Description of problem: SSIA Version-Release number of selected component (if applicable): 5.5.4.0 5.6.0.6-beta2.5 How reproducible: Always Steps to Reproduce: 1. Start a fresh appliance 2. # systemctl status systemd-journald Actual results: systemd-journald is not running Expected results: systemd-journald is running out of the box Additional info: dmesg: ====== [ 13.331781] type=1400 audit(1463408382.377:4): avc: denied { read } for pid=503 comm="systemd-journal" name="machine-id" dev="dm-0" ino=9948640 scontext=system_u:system_r:syslogd_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file Workaround: =========== # restorecon /etc/machine-id # systemctl start systemd-journald
I can't reproduce this on a 5.6.0.6-beta2.5 deploy. What appliance build was this? VMWare? RHEV? I deployed the VMWare appliance on Workstation and systemd-journald is up and running fine.
The problem is that we have /etc/machine-id with unlabeled_t selinux label on the image (looking into rhos version, haven't unpacked vmware).
The unlabeled_t means that we have re-created the /etc/machine-id during the build and we did not have the guest policy loaded during that operation. Do we keep appliance build logs somewhere? Also, the bug 1308997 is worth reading.
There are more unlabeled_t files: # find / -context *:unlabeled_t:* /etc/machine-id /var/account/pacct /mnt /mnt/lost+found Because of this, logrorate fails to service psacct on the appliance. avc: denied { getattr } for pid=1967 comm="logrotate" path="/var/account/pacct" dev="dm-8" ino=113078 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file
libguestfs package has been updated on the build machine, it now has the version mentioned above.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2016:1348