Bug 697131

Summary: SELinux prevents creation of kickstart profile
Product: [Community] Spacewalk Reporter: Jonathan DeHaan <jdehaan>
Component: ServerAssignee: Michael Mráka <mmraka>
Status: CLOSED CURRENTRELEASE QA Contact: Red Hat Satellite QA List <satqe-list>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 1.3   
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-07-21 14:43:33 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On:    
Bug Blocks: 695242    

Description Jonathan DeHaan 2011-04-15 23:32:36 UTC
Description of problem:
SELinux in Enforcing mode with the 'targetted' profile prevents creation of a new kickstart profile. Setting SELinux to Permissive allows the kickstart profile to be created.

Version-Release number of selected component (if applicable):
Spacewalk 1.3
Fedora 14 x86_64

How reproducible:
Always

Steps to Reproduce:
1. Install Fedora 14 x86_64, keeping the default SELinux setting of Enorcing
2. Install Spacewalk 1.3
3. Create base channel and kickstart distribution
4. Create kickstart profile
  
Actual results:
500 Internal Error after setting root password for profile. The profile is created in Cobbler, but cannot be managed in Spacewalk.

Expected results:
A profile is created that can be edited in Spacewalk.


Additional info:
/var/log/audit/audit.log:
type=AVC msg=audit(1302910027.295:399): avc:  denied  { getattr } for  pid=12033 comm="cobblerd" path="/var/lib/rhn/kickstarts/wizard/Maximum--1.cfg" dev=dm-0 ino=21104823 scontext=system_u:system_r:cobblerd_t:s0 tcontext=system_u:object_r:var_lib_t:s0 tclass=file

Comment 1 Michael Mráka 2011-05-11 07:13:26 UTC
This issue has been fixed in spacewalk master as a part of bug 702274.

Comment 2 Jan Pazdziora 2011-07-19 19:36:46 UTC
This bugzilla is currently MODIFIED, so we believe the fix is in the Spacewalk nightly yum repository at http://spacewalk.redhat.com/yum/nightly/

Therefore, moving ON_QA.

Comment 3 Jan Pazdziora 2011-07-21 14:43:33 UTC
Spacewalk 1.5 was released.