Bug 488699
Summary: | AVCs during 20090227.1 installation | ||||||
---|---|---|---|---|---|---|---|
Product: | Red Hat Satellite 5 | Reporter: | Jan Hutař <jhutar> | ||||
Component: | Server | Assignee: | Jan Pazdziora <jpazdziora> | ||||
Status: | CLOSED CURRENTRELEASE | QA Contact: | Jan Hutař <jhutar> | ||||
Severity: | medium | Docs Contact: | |||||
Priority: | medium | ||||||
Version: | 530 | CC: | cperry, mzazrivec | ||||
Target Milestone: | --- | ||||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | sat530 | Doc Type: | Bug Fix | ||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2009-09-10 19:12:17 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | 493629 | ||||||
Bug Blocks: | 457079 | ||||||
Attachments: |
|
Description
Jan Hutař
2009-03-05 09:40:51 UTC
The load_policy_t and setfiles_t issues addressed in 4ac8e4589ccef0d1b54236d7096f030fca4b5244. The spacewalk_monitoring_t initrc_t:fifo_file addressed in 883d0398abac9155216864c8e62cfd4e6ec39a55. The oracle_sqlplus_t nfs_t:dir search issue -- I am not exactly sure where it comes from. The oracle_tnslsnr_t initrc_t:fifo_file -- again, not exactly sure. The etc_runtime_t is strange -- I never saw /etc/tnsnames.ora created with this type. I just tried installation of Satellite-5.3.0-RHEL5-re20090403.2 on i386 and reboot and did not get any AVCs. As also noted in bug 493629, the etc_runtime_t AVC denial seems to be caused by the way the RHTS automation tests are started -- as initrc_t, not as unconfined_t. The other AVC denials were either addressed or I was not able to reproduce them. Moving to MODIFIED for now, as soon as RHTS is changed to run ./install.pl as unconfined_t, we should be able to move ON_QA to re-test. Moving ON_QA, as Jan H. noted in bug 493629 comment 6 that RHTS now uses runcon. Thanks to jpazdziora I have fixed the test and now satellite installs correctly, closing this one. Could you make the bugzilla VERIFIED then? We don't want this issue to disappear in the NOTABUG pile as the problem might reappear and by having it not CLOSED, it will be more visible. Sorry, done. Verified with last stage iso, no denials -> RELEASE_PENDING An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on therefore solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHEA-2009-1434.html |