RDO tickets are now tracked in Jira https://issues.redhat.com/projects/RDO/issues/
Bug 1211719 - selinux audit failures on openvswitch in rdo kilo
Summary: selinux audit failures on openvswitch in rdo kilo
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: RDO
Classification: Community
Component: openstack-selinux
Version: trunk
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
: Kilo
Assignee: Ryan Hallisey
QA Contact: Ofer Blaut
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-04-14 17:40 UTC by wes hayutin
Modified: 2016-04-26 17:52 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-08-26 15:35:25 UTC
Embargoed:


Attachments (Terms of Use)

Description wes hayutin 2015-04-14 17:40:07 UTC
Description of problem:
type=AVC msg=audit(1428973033.595:7478): avc:  denied  { dac_override } for  pid=17446 comm="revalidator_3" capability=1  scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:system_r:openvswitch_t:s0 tclass=capability
type=AVC msg=audit(1428973033.595:7479): avc:  denied  { write } for  pid=17446 comm="revalidator_3" name="/" dev="vda1" ino=128 scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=dir
type=AVC msg=audit(1428973033.595:7480): avc:  denied  { add_name } for  pid=17446 comm="revalidator_3" name="core.17331" scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=dir
type=AVC msg=audit(1428973033.595:7481): avc:  denied  { create } for  pid=17446 comm="revalidator_3" name="core.17331" scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=file
type=AVC msg=audit(1428973033.595:7482): avc:  denied  { read write open } for  pid=17446 comm="revalidator_3" path="/core.17331" dev="vda1" ino=421231 scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=file


See job
https://prod-rdojenkins.rhcloud.com/view/RDO-Trunk/job/khaleesi-rdo-kilo-delorean-centos-7.0-aio-packstack-neutron-ml2-vxlan-qpidd-tempest-rpm-minimal/19/consoleFull

for logs and details

Comment 1 Lon Hohberger 2015-08-26 15:35:25 UTC
This should be resolved:

https://cbs.centos.org/koji/buildinfo?buildID=1426


Note You need to log in before you can comment on or make changes to this bug.