Bug 799498 - Various AVC denial issues with RHUI [RHUI Upgrade]
Summary: Various AVC denial issues with RHUI [RHUI Upgrade]
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Update Infrastructure for Cloud Providers
Classification: Red Hat
Component: Security
Version: 2.0.2
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
: ---
Assignee: James Slagle
QA Contact: Kedar Bidarkar
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2012-03-02 19:37 UTC by Kedar Bidarkar
Modified: 2012-03-12 19:38 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2012-03-12 19:38:43 UTC
Target Upstream Version:


Attachments (Terms of Use)
AVC denial issues (28.58 KB, application/octet-stream)
2012-03-02 19:37 UTC, Kedar Bidarkar
no flags Details
avc denial issues (12.82 KB, application/octet-stream)
2012-03-06 14:17 UTC, Kedar Bidarkar
no flags Details

Description Kedar Bidarkar 2012-03-02 19:37:10 UTC
Created attachment 567148 [details]
AVC denial issues

Description of problem:

Various AVC denial issues found under the log 

/var/log/audit/audit.log

Version-Release number of selected component (if applicable):


How reproducible:
After Upgrade only

Steps to Reproduce:
1.
2.
3.
  
Actual results:


Expected results:


Additional info:

Please find the attached logs.

Comment 1 James Slagle 2012-03-02 20:06:27 UTC
Did you see any errors during the update?

Please do 'rpm -qa > qa.txt' and attach qa.txt to this bugzilla.

Comment 2 James Slagle 2012-03-02 22:27:57 UTC
Actually, I think I know what the issue might be here.  We need to enable selinux *before* doing the update.  There are some steps in the spec file that apply the policy, but they only run if selinux is already enabled.

Going to test this and I'll report back.

Comment 3 James Slagle 2012-03-05 15:09:02 UTC
Nevermind, that doesn't appear to be the issue.  The policy should still be applied because /usr/sbin/selinuxenabled will report selinux as enabled even when you're in permissive mode, which I was.

Comment 4 James Slagle 2012-03-05 21:20:27 UTC
*** Bug 799495 has been marked as a duplicate of this bug. ***

Comment 5 James Slagle 2012-03-05 21:24:43 UTC
These SELinux issues were caused by the migration of files from /etc/pki/content to /etc/pki/pulp/content.  There's actually a migration script that runs as part of pulp-migrate that handles this, but it only works if the config files have already been updated for the new paths.

There was a migration needed to move the pulp-protected-repos file to the new location, and I added that as a %post install script in pulp.spec.  This will be in pulp-0.263-13

I updated the release notes at https://engineering.redhat.com/trac/mgmt-integrated/wiki/cloude/rhui-202-release-notes to account for this requirement.  Please use those release notes when you do the update testing.

I'll move this bug to ON_QA once the new iso build is done and the yum repo at cdn.rcm-qa.redhat.com has been updated with the new pulp packages.

Comment 7 Kedar Bidarkar 2012-03-06 14:17:11 UTC
Created attachment 567959 [details]
avc denial issues

Upgraded with the latest iso and still face AVC denial issues

Comment 8 Kedar Bidarkar 2012-03-06 14:36:20 UTC
s/iso/content from cdn.rcm-qa/

Comment 9 James Slagle 2012-03-06 19:58:15 UTC
after fixing bug #800485 and bug #800614 I don't see the AVC's in the audit log when I restart the pulp-server service or sync a repo.

Can you try going through the upgrade again after today's builds and see if you still see the AVC's?

If you do, please let me know what actions you're doing to trigger them.

Comment 10 Kedar Bidarkar 2012-03-07 13:40:28 UTC
No AVC denial messages observed today from the logs after RHUI upgrade

Comment 11 James Slagle 2012-03-12 19:38:43 UTC
Released in RHUI 2.0.2


Note You need to log in before you can comment on or make changes to this bug.