Bug 1278495

Summary: Got 17 "avc denied" messages on starting up openvswitch service
Product: Red Hat Enterprise Linux 7 Reporter: Jean-Tsung Hsiao <jhsiao>
Component: selinux-policyAssignee: Lukas Vrabec <lvrabec>
Status: CLOSED ERRATA QA Contact: Milos Malik <mmalik>
Severity: high Docs Contact:
Priority: high    
Version: 7.2CC: edannon, ekuris, fleitner, jhsiao, kzhang, lvrabec, mgrepl, mmalik, nyechiel, plautrba, pvrabec, rcain, sdodson, snagar, ssekidde
Target Milestone: rcKeywords: ZStream
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: selinux-policy-3.13.1-62.el7 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 1299405 (view as bug list) Environment:
Last Closed: 2016-11-04 02:24:09 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1299405    
Attachments:
Description Flags
/var/log/audit/audit.log none

Description Jean-Tsung Hsiao 2015-11-05 15:47:29 UTC
Created attachment 1090186 [details]
/var/log/audit/audit.log

Description of problem: Got 17 "avc denied" messages on starting up openvswitch service
type=AVC msg=audit(1446735509.031:30): avc:  denied  { read } for  pid=1900 comm="ovs-vswitchd" name="/" dev="hugetlbfs" ino=12482 scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:hugetlbfs_t:s0 tclass=dir
type=AVC msg=audit(1446735509.031:30): avc:  denied  { open } for  pid=1900 comm="ovs-vswitchd" path="/dev/hugepages" dev="hugetlbfs" ino=12482 scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:hugetlbfs_t:s0 tclass=dir
type=AVC msg=audit(1446735509.031:31): avc:  denied  { lock } for  pid=1900 comm="ovs-vswitchd" path="/dev/hugepages" dev="hugetlbfs" ino=12482 scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:hugetlbfs_t:s0 tclass=dir
type=AVC msg=audit(1446735509.064:32): avc:  denied  { write } for  pid=1900 comm="ovs-vswitchd" name="/" dev="hugetlbfs" ino=12482 scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:hugetlbfs_t:s0 tclass=dir

See attached audit.log for more.


Version-Release number of selected component (if applicable):
RHEL 7.2 Beta Snapshot #5
openvswitch-dpdk-2.4.0-0.10346.git97bab959.1.el7.x86_64
dpdk-2.1.0-3.el7.x86_64

How reproducible: Reproducible


Steps to Reproduce:
1. Set up OVS+DPDK test-bed
2. setenforce 0
3. systemctl start openvswitch
4. Check /var/log/audit/audit.log

Actual results:


Expected results:


Additional info:

Comment 2 Flavio Leitner 2015-11-05 17:43:08 UTC
Those are correct. DPDK enabled openvswitch allocates hugepages and so it needs access to hugetlbfs filesystem.
Reassigning to selinux-policy.

Comment 3 Milos Malik 2015-11-06 07:51:30 UTC
It's too late for RHEL-7.2.

Comment 10 Lukas Vrabec 2016-01-18 09:09:15 UTC
Commit id in comment 9 is pointing to fix in selinux-policy gitlab, where we store fixes before distgit repo.

Comment 15 Nir Yechiel 2016-09-01 08:36:19 UTC
*** Bug 1320043 has been marked as a duplicate of this bug. ***

Comment 17 errata-xmlrpc 2016-11-04 02:24:09 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2283.html