Bug 1441216
| Summary: | Restricted SCC prevents execute on Gluster PVs | ||||||
|---|---|---|---|---|---|---|---|
| Product: | [Red Hat Storage] Red Hat Gluster Storage | Reporter: | Matthew Robson <mrobson> | ||||
| Component: | CNS-deployment | Assignee: | Humble Chirammal <hchiramm> | ||||
| Status: | CLOSED CURRENTRELEASE | QA Contact: | Anoop <annair> | ||||
| Severity: | high | Docs Contact: | |||||
| Priority: | unspecified | ||||||
| Version: | unspecified | CC: | akhakhar, annair, aos-bugs, bchilds, fkrska, hchiramm, jarrpa, jokerman, madam, misalunk, mliyazud, mmccomas, mrobson, mzywusko, pprakash, rcyriac, rhs-bugs, rreddy, rtalur, vinug, wmeng | ||||
| Target Milestone: | --- | ||||||
| Target Release: | --- | ||||||
| Hardware: | All | ||||||
| OS: | All | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | |||||||
| : | 1445226 (view as bug list) | Environment: | |||||
| Last Closed: | 2017-08-02 15:46:46 UTC | Type: | Bug | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Bug Depends On: | 1445226 | ||||||
| Bug Blocks: | |||||||
| Attachments: |
|
||||||
|
Description
Matthew Robson
2017-04-11 12:45:26 UTC
Created attachment 1270775 [details]
POD example
So we installed selinux modules on your Openshift node which helped.
Summary ->
we oc rsh'ed in to jenkins pod
executed the script which gave permission denied
We checked the audit logs
cat /var/log/audit.log | grep denied
We saw the following
avc: denied { execute }
# getsebool virt_sandbox_use_fusefs virt_use_fusefs
# grep fusefs /var/log/audit/audit.log | grep execute | audit2allow -M fusefstoexecutetemp
Installing the module on OpenShift node->
# semodule -i fusefstoexecutetemp.pp
Then again we oc rsh'ed to the jenkins pod and executed the script.
We saw the audit logs again and we saw ->
avc: denied { execute_no_trans }
- Checking and deleting earlier fusefstoexecutetemp
# semodule -l | grep fusefstoexecutetemp
# semodule -d fusefstoexecutetemp
Copy and add the contents to the new file as per the latest avc denial
# cp fusefstoexecutetemp.te fusefstoexecute.te
# Add the following to fusefstoexecute.te
##########################################################################
module fusefstoexecute 1.0;
require {
type svirt_lxc_net_t;
type fusefs_t;
class file { execute execute_no_trans };
}
#============= svirt_lxc_net_t ==============
allow svirt_lxc_net_t fusefs_t:file execute_no_trans;
allow svirt_lxc_net_t fusefs_t:file execute;
###########################################################################
Save the file and run the following.
# checkmodule -M -m -o fusefstoexecute.mod fusefstoexecute.te
# semodule_package -m fusefstoexecute.mod -o fusefstoexecute.pp
Install the module the same way as before.
# semodule -i fusefstoexecute.pp
Again we oc rsh'ed into the pod and then we were able to execute the script.
After the package will be released, told them that they can simply remove the workaround by running (on every node)
# semodule -l | grep fuse
fusefstoexecutetemp 1.0
fusefstoexecute 1.0
# semodule -d fusefstoexecutetemp
# semodule -d fusefstoexecute
I am closing this bug as the subjected fix is already available and shipped. Please revert if the issue is still present. |