Bug 1112361
| Summary: | rhel/centos packstack multinode w/ neutron gre networking selinux denial on swift-proxy-ser | ||||||
|---|---|---|---|---|---|---|---|
| Product: | [Community] RDO | Reporter: | wes hayutin <whayutin> | ||||
| Component: | openstack-selinux | Assignee: | RHOS Maint <rhos-maint> | ||||
| Status: | CLOSED CURRENTRELEASE | QA Contact: | wes hayutin <whayutin> | ||||
| Severity: | high | Docs Contact: | |||||
| Priority: | unspecified | ||||||
| Version: | unspecified | CC: | apevec, jruzicka, lhh, rhallise, yeylon | ||||
| Target Milestone: | Milestone1 | ||||||
| Target Release: | --- | ||||||
| Hardware: | Unspecified | ||||||
| OS: | Unspecified | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | openstack-selinux-0.5.4-1.el7ost | Doc Type: | Bug Fix | ||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | Type: | Bug | |||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Attachments: |
|
||||||
I pushed openstack-selinux-0.5.4-1.el7ost to RDO stage, It's going to be available on next sync. resolved for RHEL/CetnOS |
Created attachment 911528 [details] install and config logs Description of problem: type=SYSCALL msg=audit(1403525972.129:95): arch=c000003e syscall=313 success=yes exit=0 a0=0 a1=7f6541b5cd89 a2=0 a3=0 items=0 ppid=1515 pid=1533 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="modprobe" exe="/usr/bin/kmod" subj=system_u:system_r:insmod_t:s0 key=(null) type=AVC msg=audit(1403525972.222:96): avc: denied { search } for pid=1121 comm="swift-proxy-ser" name="httpd" dev="vda1" ino=276866351 scontext=system_u:system_r:swift_t:s0 tcontext=system_u:object_r:httpd_config_t:s0 tclass=dir attached are the setup and configuration logs. the audit log is in the tar file