit(1414739004.471:4): avc: denied { add_name } for pid=1536 comm="prelink" name="#prelink#.eckYE7" scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=dir messages:Oct 31 08:03:36 cd kernel: type=1400 audit(1414739004.471:5): avc: denied { create } for pid=1536 comm="prelink" name="#prelink#.eckYE7" scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 08:03:36 cd kernel: type=1400 audit(1414739004.471:6): avc: denied { open } for pid=1536 comm="prelink" name="#prelink#.eckYE7" dev=tmpfs ino=12208 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 08:03:36 cd kernel: type=1400 audit(1414739004.473:7): avc: denied { setattr } for pid=1536 comm="prelink" name="#prelink#.eckYE7" dev=tmpfs ino=12208 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 08:03:36 cd kernel: type=1400 audit(1414739004.474:8): avc: denied { relabelfrom } for pid=1535 comm="prelink" name="#prelink#.C5DoF7" dev=tmpfs ino=12209 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 08:03:36 cd kernel: type=1400 audit(1414739004.474:9): avc: denied { relabelfrom } for pid=1536 comm="prelink" name="#prelink#.eckYE7" dev=tmpfs ino=12208 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 08:03:36 cd kernel: type=1400 audit(1414739004.479:10): avc: denied { remove_name } for pid=1536 comm="prelink" name="#prelink#.eckYE7" dev=tmpfs ino=12208 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=dir messages:Oct 31 08:16:22 cd kernel: type=1400 audit(1414739770.962:3): avc: denied { write } for pid=1554 comm="prelink" name="/" dev=tmpfs ino=5771 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=dir messages:Oct 31 08:16:22 cd kernel: type=1400 audit(1414739770.962:4): avc: denied { add_name } for pid=1554 comm="prelink" name="#prelink#.rIXw8c" scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=dir messages:Oct 31 08:16:22 cd kernel: type=1400 audit(1414739770.963:5): avc: denied { create } for pid=1554 comm="prelink" name="#prelink#.rIXw8c" scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 08:16:22 cd kernel: type=1400 audit(1414739770.963:6): avc: denied { open } for pid=1554 comm="prelink" name="#prelink#.rIXw8c" dev=tmpfs ino=12241 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 08:16:22 cd kernel: type=1400 audit(1414739770.964:7): avc: denied { setattr } for pid=1555 comm="prelink" name="#prelink#.BFWz8c" dev=tmpfs ino=12242 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 08:16:22 cd kernel: type=1400 audit(1414739770.965:8): avc: denied { relabelfrom } for pid=1554 comm="prelink" name="#prelink#.rIXw8c" dev=tmpfs ino=12241 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=file messages:Oct 31 08:16:22 cd kernel: type=1400 audit(1414739770.970:10): avc: denied { remove_name } for pid=1554 comm="prelink" name="#prelink#.rIXw8c" dev=tmpfs ino=12241 scontext=system_u:system_r:prelink_mask_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmpfs_t:s0 tclass=dir -- Gruß, Christian _______________________________________________ CentOS mailing list CentOS@xxxxxxxxxx http://lists.centos.org/mailman/listinfo/centos