Bug 1321781 - [SELinux]: user_avc seen in audit logs while nfs-ganesha configuration in RHEL7
Summary: [SELinux]: user_avc seen in audit logs while nfs-ganesha configuration in RHEL7
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Gluster Storage
Classification: Red Hat Storage
Component: nfs-ganesha
Version: rhgs-3.1
Hardware: x86_64
OS: Linux
unspecified
medium
Target Milestone: ---
: RHGS 3.2.0
Assignee: Kaleb KEITHLEY
QA Contact: surabhi
URL:
Whiteboard:
Depends On: 1321785
Blocks: 1351522
TreeView+ depends on / blocked
 
Reported: 2016-03-29 07:03 UTC by Shashank Raj
Modified: 2017-03-23 06:21 UTC (History)
10 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
: 1321785 (view as bug list)
Environment:
Last Closed: 2017-03-23 06:21:46 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHEA-2017:0493 0 normal SHIPPED_LIVE Red Hat Gluster Storage 3.2.0 nfs-ganesha bug fix and enhancement update 2017-03-23 09:19:13 UTC

Description Shashank Raj 2016-03-29 07:03:23 UTC
Description of problem:
user_avc seen in audit logs while nfs-ganesha configuration.

Version-Release number of selected component (if applicable):
3.7.9-1

How reproducible:
Always

Steps to Reproduce:
1.Install a 4 node cluster.
2.Configure and setup nfs-ganesha on the cluster
3.Observed below user_avc in audit.log, however It doesn't hamper any functionality as of now

type=USER_AVC msg=audit(1459157156.191:3548): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='avc:  denied  { status } for auid=n/a uid=0 gid=0 cmdline="systemctl is-enabled corosync pacemaker pcsd" scontext=system_u:system_r:glusterd_t:s0 tcontext=system_u:system_r:init_t:s0 tclass=system  exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? Terminal=?'

Actual results:
user_avc seen in audit logs while nfs-ganesha configuration.

Expected results:
Should not be seen

Additional info:

Comment 2 Shashank Raj 2016-03-29 07:30:25 UTC
Selinux version:

[root@dhcp46-247 ganesha]# rpm -qa|grep selinux

selinux-policy-targeted-3.13.1-60.el7.noarch
selinux-policy-3.13.1-60.el7.noarch

Comment 11 surabhi 2016-11-17 07:22:08 UTC
There are no AVC's seen related to pcs,pacemaker,corosync or ganesha as mentioned in bz description on configuring gnaesha on rhel7.3 based layered install.

nfs-ganesha-2.4.1-1.el7rhgs.x86_64
nfs-ganesha-gluster-2.4.1-1.el7rhgs.x86_64
glusterfs-ganesha-3.8.4-5.el7rhgs.x86_64
selinux-policy-3.13.1-102.el7_3.4.noarch
selinux-policy-targeted-3.13.1-102.el7_3.4.noarch

Will verify once with the ISO installation and will update the BZ.

Comment 12 surabhi 2016-11-18 09:15:32 UTC
Verified with ISO installation from RHGS3.1.3 upgraded to 3.2 bits and with latest SELinux policy build. Moving the BZ to verified.

Comment 14 errata-xmlrpc 2017-03-23 06:21:46 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHEA-2017-0493.html


Note You need to log in before you can comment on or make changes to this bug.