Bug 680221

Summary: tps srpmtest failure due to avc failure at config.log
Product: Red Hat Enterprise Linux 6 Reporter: Vladimir Benes <vbenes>
Component: NetworkManagerAssignee: Dan Williams <dcbw>
Status: CLOSED NOTABUG QA Contact: Desktop QE <desktop-qa-list>
Severity: low Docs Contact:
Priority: low    
Version: 6.0CC: dwalsh
Target Milestone: rcKeywords: Regression
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-10-25 17:42:49 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Vladimir Benes 2011-02-24 17:30:24 UTC
Description of problem:

Running: /sbin/ausearch -sv no -m AVC -ts 02/17/2011 12:44:47 SELinux Check: 

FAIL SELinux AVC messages found: type=1400 audit(1297964727.372:32104): avc: 
denied { append } for pid=14594 comm="dhclient" path="/usr/src/redhat/BUILD/NetworkManager-0.8.1/config.log" dev=cciss/c0d0p2 ino=4164994 scontext=unconfined_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:object_r:usr_t:s0 tclass=file 

TPSHINT: It is possible that other stable systems activity has caused this issue. If you are sure that this is the case, you may waive this failure. If you have any doubts, RE-RUN tps to be sure. TPSRESULT: tps-srpmtest-selinux Returning: FAIL 

Version-Release number of selected component (if applicable):
NetworkManager-0.8.1-7.el6.src.rpm

Comment 1 Vladimir Benes 2011-02-24 17:34:36 UTC
it's looking like regression as there are no errors in z stream rhel6 package before:
http://nest.test.redhat.com/mnt/qa/scratch/i386-6s-m1/2010:10100/tps/tps.html

setting appropriate keywords

Comment 5 Dan Williams 2011-06-13 15:06:38 UTC
So the issue here is that the configure script needs to check the dhclient version to ensure it's >= 4.  That's only something that is done at build-time, not runtime.  No idea how we're supposed to handle build-time SELinux issues, since clearly a policy that allows this should not be applied to normal machines.

Comment 6 Dan Williams 2011-06-14 20:01:47 UTC
Dan; any idea what we do here for other packages?  Do we generally update SELinux policy just for issues rebuilding SRPMs?

Comment 7 Daniel Walsh 2011-06-14 20:52:05 UTC
I have no clue what is going on here.

This does not seem to be a runtime error.  I don't think we care about build errors.

Comment 9 Dan Williams 2011-10-25 15:50:16 UTC
So basically we either need to:

1) adjust selinux policy to allow certain operations at build time  but not at runtime (since this behavior isn't needed at runtime)

2) OR not use selinux on the build systems

Yes, we can patch out the dhclient version check for RHEL, but that's a hack since this shouldn't really be an issue in the first place, and this sort of thing happens in a few other places too.

Comment 10 Daniel Walsh 2011-10-25 17:42:49 UTC
So this only happens if you build NetworkManager as root, I am closing as not a bug.

Comment 11 Daniel Walsh 2011-10-25 17:43:40 UTC
We could change the build script to put a label on the log file.  I guess this build is happening from init?