Bug 1278495 - Got 17 "avc denied" messages on starting up openvswitch service
Got 17 "avc denied" messages on starting up openvswitch service
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: selinux-policy (Show other bugs)
7.2
x86_64 Linux
high Severity high
: rc
: ---
Assigned To: Lukas Vrabec
Milos Malik
: ZStream
: 1320043 (view as bug list)
Depends On:
Blocks: 1299405
  Show dependency treegraph
 
Reported: 2015-11-05 10:47 EST by Jean-Tsung Hsiao
Modified: 2016-11-03 22:24 EDT (History)
15 users (show)

See Also:
Fixed In Version: selinux-policy-3.13.1-62.el7
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 1299405 (view as bug list)
Environment:
Last Closed: 2016-11-03 22:24:09 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
/var/log/audit/audit.log (538.82 KB, text/plain)
2015-11-05 10:47 EST, Jean-Tsung Hsiao
no flags Details

  None (edit)
Description Jean-Tsung Hsiao 2015-11-05 10:47:29 EST
Created attachment 1090186 [details]
/var/log/audit/audit.log

Description of problem: Got 17 "avc denied" messages on starting up openvswitch service
type=AVC msg=audit(1446735509.031:30): avc:  denied  { read } for  pid=1900 comm="ovs-vswitchd" name="/" dev="hugetlbfs" ino=12482 scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:hugetlbfs_t:s0 tclass=dir
type=AVC msg=audit(1446735509.031:30): avc:  denied  { open } for  pid=1900 comm="ovs-vswitchd" path="/dev/hugepages" dev="hugetlbfs" ino=12482 scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:hugetlbfs_t:s0 tclass=dir
type=AVC msg=audit(1446735509.031:31): avc:  denied  { lock } for  pid=1900 comm="ovs-vswitchd" path="/dev/hugepages" dev="hugetlbfs" ino=12482 scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:hugetlbfs_t:s0 tclass=dir
type=AVC msg=audit(1446735509.064:32): avc:  denied  { write } for  pid=1900 comm="ovs-vswitchd" name="/" dev="hugetlbfs" ino=12482 scontext=system_u:system_r:openvswitch_t:s0 tcontext=system_u:object_r:hugetlbfs_t:s0 tclass=dir

See attached audit.log for more.


Version-Release number of selected component (if applicable):
RHEL 7.2 Beta Snapshot #5
openvswitch-dpdk-2.4.0-0.10346.git97bab959.1.el7.x86_64
dpdk-2.1.0-3.el7.x86_64

How reproducible: Reproducible


Steps to Reproduce:
1. Set up OVS+DPDK test-bed
2. setenforce 0
3. systemctl start openvswitch
4. Check /var/log/audit/audit.log

Actual results:


Expected results:


Additional info:
Comment 2 Flavio Leitner 2015-11-05 12:43:08 EST
Those are correct. DPDK enabled openvswitch allocates hugepages and so it needs access to hugetlbfs filesystem.
Reassigning to selinux-policy.
Comment 3 Milos Malik 2015-11-06 02:51:30 EST
It's too late for RHEL-7.2.
Comment 10 Lukas Vrabec 2016-01-18 04:09:15 EST
Commit id in comment 9 is pointing to fix in selinux-policy gitlab, where we store fixes before distgit repo.
Comment 15 Nir Yechiel 2016-09-01 04:36:19 EDT
*** Bug 1320043 has been marked as a duplicate of this bug. ***
Comment 17 errata-xmlrpc 2016-11-03 22:24:09 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2283.html

Note You need to log in before you can comment on or make changes to this bug.