Description of problem: I'm trying to create some instances in the root/InterOp namespace using the cimmof tool. By default only the root, root/cimv2, root/PG_Internal and root/PG_InterOp namespaces are created. Pegasus tries to create the new namespace in the repository by firstly creating a new directory which unfortunately fails. Here's the relevant lines from /var/log/audit/audit.log: type=AVC msg=audit(1170299067.872:189): avc: denied { create } for pid=19121 comm="cimserver" name="root#InterOp" scontext=user_u:system_r:pegasus_t:s0 tcontext=user_u:object_r:pegasus_data_t:s0 tclass=dir type=SYSCALL msg=audit(1170299067.872:189): arch=c0000032 syscall=1055 success=no exit=-13 a0=2000000801abc730 a1=1ff a2=2000000800ba0158 a3=2000000801a53b00 items=0 ppid=1 pid=19121 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) comm="cimserver" exe="/usr/sbin/cimserver" subj=user_u:system_r:pegasus_t:s0 key=(null) My guess is that the tog-pegasus SELinux policy does not allow the creation of directories in /var/lib/Pegasus/repository but I can't figure out the location of the policy source files for the rhel5rcs7 release. Version-Release number of selected component (if applicable): tog-pegasus-2.5.2-4.el5 How reproducible: # cimmof -n root/InterOp < /dev/null Error: CIM_ERR_FAILED: A general error occurred that is not covered by a more specific error code: "cannot create directory: /var/lib/Pegasus/repository/root#InterOp" Steps to Reproduce: 1. 2. 3. Actual results: Expected results: Additional info:
Oh man now that I've typed all that in I understand bug 213809 and it's basically the same thing. I've been working against the latest release candidate snapshot though, not any of the betas or rc1.
Can you please check, if this bug is still present? With tog-pegasus-2.6.1-2.el5, tog-pegasus-devel-2.6.1-2.el5, selinux-policy-2.4.6-88.el5, selinux-policy-targeted-2.4.6-88.el5 it works for me. This versions (or higher version of selinux-policy maybe) are in latest RHEL5.1 beta. Bug #213809 is there fixed too. Thank you in advance.
Hi - the problem seems fixed now. Thanks!