Hide Forgot
Description of problem: Can't deploy an overcloud because selinux blocks neutron_t to access unlabeled_t files (nsfs) require { type unlabeled_t; type neutron_t; class file { read open }; } #============= neutron_t ============== allow neutron_t unlabeled_t:file { read open }; Version-Release number of selected component (if applicable): How reproducible: Always Steps to Reproduce: 1. Generate images on RHEL 7.2 2. Install undercloud 3. Introspection works fine 4. openstack overcloud deploy times out Actual results: Fails to PXE boot Expected results: Should be allowed. Additional info:
https://bugzilla.redhat.com/show_bug.cgi?id=1359216 is the same issue.
*** Bug 1359216 has been marked as a duplicate of this bug. ***
Sounds like a configuration / labeling issue: 1) Nothing should be unlabeled_t 2) The installer should be setting contexts if necessary
https://bugzilla.redhat.com/attachment.cgi?id=1090403&action=diff#a/policy-f22-base.patch.orig_sec2 RHEL base policy is missing that patch from upstream. ... +fs_use_task nsfs gen_context(system_u:object_r:fs_t,s0); ...
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2017:1861