Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 923426

Summary: openstack-selinux for RHOS 2.1 should depend on selinux-policy >= 3.7.19-195.el6_4.2 from 6.4.z
Product: Red Hat OpenStack Reporter: Lon Hohberger <lhh>
Component: openstack-selinuxAssignee: Lon Hohberger <lhh>
Status: CLOSED ERRATA QA Contact: Ofer Blaut <oblaut>
Severity: medium Docs Contact:
Priority: high    
Version: 2.1Keywords: EasyFix
Target Milestone: snapshot5   
Target Release: 2.1   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: openstack-selinux-0.1.2-10.el6ost Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-04-04 18:04:03 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
Spec file change (one line)
none
Updated fix (two lines)
none
Additional patch: move to el6_4.2 release of selinux-policy none

Description Lon Hohberger 2013-03-19 19:28:07 UTC
Description of problem: SSIA

The updated selinux-policy package includes updates which make quantum operate correctly in an SELinux-enabled environment

Version-Release number of selected component (if applicable): openstack-selinux-0.1.2-8.el6ost

How reproducible:

Steps to Reproduce:
1. Disable 6.4.z
2. Install current Red Hat OpenStack packages
3. Try to run quantum instead of nova
  
Actual results: AVC denials, like:

https://bugzilla.redhat.com/show_bug.cgi?id=915906#c31

Expected results: No AVC denials

Additional info:

This bugzilla is a convenience; resolving it in openstack-selinux prevents an administrator from having to sort out the details of which errata to include when deploying Red Hat OpenStack 2.1

Comment 1 Lon Hohberger 2013-03-19 19:30:52 UTC
Created attachment 712930 [details]
Spec file change (one line)

Comment 3 Lon Hohberger 2013-03-19 19:50:35 UTC
Created attachment 712931 [details]
Updated fix (two lines)

Openstack-selinux also should depend on selinux-policy-targeted if we want to actually resolve this issue.

Comment 5 Lon Hohberger 2013-03-20 13:24:08 UTC
Back to ASSIGNED - need to pick up el6_4.2 since it includes fixes for Red Hat Storage

Comment 6 Lon Hohberger 2013-03-20 13:27:54 UTC
Created attachment 713248 [details]
Additional patch: move to el6_4.2 release of selinux-policy

Comment 7 Ofer Blaut 2013-03-24 11:40:01 UTC
Tested

root@puma40 ~]# rpm -qa | grep  selinux*
selinux-policy-targeted-3.7.19-195.el6_4.3.noarch
libselinux-ruby-2.0.94-5.3.el6.x86_64
selinux-policy-3.7.19-195.el6_4.3.noarch
openstack-selinux-0.1.2-10.el6ost.noarch
libselinux-2.0.94-5.3.el6.x86_64
libselinux-utils-2.0.94-5.3.el6.x86_64



without rhn (only rhel 6.4 & folsom puddle ) packstack will fail

> This system is not registered to Red Hat Subscription Management. You
> can use subscription-manager to register.
> Setting up Install Process
> Resolving Dependencies
> --> Running transaction check
> ---> Package openstack-selinux.noarch 0:0.1.2-10.el6ost will be
> installed
> --> Processing Dependency: selinux-policy-targeted >=
> 3.7.19-195.el6_4.2 for package:
> openstack-selinux-0.1.2-10.el6ost.noarch
> --> Processing Dependency: selinux-policy-base >= 3.7.19-195.el6_4.2
> for package: openstack-selinux-0.1.2-10.el6ost.noarch
> --> Finished Dependency Resolution
> Error: Package: openstack-selinux-0.1.2-10.el6ost.noarch
> (OpenStack-Folsom-Puddle)
>            Requires: selinux-policy-base >= 3.7.19-195.el6_4.2
>            Installed: selinux-policy-targeted-3.7.19-195.el6.noarch
>            (@anaconda-RedHatEnterpriseLinux-201301301459.x86_64/6.4)
>                selinux-policy-base = 3.7.19-195.el6
>            Available: selinux-policy-minimum-3.7.19-195.el6.noarch
>            (rhel-server)
>                selinux-policy-base = 3.7.19-195.el6
>            Available: selinux-policy-mls-3.7.19-195.el6.noarch
>            (rhel-server)
>                selinux-policy-base = 3.7.19-195.el6
> Error: Package: openstack-selinux-0.1.2-10.el6ost.noarch
> (OpenStack-Folsom-Puddle)
>            Requires: selinux-policy-targeted >= 3.7.19-195.el6_4.2
>            Installed: selinux-policy-targeted-3.7.19-195.el6.noarch
>            (@anaconda-RedHatEnterpriseLinux-201301301459.x86_64/6.4

Comment 8 errata-xmlrpc 2013-04-04 18:04:03 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2013-0706.html