Bug 1467601 - SELINUX_ERR during creating oracle instance in Docker
SELINUX_ERR during creating oracle instance in Docker
Status: NEW
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: container-selinux (Show other bugs)
7.4
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: Lokesh Mandvekar
atomic-bugs@redhat.com
: Extras
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2017-07-04 06:24 EDT by Pavel Studeník
Modified: 2017-07-04 07:30 EDT (History)
6 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Pavel Studeník 2017-07-04 06:24:14 EDT
Description of problem:
I am not sure that it is problem of RHEL or problem of Oracle, but when I try to create oracle instance in Docker I receive following AVC message in audit.log

type=PROCTITLE msg=audit(1499101476.902:129): proctitle=2F746D702F4F7261496E7374616C6C323031372D30372D30335F30352D30342D3135504D2F6A646B2F6A72652F62696E2F6A617661002D446F7261636C652E696E7374616C6C65722E6C6962726172795F6C6F633D2F746D702F4F7261496E7374616C6C323031372D30372D30335F30352D30342D3135504D2F6F75692F6C69
type=SYSCALL msg=audit(1499101476.902:129): arch=c000003e syscall=2 per=400000 success=yes exit=6 a0=7f1ebcdb72e0 a1=80000 a2=10000 a3=8 items=0 ppid=4255 pid=4436 auid=4294967295 uid=54321 gid=54321 euid=54321 suid=54321 fsuid=54321 egid=54321 sgid=54321 fsgid=54321 tty=(none) ses=4294967295 comm="java" exe="/tmp/OraInstall2017-07-03_05-04-15PM/jdk/jre/bin/java" subj=system_u:system_r:svirt_lxc_net_t:s0:c666,c919 key=(null)
type=SELINUX_ERR msg=audit(1499101476.902:129): op=security_compute_av reason=bounds scontext=system_u:system_r:svirt_lxc_net_t:s0:c666,c919 tcontext=system_u:object_r:cpu_online_t:s0 tclass=file perms=entrypoint
Fail: AVC messages found.

Version-Release number of selected component (if applicable):
selinux-policy-3.13.1-165.el7.noarch
redhat-release-server-7.4-18.el7.x86_64

How reproducible:
always

Steps to Reproduce:
1. Install oracle in docker by instructions from https://github.com/oracle/docker-images/tree/master/OracleDatabase

Actual results:
same similar AVC messages in audit log

Expected results:
No AVC mesage
Comment 3 Lukas Vrabec 2017-07-04 07:30:41 EDT
Moving to proper component.

Note You need to log in before you can comment on or make changes to this bug.