Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: Occured during RDO installation. Answer file attached. SELinux is preventing /usr/bin/python2.7 from 'name_bind' accesses on the tcp_socket . ***** Plugin catchall (100. confidence) suggests ************************** If you believe that python2.7 should be allowed name_bind access on the tcp_socket by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # grep swift-container /var/log/audit/audit.log | audit2allow -M mypol # semodule -i mypol.pp Additional Information: Source Context system_u:system_r:swift_t:s0 Target Context system_u:object_r:xserver_port_t:s0 Target Objects [ tcp_socket ] Source swift-container Source Path /usr/bin/python2.7 Port 6000 Host (removed) Source RPM Packages python-2.7.5-11.fc20.x86_64 Target RPM Packages Policy RPM selinux-policy-3.12.1-122.fc20.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 3.13.5-200.fc20.x86_64 #1 SMP Mon Feb 24 16:51:35 UTC 2014 x86_64 x86_64 Alert Count 3 First Seen 2014-03-03 11:31:18 EST Last Seen 2014-03-03 11:31:20 EST Local ID 0ebbd96d-cba9-436a-813f-e0f47314c81f Raw Audit Messages type=AVC msg=audit(1393864280.152:12073): avc: denied { name_bind } for pid=29073 comm="swift-object-se" src=6000 scontext=system_u:system_r:swift_t:s0 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket type=SYSCALL msg=audit(1393864280.152:12073): arch=x86_64 syscall=bind success=no exit=EACCES a0=4 a1=7fffdbe9a510 a2=10 a3=14 items=0 ppid=1 pid=29073 auid=4294967295 uid=1001 gid=1001 euid=1001 suid=1001 fsuid=1001 egid=1001 sgid=1001 fsgid=1001 ses=4294967295 tty=(none) comm=swift-object-se exe=/usr/bin/python2.7 subj=system_u:system_r:swift_t:s0 key=(null) Hash: swift-container,swift_t,xserver_port_t,tcp_socket,name_bind Additional info: reporter: libreport-2.1.12 hashmarkername: setroubleshoot kernel: 3.13.5-200.fc20.x86_64 type: libreport
Created attachment 870035 [details] File: packstack-answers-20140303-103051.txt
Why does /usr/bin/swift-object-server need this?
Swift object server is acting as an XServer?
No, it just listens on port 6000 (among others). It's actually HTTP. It can be configured, but due to unfortunate historic tradition the 6000 is assumed.
BTW, this is a long-standing problem. See bug 1004881 comment #4. I keep getting to an idea of moving all the port blocks away from 6000, but it requires a coordinated effort due to those ports being stuck in several places: docs, scripts, Puppet, config examples.
(In reply to Pete Zaitcev from comment #4) > No, it just listens on port 6000 (among others). It's actually HTTP. > It can be configured, but due to unfortunate historic tradition > the 6000 is assumed. I would love to change this port to another. So now it is not going to be working correctly in enforcing mode without it.
Description of problem: Trying to start instance in openstack. Additional info: reporter: libreport-2.2.0 hashmarkername: setroubleshoot kernel: 3.13.7-200.fc20.x86_64 type: libreport
This package has changed ownership in the Fedora Package Database. Reassigning to the new owner of this component.
This message is a reminder that Fedora 20 is nearing its end of life. Approximately 4 (four) weeks from now Fedora will stop maintaining and issuing updates for Fedora 20. It is Fedora's policy to close all bug reports from releases that are no longer maintained. At that time this bug will be closed as EOL if it remains open with a Fedora 'version' of '20'. Package Maintainer: If you wish for this bug to remain open because you plan to fix it in a currently maintained version, simply change the 'version' to a later Fedora version. Thank you for reporting this issue and we are sorry that we were not able to fix it before Fedora 20 is end of life. If you would still like to see this bug fixed and are able to reproduce it against a later version of Fedora, you are encouraged change the 'version' to a later Fedora version prior this bug is closed as described in the policy above. Although we aim to fix as many bugs as possible during every release's lifetime, sometimes those efforts are overtaken by events. Often a more recent Fedora release includes newer upstream software that fixes bugs or makes them obsolete.
Fedora 20 changed to end-of-life (EOL) status on 2015-06-23. Fedora 20 is no longer maintained, which means that it will not receive any further security or bug fix updates. As a result we are closing this bug. If you can reproduce this bug against a currently maintained version of Fedora please feel free to reopen this bug against that version. If you are unable to reopen this bug, please file a new report against the current release. If you experience problems, please add a comment to this bug. Thank you for reporting this bug and we are sorry it could not be fixed.