Bug 1546897 - RabbitMQ Selinux Allow dir create in tmp_t
Summary: RabbitMQ Selinux Allow dir create in tmp_t
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: selinux-policy
Version: 7.4
Hardware: All
OS: Linux
unspecified
unspecified
Target Milestone: rc
: ---
Assignee: Lukas Vrabec
QA Contact: Milos Malik
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-02-19 23:21 UTC by Erinn Looney-Triggs
Modified: 2018-10-30 10:03 UTC (History)
5 users (show)

Fixed In Version: selinux-policy-3.13.1-203.el7
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-10-30 10:02:53 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2018:3111 None None None 2018-10-30 10:03:21 UTC

Description Erinn Looney-Triggs 2018-02-19 23:21:55 UTC
Description of problem:
Short version, the following needs to be added to SELinux policy:
allow rabbitmq_t tmp_t:dir create;


Version-Release number of selected component (if applicable):

selinux-policy-3.13.1-166.el7_4.7.noarch
rabbitmq-server-3.3.5-34.el7.noarch

How reproducible:
Attempt to trace a message sent to and out of the queue via the web interface (there may be another way to trigger this but web UI is where we ran across this). 


Actual results:
Failure due to the above SELinux permission lacking

Expected results:
Working

Additional info:
Ensure this is in fedora/upstream as well, thanks.

Comment 5 errata-xmlrpc 2018-10-30 10:02:53 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:3111


Note You need to log in before you can comment on or make changes to this bug.