Bug 1626070
Summary: | [Ceph-Ansible] Ansible Playbook fails during Ceph NFS installation | ||
---|---|---|---|
Product: | [Red Hat Storage] Red Hat Ceph Storage | Reporter: | Sidhant Agrawal <sagrawal> |
Component: | Ceph-Ansible | Assignee: | Guillaume Abrioux <gabrioux> |
Status: | CLOSED ERRATA | QA Contact: | Persona non grata <nobody+410372> |
Severity: | urgent | Docs Contact: | |
Priority: | high | ||
Version: | 3.1 | CC: | anharris, aschoen, branto, ceph-eng-bugs, gfidente, gmeno, hnallurv, kdreyer, nthomas, rgowdege, sankarshan, sostapov, tbarron, tchandra |
Target Milestone: | z1 | Keywords: | Regression, Reopened |
Target Release: | 3.1 | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | RHEL: ceph-ansible-3.1.7-1.rc3.el7cp Ubuntu: ceph-ansible_3.1.7-2redhat1xenial | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2018-11-09 00:59:32 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 1578730 |
Description
Sidhant Agrawal
2018-09-06 14:06:22 UTC
How reproducible: 2 out of 4 test setup encountered this issue This is not a bug. [ubuntu@magna060 ~]$ yum info selinux-policy Loaded plugins: fastestmirror, langpacks, priorities, product-id, search-disabled-repos, subscription-manager Installed Packages Name : selinux-policy Arch : noarch Version : 3.13.1 Release : 222.el7 Size : 6.3 k Repo : installed From repo : rhel-7-server-htb-rpms Summary : SELinux policy configuration URL : http://oss.tresys.com/repos/refpolicy/ License : GPLv2+ Description : SELinux Reference Policy - modular. : Based off of reference policy: Checked out revision 2.20091117 The currently installed selinux-policy package is a beta from RHEL 7.6. We will need to correct it but this invalidates the test against the currently supported platform RHEL-7.5 We checked the package and have observed changes to the ganesha domain. I will file a BZ to address that with selinux-policy for reference the correct package to test with is selinux-policy-3.13.1-192.el7 We need to update our ansible scripts to support the policy changes made in RHEL 7.6. As of RHEL 7.6, the ganesha_t is no longer a domain type and so running the command that sets the domain as permissive fails there. The nfs.ganesha daemon will run unconfined in RHEL 7.6 instead -- this should be pretty much the same as making its domain permissive. We should be safe simply ignoring this failure in the ansible scripts (i.e. adding failed_when: false). this fix will be in the next upstream stable-3.1 release (v3.1.5) Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2018:3530 |