Bug 1336742
Summary: | Service systemd-journald fails to start due to AVC denial on /etc/machine-id read | |||
---|---|---|---|---|
Product: | Red Hat CloudForms Management Engine | Reporter: | Jan Krocil <jkrocil> | |
Component: | Appliance | Assignee: | Šimon Lukašík <slukasik> | |
Status: | CLOSED ERRATA | QA Contact: | luke couzens <lcouzens> | |
Severity: | high | Docs Contact: | ||
Priority: | high | |||
Version: | 5.5.0 | CC: | abellott, cpelland, dajohnso, jhardy, jkrocil, ncarboni, obarenbo, simaishi, slukasik | |
Target Milestone: | GA | Keywords: | ZStream | |
Target Release: | 5.6.0 | Flags: | jkrocil:
automate_bug+
|
|
Hardware: | Unspecified | |||
OS: | Unspecified | |||
Whiteboard: | appliance | |||
Fixed In Version: | 5.6.0.8 | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | ||
Clone Of: | ||||
: | 1341242 (view as bug list) | Environment: | ||
Last Closed: | 2016-06-29 16:02:54 UTC | Type: | Bug | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: | ||||
Bug Depends On: | ||||
Bug Blocks: | 1341242 |
Description
Jan Krocil
2016-05-17 11:40:13 UTC
I can't reproduce this on a 5.6.0.6-beta2.5 deploy. What appliance build was this? VMWare? RHEV? I deployed the VMWare appliance on Workstation and systemd-journald is up and running fine. The problem is that we have /etc/machine-id with unlabeled_t selinux label on the image (looking into rhos version, haven't unpacked vmware). The unlabeled_t means that we have re-created the /etc/machine-id during the build and we did not have the guest policy loaded during that operation. Do we keep appliance build logs somewhere? Also, the bug 1308997 is worth reading. There are more unlabeled_t files: # find / -context *:unlabeled_t:* /etc/machine-id /var/account/pacct /mnt /mnt/lost+found Because of this, logrorate fails to service psacct on the appliance. avc: denied { getattr } for pid=1967 comm="logrotate" path="/var/account/pacct" dev="dm-8" ino=113078 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file libguestfs package has been updated on the build machine, it now has the version mentioned above. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2016:1348 |