Bug 1231868 - SELinux: openvswitch and sysctl denials
Summary: SELinux: openvswitch and sysctl denials
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-selinux
Version: 7.0 (Kilo)
Hardware: Unspecified
OS: Linux
high
unspecified
Target Milestone: ga
: 7.0 (Kilo)
Assignee: Ryan Hallisey
QA Contact: Ofer Blaut
URL:
Whiteboard:
Depends On: 1176730
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-06-15 14:11 UTC by Ryan Hallisey
Modified: 2023-02-22 23:02 UTC (History)
12 users (show)

Fixed In Version: openstack-selinux-0.6.34-1.el7ost
Doc Type: Bug Fix
Doc Text:
Clone Of: 1176730
Environment:
Last Closed: 2015-08-05 13:26:31 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Launchpad 1405021 0 None None None Never
Red Hat Product Errata RHEA-2015:1548 0 normal SHIPPED_LIVE Red Hat Enterprise Linux OpenStack Platform Enhancement Advisory 2015-08-05 17:07:06 UTC

Description Ryan Hallisey 2015-06-15 14:11:59 UTC
+++ This bug was initially created as a clone of Bug #1176730 +++

Description of problem:
We have recently noticed these denials on Fedora 20,
type=AVC msg=audit(1418940256.937:191): avc:  denied  { search } for  pid=3481 comm="handler5" name="net" dev="proc" ino=9722 scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:sysctl_net_t:s0 tclass=dir permissive=1
type=AVC msg=audit(1418940256.937:191): avc:  denied  { read } for  pid=3481 comm="handler5" name="netdev_max_backlog" dev="proc" ino=16646 scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:sysctl_net_t:s0 tclass=file permissive=1
type=AVC msg=audit(1418940256.937:191): avc:  denied  { open } for  pid=3481 comm="handler5" path="/proc/sys/net/core/netdev_max_backlog" dev="proc" ino=16646 scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:sysctl_net_t:s0 tclass=file permissive=1
type=AVC msg=audit(1418940256.937:192): avc:  denied  { getattr } for  pid=3481 comm="handler5" path="/proc/sys/net/core/netdev_max_backlog" dev="proc" ino=16646 scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:sysctl_net_t:s0 tclass=file permissive=1

Version-Release number of selected component (if applicable):
openvswitch-2.3.0-3.git20141107.fc20.i686
selinux-policy-targeted-3.12.1-196.fc20.noarch

How reproducible:
always

Steps to Reproduce:
1. Run tripleo devtest and examine overcloud controller logs.


Actual results:
openvswitch denials logged

Expected results:
no denials logged

Additional info:

--- Additional comment from Fedora End Of Life on 2015-05-29 09:32:28 EDT ---

This message is a reminder that Fedora 20 is nearing its end of life.
Approximately 4 (four) weeks from now Fedora will stop maintaining
and issuing updates for Fedora 20. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as EOL if it remains open with a Fedora  'version'
of '20'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version.

Thank you for reporting this issue and we are sorry that we were not 
able to fix it before Fedora 20 is end of life. If you would still like 
to see this bug fixed and are able to reproduce it against a later version 
of Fedora, you are encouraged  change the 'version' to a later Fedora 
version prior this bug is closed as described in the policy above.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events. Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

Comment 3 Ryan Hallisey 2015-06-15 14:15:59 UTC
Migrating tripleo selinux element into openstack-selinux

Comment 5 Ryan Hallisey 2015-06-18 15:21:08 UTC
Additional policy needed for openstack-selinux so that we can remove tripleo selinux.  All set to build just need acks.

Comment 7 Ofer Blaut 2015-06-25 15:43:38 UTC
No Avc is seen on controllers/computes 

openstack-selinux-0.6.35-1.el7ost.noarch

Comment 9 errata-xmlrpc 2015-08-05 13:26:31 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2015:1548


Note You need to log in before you can comment on or make changes to this bug.