Bug 1937111
| Summary: | Add cluster_exec_t default context for /usr/lib/pcs/pcs_snmp_agent | |||
|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Reid Wahl <nwahl> | |
| Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> | |
| Status: | CLOSED ERRATA | QA Contact: | Milos Malik <mmalik> | |
| Severity: | medium | Docs Contact: | ||
| Priority: | medium | |||
| Version: | 8.3 | CC: | cfeist, cluster-maint, idevat, kmalyjur, lvrabec, mlisik, mmalik, mpospisi, omular, plautrba, rmetrich, ssekidde, tojeline | |
| Target Milestone: | rc | Keywords: | AutoVerified, Triaged | |
| Target Release: | 8.5 | Flags: | pm-rhel:
mirror+
|
|
| Hardware: | All | |||
| OS: | Linux | |||
| Whiteboard: | ||||
| Fixed In Version: | selinux-policy-3.14.3-75.el8 | Doc Type: | Bug Fix | |
| Doc Text: |
Cause:
The /usr/lib/pcs/pcs_snmp_agent file has the default lib_t type which is incorrect.
Consequence:
The pcs_snmp_agent process doesn't have the permission to write to the /var/log/pcsd directory. As a result, the pcs_snmp_agent service fails to start.
Fix:
The /usr/lib/pcs/pcs_snmp_agent file now has the cluster_exec_t type.
Result:
The pcs_snmp_agent service starts correctly and is able to write to its logs.
|
Story Points: | --- | |
| Clone Of: | ||||
| : | 2029316 (view as bug list) | Environment: | ||
| Last Closed: | 2021-11-09 19:42:58 UTC | Type: | Bug | |
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Embargoed: | ||||
|
Description
Reid Wahl
2021-03-09 21:03:06 UTC
It might make sense to also give cluster_exec_t context to /usr/lib/pcs/pcs_internal, although the current lib_t context hasn't caused any known problems for that file. I've submitted a Fedora PR to address the issue: https://github.com/fedora-selinux/selinux-policy/pull/811 Commit to backport:
commit f8bbececbc075ba7a6da112ab9f596bf7cd32ab7 (HEAD -> rawhide, upstream/rawhide)
Author: Zdenek Pytela <zpytela>
Date: Wed Jul 28 17:32:26 2021 +0200
Label /usr/lib/pcs/pcs_snmp_agent with cluster_exec_t
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (selinux-policy bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2021:4420 |