Bug 977415
Summary: | AVC denials when using openvswitch logrotate | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 6 | Reporter: | Ofer Blaut <oblaut> |
Component: | selinux-policy | Assignee: | Miroslav Grepl <mgrepl> |
Status: | CLOSED ERRATA | QA Contact: | Milos Malik <mmalik> |
Severity: | urgent | Docs Contact: | |
Priority: | urgent | ||
Version: | 6.5 | CC: | dwalsh, lhh, mmalik |
Target Milestone: | rc | Keywords: | ZStream |
Target Release: | 6.5 | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: |
Previously, the logrotate daemon rotated logs and tried to update the process ID (PID) in the "/var/run/openvswitch/ovs-vswitchd.pid" configuration, which caused AVC denials. Usually, the logrotate script sends a SIGHUP to a daemon to order it to reopen log files after they were rotated. This update revises the openvswitch policy, and AVC denials no longer occur in the described scenario.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2013-11-21 10:31:42 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 977477 |
Description
Ofer Blaut
2013-06-24 13:49:00 UTC
Fixed in selinux-policy-3.7.19-206.el6 Hi I have tried to reproduce with Milos help edit crontab -e with * * * * * logrotate -f /etc/logrotate.d/openvswitch * * * * * logrotate -f /etc/logrotate.d/openstack-quantum Didn't see any AVC Ofer Issue is reproduced thanks to Milos Steps: ## modify following lines in /etc/anacrontab RANDOM_DELAY=1 1 1 cron.daily nice run-parts /etc/cron.daily service auditd stop rm -f /var/log/audit/audit.log service auditd start rm -f /var/log/openvswitch/* service openvswitch restart rm -f /var/spool/anacron/cron.daily killall anacron ## modify following lines in /var/lib/logrotate.status /var/log/openvswitch/ovsdb-server.log" 2013-6-06 /var/log/openvswitch/ovs-vswitchd.log" 2013-6-06 date 06260300 tail -f /var/log/cron (wait 2 minutes) ausearch -m avc -m selinux_err -i Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2013-1598.html |