Description of problem: If you run packstack with SELinux enabled, then Neutron fails to initialize correctly. You only see the loopback interface: 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever inet6 ::1/128 scope host valid_lft forever preferred_lft forever When I started a fresh packstack run with SELinux set to permissive, I see the full set of interfaces. audit2allow recommends: #============= neutron_t ============== allow neutron_t unlabeled_t:file { read open }; (I'm afraid I no longer have the original audit logs so I don't know exactly what file is unlabelled). Version-Release number of selected component (if applicable): openstack-packstack-2014.2-0.15.dev1401.gdd19d48.aa7a.noarch openstack-selinux-0.6.17-1.aa7a.noarch How reproducible: Several times. Steps to Reproduce: 1. Run packstack, multinode with default (Neutron) network configuration. Additional info: Longer explanation by Lars K-S here: http://post-office.corp.redhat.com/archives/rh-openstack-dev/2015-February/msg00457.html
(In reply to Richard W.M. Jones from comment #0) > Description of problem: > > If you run packstack with SELinux enabled, then Neutron > fails to initialize correctly. You only see the loopback > interface: > > 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN > link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 > inet 127.0.0.1/8 scope host lo > valid_lft forever preferred_lft forever > inet6 ::1/128 scope host > valid_lft forever preferred_lft forever > > When I started a fresh packstack run with SELinux set to > permissive, I see the full set of interfaces. > > audit2allow recommends: > > #============= neutron_t ============== > allow neutron_t unlabeled_t:file { read open }; We would need to see raw AVCs to check if it is a kernel issue or a bad labeling. > > (I'm afraid I no longer have the original audit logs so I > don't know exactly what file is unlabelled). > > Version-Release number of selected component (if applicable): > > openstack-packstack-2014.2-0.15.dev1401.gdd19d48.aa7a.noarch > openstack-selinux-0.6.17-1.aa7a.noarch > > How reproducible: > > Several times. > > Steps to Reproduce: > 1. Run packstack, multinode with default (Neutron) network configuration. > > Additional info: > > Longer explanation by Lars K-S here: > http://post-office.corp.redhat.com/archives/rh-openstack-dev/2015-February/ > msg00457.html