Description of problem: We have our zabbix monitoring user perform restarts of services when he detects that they are down. During a recent mcollective restart we noticed that the selinux contexts had changed. Here is what it looks like: system_u:system_r:zabbix_agent_t:s0 (mcollective process) Normally it is: system_u:system_r:openshift_initrc_t:s0-s0:c0.c1023 OR unconfined_u:system_r:openshift_initrc_t:s0-s0:c0.c1023 It appears that the service restart from zabbix needs to allow the transition back to the openshift context. Version-Release number of selected component (if applicable): Current. How reproducible: Very in our environment. Steps to Reproduce: 1. As root, stop the mcollective service 2. Zabbix will detect that mcollective is down and attempt to restart it. 3. Once restarted it will have the new context. Actual results: Mcollective process now has zabbix_agent_t as a context. Expected results: Should return to openshift_initrc_t. Additional info: Please let me know if you need any information on this. Excuse my ignorance when it comes to selinux but I believe we would like our policy to allow the zabbix user to restart services and for those services to transition back to their normal contexts. I believe this is new as of RHEL 6.5
*** Bug 1040145 has been marked as a duplicate of this bug. ***
Commit pushed to master at https://github.com/openshift/li https://github.com/openshift/li/commit/d22e439902d96b4c9767b674a217313cba829d40 Bug 1038237 - unconfine Zabbix agent for Online * As a stop gap solution for OpenShift Online add selinux policy to unconfine Zabbix agent. Code provided by dwalsh.
With the recent commit pushed to 'li', shouldn't this BZ be ON_QA? Also, is there relation with https://bugzilla.redhat.com/show_bug.cgi?id=1032691?
Stop gap solution was put in place, waiting on backport of permanent solution from selinux team. BZ#1032691 is tracking that change.
Jhon, so do we need this bug in addition to 1032691?
https://bugzilla.redhat.com/show_bug.cgi?id=1032691 is tracking the change in the default policy files, this bug is to remind us to pull the customized policies for Online.
Jhon, looks like the above references are all closed. Something we need to do now?
Fixed in https://github.com/openshift/li/pull/3021
Commit pushed to master at https://github.com/openshift/li https://github.com/openshift/li/commit/47dba74db2df0556a6f40a0fa7e7faa7c853e531 Bug 1038237 - remove online Zabbix policy * Revert d22e439902d96b4c9767b674a217313cba829d40
since zabbix has been remove from li, so Verified this bug