This service will be undergoing maintenance at 00:00 UTC, 2017-10-23 It is expected to last about 30 minutes
Bug 1065327 - PCP mislabels newly created log files
PCP mislabels newly created log files
Status: CLOSED NOTABUG
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: pcp (Show other bugs)
7.0
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: Nathan Scott
qe-baseos-tools
:
Depends On: 999293
Blocks:
  Show dependency treegraph
 
Reported: 2014-02-14 06:13 EST by Marko Myllynen
Modified: 2015-10-09 09:13 EDT (History)
8 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: 999293
Environment:
Last Closed: 2014-03-20 09:19:35 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Marko Myllynen 2014-02-14 06:13:15 EST
+++ This bug was initially created as a clone of Bug #999293 +++

Description of problem:
After installing PCP on a new system, enabling all PCP services, and letting them run a while, the newly created log files have been mislabeled:

localhost:~# restorecon -v -R /var
restorecon reset /var/log/pcp/pmlogger/localhost/20130821.00.10.meta context system_u:object_r:cron_log_t:s0->system_u:object_r:var_log_t:s0
restorecon reset /var/log/pcp/pmlogger/localhost/20130821.00.10.index context system_u:object_r:cron_log_t:s0->system_u:object_r:var_log_t:s0
restorecon reset /var/log/pcp/pmlogger/localhost/20130820.index context system_u:object_r:cron_log_t:s0->system_u:object_r:var_log_t:s0
restorecon reset /var/log/pcp/pmlogger/localhost/20130820.0 context system_u:object_r:cron_log_t:s0->system_u:object_r:var_log_t:s0
restorecon reset /var/log/pcp/pmlogger/localhost/20130821.00.10.0 context system_u:object_r:cron_log_t:s0->system_u:object_r:var_log_t:s0
restorecon reset /var/log/pcp/pmlogger/localhost/pmlogger.log.prior context system_u:object_r:cron_log_t:s0->system_u:object_r:var_log_t:s0
restorecon reset /var/log/pcp/pmlogger/localhost/20130820.meta context system_u:object_r:cron_log_t:s0->system_u:object_r:var_log_t:s0
localhost:~# 

Version-Release number of selected component (if applicable):
pcp-3.8.2-1.el6.x86_64
selinux-policy-targeted-3.7.19-195.el6_4.12.noarch

--- Additional comment from Marko Myllynen on 2013-09-10 11:15:23 EEST ---

Also

restorecon reset /etc/pcp/pmlogger/config.default context system_u:object_r:etc_runtime_t:s0->system_u:object_r:etc_t:s0
Comment 2 Nathan Scott 2014-03-18 19:29:25 EDT
Hi Lukas,

Will the SELinux policy commit you made in #c8 of bz 1072785 tackle this issue that Marko has reported as well, by any chance?

thanks!
Comment 3 Lukas Vrabec 2014-03-20 09:07:16 EDT
Hi Nathan, 

Restorecon just restore right context for these files.

Marko, 
Some AVC appeared?
Comment 4 Marko Myllynen 2014-03-20 09:14:47 EDT
(In reply to Lukas Vrabec from comment #3)
> Restorecon just restore right context for these files.
> 
> Some AVC appeared?

I haven't seen any, I merely noticed this while I happened to run restorecon.
Comment 5 Lukas Vrabec 2014-03-20 09:19:35 EDT
It's OK. 

I'll close this, but please when you will get some AVC please report it here.
Comment 6 Marko Myllynen 2014-03-20 09:22:48 EDT
(In reply to Lukas Vrabec from comment #5)
> It's OK. 
> 
> I'll close this, but please when you will get some AVC please report it here.

Shouldn't the files be created with correct labels regardless of AVCs?
Comment 7 Nathan Scott 2014-03-20 21:45:30 EDT
(In reply to Marko Myllynen from comment #6)
> Shouldn't the files be created with correct labels regardless of AVCs?

Hi Marko - AIUI, the SELinux policy updates Lukas made (see #c8 of bz 1072785) ensure this labelling will be done correctly.  These are a relatively recent addition and wouldn't have been in the RHEL7 images you were testing.  Possibly this BZ could have been marked as a duplicate of that other, instead of closed/notabug.

cheers.
Comment 8 Marko Myllynen 2014-03-21 03:30:54 EDT
(In reply to Nathan Scott from comment #7)
> (In reply to Marko Myllynen from comment #6)
> > Shouldn't the files be created with correct labels regardless of AVCs?
> 
> Hi Marko - AIUI, the SELinux policy updates Lukas made (see #c8 of bz
> 1072785) ensure this labelling will be done correctly.  These are a
> relatively recent addition and wouldn't have been in the RHEL7 images you
> were testing.

Ok, sounds good, thanks!

Note You need to log in before you can comment on or make changes to this bug.