Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1336742 - Service systemd-journald fails to start due to AVC denial on /etc/machine-id read
Service systemd-journald fails to start due to AVC denial on /etc/machine-id ...
Status: CLOSED ERRATA
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: Appliance (Show other bugs)
5.5.0
Unspecified Unspecified
high Severity high
: GA
: 5.6.0
Assigned To: Šimon Lukašík
luke couzens
appliance
: ZStream
Depends On:
Blocks: 1341242
  Show dependency treegraph
 
Reported: 2016-05-17 07:40 EDT by Jan Krocil
Modified: 2016-06-29 12:02 EDT (History)
9 users (show)

See Also:
Fixed In Version: 5.6.0.8
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 1341242 (view as bug list)
Environment:
Last Closed: 2016-06-29 12:02:54 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
jkrocil: automate_bug+


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2016:1348 normal SHIPPED_LIVE CFME 5.6.0 bug fixes and enhancement update 2016-06-29 14:50:04 EDT

  None (edit)
Description Jan Krocil 2016-05-17 07:40:13 EDT
Description of problem:
SSIA

Version-Release number of selected component (if applicable):
5.5.4.0
5.6.0.6-beta2.5

How reproducible:
Always

Steps to Reproduce:
1. Start a fresh appliance
2. # systemctl status systemd-journald

Actual results:
systemd-journald is not running

Expected results:
systemd-journald is running out of the box

Additional info:

dmesg:
======
[   13.331781] type=1400 audit(1463408382.377:4): avc:  denied  { read } for  pid=503 comm="systemd-journal" name="machine-id" dev="dm-0" ino=9948640 scontext=system_u:system_r:syslogd_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file

Workaround:
===========
# restorecon /etc/machine-id
# systemctl start systemd-journald
Comment 2 Nick Carboni 2016-05-19 09:54:20 EDT
I can't reproduce this on a 5.6.0.6-beta2.5 deploy.

What appliance build was this? VMWare? RHEV?

I deployed the VMWare appliance on Workstation and systemd-journald is up and running fine.
Comment 4 Šimon Lukašík 2016-05-19 12:34:18 EDT
The problem is that we have /etc/machine-id with unlabeled_t selinux label on the image (looking into rhos version, haven't unpacked vmware).
Comment 5 Šimon Lukašík 2016-05-20 05:03:05 EDT
The unlabeled_t means that we have re-created the /etc/machine-id during the build and we did not have the guest policy loaded during that operation. Do we keep appliance build logs somewhere?

Also, the bug 1308997 is worth reading.
Comment 6 Šimon Lukašík 2016-05-20 07:51:11 EDT
There are more unlabeled_t files:

  # find / -context *:unlabeled_t:*
  /etc/machine-id
  /var/account/pacct
  /mnt
  /mnt/lost+found

Because of this, logrorate fails to service psacct on the appliance.

   avc:  denied  { getattr } for  pid=1967 comm="logrotate"
   path="/var/account/pacct" dev="dm-8" ino=113078
   scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 
   tcontext=system_u:object_r:unlabeled_t:s0 tclass=file
Comment 9 Satoe Imaishi 2016-05-25 11:30:15 EDT
libguestfs package has been updated on the build machine, it now has the version mentioned above.
Comment 16 errata-xmlrpc 2016-06-29 12:02:54 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2016:1348

Note You need to log in before you can comment on or make changes to this bug.