Bug 2000044 - RHVH 4.3.18: AVC denied errors (sendto) in audit.log after register to engine
Summary: RHVH 4.3.18: AVC denied errors (sendto) in audit.log after register to engine
Keywords:
Status: CLOSED DEFERRED
Alias: None
Product: Red Hat Enterprise Virtualization Manager
Classification: Red Hat
Component: redhat-virtualization-host
Version: 4.3.11
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
: ---
Assignee: Sanja Bonic
QA Contact: cshao
URL:
Whiteboard:
Depends On: 1778038
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-09-01 09:24 UTC by cshao
Modified: 2021-09-01 10:25 UTC (History)
14 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of: 1778038
Environment:
Last Closed: 2021-09-01 10:25:24 UTC
oVirt Team: Node
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHV-43345 0 None None None 2021-09-01 09:25:41 UTC

Description cshao 2021-09-01 09:24:42 UTC
+++ This bug was initially created as a clone of Bug #1778038 +++

Description of problem:
RHVH 4.3.18: AVC denied errors (sendto) in audit.log after register to engine

Version-Release number of selected component (if applicable):
RHVH-4.3-20210831.0-RHVH-x86_64-dvd1.iso

How reproducible:
100%

Steps to Reproduce:
1.RHVH-4.3-20210831.0-RHVH-x86_64-dvd1.iso installed successful. selinux in enforcing mode as default.
2. Register RHVH to engine.
3. Login to RHVH and run "grep "avc:  denied" /var/log/audit/audit.log".


Actual results:
# imgbase w 
You are on rhvh-4.3.18.1-0.20210831.0+1

# grep "avc:  denied" /var/log/audit/audit.log
type=AVC msg=audit(1630469193.928:1927): avc:  denied  { sendto } for  pid=1691 comm="chronyd" path="/run/chrony/chronyc.24025.sock" scontext=system_u:system_r:chronyd_t:s0 tcontext=system_u:system_r:virtd_t:s0-s0:c0.c1023 tclass=unix_dgram_socket permissive=0



Expected results:
No AVC error.

Additional info:
No such issue on previous build(redhat-virtualization-host-4.3.17-20210713.0.el7_9).


Note You need to log in before you can comment on or make changes to this bug.