Bug 1364377
Summary: | ipa-server-install fails with failed to create ds instance | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 7 | Reporter: | Jan Pazdziora <jpazdziora> |
Component: | 389-ds-base | Assignee: | Noriko Hosoi <nhosoi> |
Status: | CLOSED DUPLICATE | QA Contact: | Viktor Ashirov <vashirov> |
Severity: | unspecified | Docs Contact: | |
Priority: | unspecified | ||
Version: | 7.3 | CC: | jpazdziora, nkinder, rmeggins |
Target Milestone: | rc | Keywords: | Regression |
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2016-08-11 15:26:56 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Jan Pazdziora
2016-08-05 08:33:50 UTC
This is regression against 389-ds-base-1.3.5.10-5.el7.x86_64. There are also new AVC denials that I did not see before. They are about SSSD but neither SSSD nor selinux-policy version changed from working installations: type=AVC msg=audit(1470385620.907:199): avc: denied { write } for pid=21669 comm="sssd" path="/etc/sssd/sssd.conf" dev="dm-0" ino=68557311 scontext=system_u:system_r:sssd_t:s0 tcontext=system_u:object_r:sssd_conf_t:s0 tclass=file type=AVC msg=audit(1470385620.907:199): avc: denied { create } for pid=21669 comm="sssd" name="sssd.conf" scontext=system_u:system_r:sssd_t:s0 tcontext=system_u:object_r:sssd_conf_t:s0 tclass=file type=AVC msg=audit(1470385620.907:199): avc: denied { add_name } for pid=21669 comm="sssd" name="sssd.conf" scontext=system_u:system_r:sssd_t:s0 tcontext=system_u:object_r:sssd_conf_t:s0 tclass=dir type=AVC msg=audit(1470385620.907:199): avc: denied { write } for pid=21669 comm="sssd" name="sssd" dev="dm-0" ino=68005492 scontext=system_u:system_r:sssd_t:s0 tcontext=system_u:object_r:sssd_conf_t:s0 tclass=dir type=AVC msg=audit(1470385620.907:200): avc: denied { setattr } for pid=21669 comm="sssd" name="sssd.conf" dev="dm-0" ino=68557311 scontext=system_u:system_r:sssd_t:s0 tcontext=system_u:object_r:sssd_conf_t:s0 tclass=file type=AVC msg=audit(1470385621.493:201): avc: denied { create } for pid=21670 comm="sssd" name="sbus-monitor" scontext=system_u:system_r:sssd_t:s0 tcontext=system_u:object_r:sssd_conf_t:s0 tclass=sock_file type=AVC msg=audit(1470385621.493:202): avc: denied { setattr } for pid=21670 comm="sssd" name="sbus-monitor" dev="dm-0" ino=598583 scontext=system_u:system_r:sssd_t:s0 tcontext=system_u:object_r:sssd_conf_t:s0 tclass=sock_file type=AVC msg=audit(1470385621.493:203): avc: denied { getattr } for pid=21670 comm="sssd" path="/var/lib/sss/pipes/private/sbus-monitor" dev="dm-0" ino=598583 scontext=system_u:system_r:sssd_t:s0 tcontext=system_u:object_r:sssd_conf_t:s0 tclass=sock_file type=AVC msg=audit(1470385621.505:204): avc: denied { write } for pid=21679 comm="sssd_be" name="sbus-monitor" dev="dm-0" ino=598583 scontext=system_u:system_r:sssd_t:s0 tcontext=system_u:object_r:sssd_conf_t:s0 tclass=sock_file Hi Jan, Hopefully, 389-ds-base-1.3.5.10-7.el7 fixes your problem, too... We got 3 bug reports on the day 389-ds-base-1.3.5.10-6.el7 was built and ready for testing... Just in case -7 works for you, since this bug is not acked yet and it is a regression introduced by bug 1316580 which is being implemented for rhel-7.3, could you please close this bug as a duplicate of bug 1316580? Thanks & sorry for blocking your test. --noriko I confirm that installations with 389-ds-base-1.3.5.10-7.el7.x86_64 pass. (In reply to Jan Pazdziora from comment #11) > I confirm that installations with 389-ds-base-1.3.5.10-7.el7.x86_64 pass. Thank you so much, Jan!! Closing this bug as dup of bz1316580. *** This bug has been marked as a duplicate of bug 1316580 *** |