Bug 1955461
Summary: | RHVH 4.4.6: There are gluster related AVC denied errors in audit.log after upgrade | ||
---|---|---|---|
Product: | [Red Hat Storage] Red Hat Gluster Storage | Reporter: | Sandro Bonazzola <sbonazzo> |
Component: | selinux | Assignee: | Nobody <nobody> |
Status: | CLOSED ERRATA | QA Contact: | SATHEESARAN <sasundar> |
Severity: | medium | Docs Contact: | |
Priority: | unspecified | ||
Version: | rhgs-3.5 | CC: | godas, lveyde, peyu, pprakash, rcyriac, rhs-bugs, sasundar, sheggodu |
Target Milestone: | --- | Keywords: | Regression, ZStream |
Target Release: | RHGS 3.5.z Batch Update 7 | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | No Doc Update | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2021-10-05 07:56:28 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 1955415, 2020997, 2111410 |
Description
Sandro Bonazzola
2021-04-30 07:43:23 UTC
I have tested the same with RHVH 4.4.6. This happens when updating from RHVH 4.4.5 to 4.4.6, but the same AVCs are not seen with the fresh installation and deployment of RHHI-V 1.8.5 on RHVH 4.4.6 Again there are no functional loss seen with these AVCs Tested with glusterfs-selinux-1.0-5.el8rhgs with RHVH 4.4.8 interim build (RHVH-4.4-20210818.0-RHVH-x86_64-dvd1.iso) There are no AVC messages seen related to RDMA when restarting glusterd. This was verified with the steps: 1. Installed RHVH 4.4.5 and everytime restarting glusterd introduced AVC denials for RDMA <snip> type=AVC msg=audit(1629772417.256:33): avc: denied { create } for pid=1182 comm="glusterd" scontext=system_u:system_r:glusterd_t:s0 tcontext=system_u:system_r:glusterd_t:s0 tclass=netlink_rdma_socket permissive=0 type=AVC msg=audit(1629772417.256:34): avc: denied { create } for pid=1182 comm="glusterd" scontext=system_u:system_r:glusterd_t:s0 tcontext=system_u:system_r:glusterd_t:s0 tclass=netlink_rdma_socket permissive=0 </snip> 2. Upgraded the RHVH 4.4.5 to RHVH 4.4.8 and installed glusterfs-selinux-1.0-5.el8rhgs, rebooted the node. After the RHVH node is up, restarting glusterd had no AVC denials reported. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (RHGS 3.5.z Batch Update 5 glusterfs bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2021:3729 |