Cinder upstream in Kilo has added paths /usr/local/bin and /usr/local/sbin to the rootwrap exec_paths in the default config. We should remove these from the config shipped with RHOS Cinder as a security hardening measure and document how customers can add this if really needed.
Tested using: python-cinder-7.0.1-5.el7ost.noarch openstack-cinder-7.0.1-5.el7ost.noarch python-cinderclient-1.4.0-1.el7ost.noarch Results: The paths /usr/local/bin and /usr/local/sbin have removed from rootwrap exec_paths in the default config From rootwrap config: [DEFAULT] exec_dirs=/sbin,/usr/sbin,/bin,/usr/bin
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHEA-2016-0603.html