Bug 1122688

Summary: Galera wsrep_sst_rsync selinux denials
Product: Red Hat OpenStack Reporter: Scott Lewis <sclewis>
Component: openstack-selinuxAssignee: Ryan Hallisey <rhallise>
Status: CLOSED ERRATA QA Contact: Leonid Natapov <lnatapov>
Severity: urgent Docs Contact:
Priority: urgent    
Version: 5.0 (RHEL 7)CC: ajeain, dwalsh, hbrock, jeckersb, lhh, mgrepl, ohochman, rhallise, rohara, sclewis, slong, yeylon
Target Milestone: rcKeywords: AutoVerified, OtherQA, TestOnly
Target Release: 5.0 (RHEL 7)   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Previously, SELinux prevented wsrep_sst_script from performing an lsof command. SELinux also prevented MariaDB from using port 4444. As a result, Galera could not join a cluster. With this update, the wsrep_sst_script is now allowed to execute lsof and relabel port 4444 to mariadb_port_t, so that MariaDB can successfully join a cluster and the lsof command succeeds.
Story Points: ---
Clone Of: 1118859 Environment:
Last Closed: 2014-09-02 17:38:43 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 1118859    
Bug Blocks:    

Comment 4 Lon Hohberger 2014-08-20 18:58:31 UTC
Tests for this passed devel testing; the AVCs addressed are here:

https://github.com/redhat-openstack/openstack-selinux/blob/el7/tests/bz1118859

Comment 6 errata-xmlrpc 2014-09-02 17:38:43 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2014-1116.html