Created attachment 891738 [details] ami-979e05ad.yaml
Validation failed for ami-979e05ad in ap-southeast-2 product: RHEL, version: 7.0, arch: x86_64 m3.xlarge test stage1:testcase_01_bash_history succeeded test stage1:testcase_02_selinux_context succeeded test stage1:testcase_03_running_services succeeded test stage1:testcase_06_inittab succeeded test stage1:testcase_07_libc6_xen_conf succeeded test stage1:testcase_08_memory succeeded test stage1:testcase_09_nameserver succeeded test stage1:testcase_10_networking succeeded test stage1:testcase_11_package_set succeeded test stage1:testcase_14_host_details succeeded test stage1:testcase_15_rhel_version succeeded test stage1:testcase_16_selinux succeeded test stage1:testcase_17_shells succeeded test stage1:testcase_18_sshd succeeded test stage1:testcase_19_rhn_system_id succeeded test stage1:testcase_20_auditd succeeded test stage1:testcase_21_disk_size_format succeeded test stage1:testcase_25_uname succeeded test stage1:testcase_26_verify_rpms succeeded test stage1:testcase_27_yum_repos failed ---> actual repos: {'rhui-REGION-client-config-server-7-beta': True, 'rhui-REGION-rhel-server-releases-beta': True, 'rhui-REGION-rhel-server-releases-debug-beta': False, 'rhui-REGION-rhel-server-releases-source-beta': False} expected repos: {'rhui-REGION-client-config-server-7': True, 'rhui-REGION-rhel-server-releases-debug': False, 'rhui-REGION-rhel-server-releases': True, 'rhui-REGION-rhel-server-releases-source': False} result: failed <--- test stage1:testcase_31_subscription_management succeeded test stage1:testcase_32_ephemeral succeeded test stage1:testcase_33_userdata succeeded test stage1:testcase_34_cpu succeeded test stage1:testcase_35_console succeeded test stage1:testcase_360_ebs succeeded test stage1:testcase_39_root_is_locked succeeded test stage1:testcase_41_rh_amazon_rhui_client failed ---> actual: 1 command: rpm -q rh-amazon-rhui-client result: failed <--- test stage1:testcase_50_yum_package_install succeeded test stage1:testcase_55_yum_group_install failed ---> actual: 1 command: yum -y groupinstall 'Development tools' result: failed <--- ---> actual: 1 command: rpm -q glibc-devel result: failed <--- test stage1:testcase_60_yum_update succeeded test stage1:testcase_61_yum_proxy skipped ---> comment: No proxy set result: skip <--- test stage1:testcase_62_cpuflags succeeded test stage1:testcase_80_no_avc_denials succeeded test stage1:testcase_99_reboot succeeded test stage2:testcase_08_memory succeeded test stage2:testcase_25_uname succeeded test stage2:testcase_37_sshd_bug923996 succeeded test stage2:testcase_62_cpuflags succeeded test stage2:testcase_80_no_avc_denials failed ---> actual: echo START; grep 'avc:[[:space:]]*denied' /var/log/messages /var/log/audit/audit.log | grep -v userdata; echo END START /var/log/messages:May 2 03:54:43 ip-10-250-15-38 kernel: type=1400 audit(1399017283.726:4): avc: denied { write } for pid=240 comm="systemd-sysctl" name="shmmax" dev="proc" ino=8487 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/messages:May 2 03:54:43 ip-10-250-15-38 kernel: type=1400 audit(1399017283.726:5): avc: denied { write } for pid=240 comm="systemd-sysctl" name="shmall" dev="proc" ino=8488 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/messages:May 2 03:54:43 ip-10-250-15-38 kernel: type=1400 audit(1399017283.726:6): avc: denied { write } for pid=240 comm="systemd-sysctl" name="sysrq" dev="proc" ino=8489 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/messages:May 2 03:54:43 ip-10-250-15-38 kernel: type=1400 audit(1399017283.726:7): avc: denied { write } for pid=240 comm="systemd-sysctl" name="core_uses_pid" dev="proc" ino=8490 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/messages:May 2 03:54:43 ip-10-250-15-38 kernel: type=1400 audit(1399017283.726:8): avc: denied { write } for pid=240 comm="systemd-sysctl" name="rp_filter" dev="proc" ino=8494 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/messages:May 2 03:54:43 ip-10-250-15-38 kernel: type=1400 audit(1399017283.726:9): avc: denied { write } for pid=240 comm="systemd-sysctl" name="accept_source_route" dev="proc" ino=8495 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/messages:May 2 03:54:43 ip-10-250-15-38 kernel: type=1400 audit(1399017283.726:10): avc: denied { write } for pid=240 comm="systemd-sysctl" name="protected_hardlinks" dev="proc" ino=8497 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/audit/audit.log:type=AVC msg=audit(1399017285.149:34): avc: denied { write } for pid=578 comm="systemd-sysctl" name="shmmax" dev="proc" ino=8487 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/audit/audit.log:type=AVC msg=audit(1399017285.149:35): avc: denied { write } for pid=578 comm="systemd-sysctl" name="shmall" dev="proc" ino=8488 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/audit/audit.log:type=AVC msg=audit(1399017285.149:36): avc: denied { write } for pid=578 comm="systemd-sysctl" name="sysrq" dev="proc" ino=8489 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/audit/audit.log:type=AVC msg=audit(1399017285.149:37): avc: denied { write } for pid=578 comm="systemd-sysctl" name="core_uses_pid" dev="proc" ino=8490 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/audit/audit.log:type=AVC msg=audit(1399017285.149:38): avc: denied { write } for pid=578 comm="systemd-sysctl" name="rp_filter" dev="proc" ino=8494 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/audit/audit.log:type=AVC msg=audit(1399017285.149:39): avc: denied { write } for pid=578 comm="systemd-sysctl" name="accept_source_route" dev="proc" ino=8495 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/audit/audit.log:type=AVC msg=audit(1399017285.149:40): avc: denied { write } for pid=578 comm="systemd-sysctl" name="protected_hardlinks" dev="proc" ino=8497 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/audit/audit.log:type=AVC msg=audit(1399017285.149:41): avc: denied { write } for pid=578 comm="systemd-sysctl" name="protected_symlinks" dev="proc" ino=8498 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/audit/audit.log:type=AVC msg=audit(1399017285.519:43): avc: denied { write } for pid=730 comm="systemd-sysctl" name="shmmax" dev="proc" ino=8487 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/audit/audit.log:type=AVC msg=audit(1399017285.519:44): avc: denied { write } for pid=730 comm="systemd-sysctl" name="shmall" dev="proc" ino=8488 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/audit/audit.log:type=AVC msg=audit(1399017285.519:45): avc: denied { write } for pid=730 comm="systemd-sysctl" name="sysrq" dev="proc" ino=8489 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/audit/audit.log:type=AVC msg=audit(1399017285.519:46): avc: denied { write } for pid=730 comm="systemd-sysctl" name="core_uses_pid" dev="proc" ino=8490 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/audit/audit.log:type=AVC msg=audit(1399017285.519:47): avc: denied { write } for pid=730 comm="systemd-sysctl" name="rp_filter" dev="proc" ino=8494 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/audit/audit.log:type=AVC msg=audit(1399017285.519:48): avc: denied { write } for pid=730 comm="systemd-sysctl" name="accept_source_route" dev="proc" ino=8495 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/audit/audit.log:type=AVC msg=audit(1399017285.519:49): avc: denied { write } for pid=730 comm="systemd-sysctl" name="protected_hardlinks" dev="proc" ino=8497 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file /var/log/audit/audit.log:type=AVC msg=audit(1399017285.519:50): avc: denied { write } for pid=730 comm="systemd-sysctl" name="protected_symlinks" dev="proc" ino=8498 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file END [root@ip-10-250-15-38 ~]# command: echo START; grep 'avc:[[:space:]]*denied' /var/log/messages /var/log/audit/audit.log | grep -v userdata; echo END expectation: START END result: failed <---
Verified: rh-amazon-rhui-client-beta included, content was not released to production rhui, avc issues are not fixed in 3.10.0-54.0.1.el7 (https://bugzilla.redhat.com/show_bug.cgi?id=1071858)
housekeeping