Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1232892 - Merge Ipxe tripleo selinux policy into openstack-selinux
Merge Ipxe tripleo selinux policy into openstack-selinux
Status: CLOSED ERRATA
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-selinux (Show other bugs)
Director
Unspecified Unspecified
high Severity unspecified
: ga
: 7.0 (Kilo)
Assigned To: Ryan Hallisey
Omri Hochman
: OtherQA, Triaged
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2015-06-17 14:32 EDT by Ryan Hallisey
Modified: 2015-08-05 09:27 EDT (History)
8 users (show)

See Also:
Fixed In Version: openstack-selinux-0.6.34-1.el7ost
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-08-05 09:27:27 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHEA-2015:1548 normal SHIPPED_LIVE Red Hat Enterprise Linux OpenStack Platform Enhancement Advisory 2015-08-05 13:07:06 EDT

  None (edit)
Description Ryan Hallisey 2015-06-17 14:32:59 EDT
Merge tripleo selinux element into openstack-selinux

module ironic-ipxe 1.0;
require {
type httpd_t;
type tftpdir_t;
class file { read getattr open };
}
#============= httpd_t ==============
allow httpd_t tftpdir_t:file { read getattr open };
Comment 3 Ryan Hallisey 2015-06-18 11:19:51 EDT
Additional policy needed for openstack-selinux so that we can remove tripleo selinux.  All set to build just need acks.
Comment 4 Ryan Hallisey 2015-06-23 10:54:00 EDT
whoops.  Ignore the blocker flag reset.
Comment 7 Omri Hochman 2015-07-22 15:42:37 EDT
Verified openstack-selinux-0.6.37-1.el7ost.noarch : 

According to comment #6
Added selinux to "exclude-element : 

    "exclude-element": [
      "pip-and-virtualenv",
      "ironic",
      "os-collect-config",
      "selinux",
      "openstack-clients"
    ],

(1) successful deployment of undercloud: 
#############################################################################
instack-install-undercloud complete.

(2) successful deployment of overcloud :
DEBUG: os_cloud_config.utils.clients Creating nova client.
Overcloud Endpoint: http://10.19.184.50:5000/v2.0/
Overcloud Deployed
DEBUG: openstackclient.shell clean_up DeployOvercloud
Comment 8 Ryan Hallisey 2015-07-23 15:39:59 EDT
    "exclude-element": [
      "pip-and-virtualenv",
      "ironic",
      "os-collect-config",
      "selinux",
      "ipxe",
      "openstack-clients"
    ],

This is actually still applying the ipxe rule.  You need to exclude the two elements linked below.  I think the above will do it.

https://github.com/rdo-management/instack-undercloud/tree/master/elements/ipxe/selinux

https://github.com/rdo-management/instack-undercloud/blob/master/elements/ipxe/os-refresh-config/configure.d/00-apply-selinux-policy
Comment 9 Omri Hochman 2015-07-28 15:43:27 EDT
Following the instructions on Comment #8 , probably caused to following side effect :

1) this file was missing /tftpboot/undionly.kpxe
2) the http wasn't running on port 8088

we need to find another way to verify..
Comment 11 errata-xmlrpc 2015-08-05 09:27:27 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2015:1548

Note You need to log in before you can comment on or make changes to this bug.