在System Manager中启用本机Fpolicy后、VMware ESXi无法启动VM、创建新VM或还原快照
适用场景
- VMware ESXi
- NFSv3
- 本机Fpolicy
问题描述
- VMware ESXi尝试启动VM、但收到错误
Task Power On virtual machine
Target MASTER-Template.726
Status An error occurred while opening configuration file "/vmfs/volumes/1234-5678/MASTER-Template.726/MASTER-Template.726.vmx": Insufficient permission to access the file.
- 如果数据存储库是使用NFSv3挂载的、则会发生这种情况
- 如果使用NFSv4挂载数据存储库、则不会发生此错误
- 当前正在运行的VM正常
- 但是、已关闭电源的VM无法启动
- 还原VM快照也可能会失败、并出现类似的权限问题
- 数据包跟踪显示
Status: NFS3ERR_ACCES (13)
适用于[V3 Procedure: CREATE (8)]
sectrace -trace-allow yes
表示允许访问
Node Index Filter Details Reason
--------------- ----- -------------------------- ------------------------------
node01 4 Security Style: UNIX Access is allowed because the
permissions user has UNIX root privileges
while reading the file.
Access is granted for: "Read"
Protocol: nfs
Volume: vol01
Share: -
Path: /MASTER-Template
.726/MASTER-Template
.726.vmx
Win-User: -
UNIX-User: 0
Session-ID: -
snetapp03-a1 4 Security Style: UNIX Access is allowed because the
permissions user has UNIX root privileges
while creating the file.
Access is granted for: "Write"
Protocol: nfs
Volume: vol01
Share: -
Path: /MASTER-Template
.726/MASTER-Template
.726.vmx.lck
Win-User: -
UNIX-User: 0
Session-ID: -