Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1134737 - Improve SELinux sosreport/foreman-debug
Improve SELinux sosreport/foreman-debug
Status: CLOSED ERRATA
Product: Red Hat Satellite 6
Classification: Red Hat
Component: Packaging (Show other bugs)
6.0.4
Unspecified Unspecified
unspecified Severity medium (vote)
: Unspecified
: Unused
Assigned To: Lukas Zapletal
Elyézer Rezende
http://projects.theforeman.org/issues...
: Triaged
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2014-08-28 04:23 EDT by Lukas Zapletal
Modified: 2017-02-23 16:01 EST (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-08-12 01:15:27 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Foreman Issue Tracker 7098 None None None 2016-04-22 11:03 EDT
Red Hat Product Errata RHSA-2015:1592 normal SHIPPED_LIVE Important: Red Hat Satellite 6.1.1 on RHEL 6 2015-08-12 05:04:35 EDT

  None (edit)
Description Lukas Zapletal 2014-08-28 04:23:16 EDT
We already added some information to foreman-debug (grep AVC and audit2allow).

Unfortunately when selinux interfaces are not installed and generated, -R option can fail:

COMMAND> audit2allow -R < /var/log/audit/audit.log

could not open interface info [/var/lib/sepolgen/interface_info]

I am going to fix this and add few more selinux related information to the tarball.

PM: Please ack this for 6.0.4, I need this to improve SELinux bug reports. I am missing some important bits. Thanks.
Comment 1 Lukas Zapletal 2014-08-28 04:24:10 EDT
Upstream patch is pending: http://projects.theforeman.org/issues/7098

https://github.com/theforeman/foreman/pull/1691

Please review.
Comment 5 Bryan Kearney 2014-10-06 06:06:50 EDT
Moving to POST since upstream bug http://projects.theforeman.org/issues/7098 has been closed
-------------
Lukas Zapletal
Applied in changeset commit:80cc99f4b0d0af0afdba8def1256b37c4862430f.
Comment 6 Lukas Zapletal 2015-02-03 07:44:43 EST
Jason, this bug was initially filed on SELinux component, but it was an improvement in our foreman-debug script. Changed the component to Packaging, this needs to be cherry-picked.

For SELinux bugs (policy) I am providing the pull requests directly to you. But this is different one. Thanks.
Comment 11 Bryan Kearney 2015-02-17 20:46:50 EST
Upstream bug assigned to lzap@redhat.com
Comment 12 Elyézer Rezende 2015-03-09 12:18:06 EDT
Verified on: Satellite-6.1.0-RHEL-7-20150303.0

Steps do verify:

[root@sat6 ~]# mkdir debug
[root@sat6 ~]# foreman-debug -d debug/
[root@sat6 ~]# ls -l debug/ | grep selinux
-rw-r--r--.  1 root root     76 Mar  9 12:10 selinux_audit2allow
-rw-r--r--.  1 root root  23308 Mar  9 12:10 selinux_booleans
-rw-r--r--.  1 root root   3129 Mar  9 12:10 selinux_denials.log
-rw-r--r--.  1 root root 627974 Mar  9 12:10 selinux_fcontext
-rw-r--r--.  1 root root   3106 Mar  9 12:10 selinux_first_denials.log
-rw-r--r--.  1 root root   5935 Mar  9 12:10 selinux_modules

Also checked the contents of each file.
Comment 13 Bryan Kearney 2015-08-11 09:32:46 EDT
This bug is slated to be released with Satellite 6.1.
Comment 14 errata-xmlrpc 2015-08-12 01:15:27 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2015:1592

Note You need to log in before you can comment on or make changes to this bug.