Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1230900 - selinux denies neutron-rootwrap to read sudodb
selinux denies neutron-rootwrap to read sudodb
Status: CLOSED ERRATA
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-selinux (Show other bugs)
7.0 (Kilo)
Unspecified Unspecified
urgent Severity urgent
: ga
: 7.0 (Kilo)
Assigned To: Lon Hohberger
Eran Kuris
: Automation, Regression
Depends On: 1230438
Blocks: 1228096
  Show dependency treegraph
 
Reported: 2015-06-11 13:46 EDT by Jakub Libosvar
Modified: 2016-04-26 10:36 EDT (History)
17 users (show)

See Also:
Fixed In Version: openstack-selinux-0.6.32-1.el7ost
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: 1230438
Environment:
Last Closed: 2015-08-05 09:26:10 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHEA-2015:1548 normal SHIPPED_LIVE Red Hat Enterprise Linux OpenStack Platform Enhancement Advisory 2015-08-05 13:07:06 EDT

  None (edit)
Comment 1 Lon Hohberger 2015-06-12 11:41:17 EDT
There are a couple of issues.  First, there may require policy changes:

https://bugzilla.redhat.com/show_bug.cgi?id=1230438#c13

Second, neutron-rootwrap-daemon is the wrong file context, which can be fixed in the bugzilla spec file.
Comment 3 Ihar Hrachyshka 2015-06-15 07:24:34 EDT
@Lon, do you mean we should set selinux policy in .spec file?
Comment 4 Ihar Hrachyshka 2015-06-15 08:03:05 EDT
OK, I see that openstack-selinux-0.6.32-1.el7ost has neutron related fixes and is tagged for rhos-7.0-rhel-7-candidate. Does it mean it will be included in ga and we can mark the bug as fixed?
Comment 5 Lon Hohberger 2015-06-16 10:05:04 EDT
Yes.
Comment 7 Eran Kuris 2015-07-01 03:43:59 EDT
verified  on 
stack@instack ~]$ rpm -qa |grep openstack-selinux-
openstack-selinux-0.6.35-1.el7ost.noarch

RHEL-OSP director puddle 7.0 RC - 2015-06-29.1


 installation and deployment successful 
Connection to 192.0.2.7 closed.
Overcloud Endpoint: http://192.0.2.7:5000/v2.0/
Overcloud Deployed
Comment 9 errata-xmlrpc 2015-08-05 09:26:10 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2015:1548

Note You need to log in before you can comment on or make changes to this bug.