Bug 977477 - AVC denials when using openvswitch logrotate
AVC denials when using openvswitch logrotate
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: selinux-policy (Show other bugs)
All Linux
urgent Severity urgent
: rc
: ---
Assigned To: Miroslav Grepl
Milos Malik
: ZStream
Depends On: 977415
  Show dependency treegraph
Reported: 2013-06-24 12:12 EDT by Ludek Smid
Modified: 2016-04-26 12:19 EDT (History)
8 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Previously, the logrotate daemon rotated logs and tried to update the process ID (PID) in the "/var/run/openvswitch/ovs-vswitchd.pid" configuration, which caused AVC denials. Usually, the logrotate script sends a SIGHUP to a daemon to order it to reopen log files after they were rotated. This update revises the openvswitch policy, and AVC denials no longer occur in the described scenario.
Story Points: ---
Clone Of:
Last Closed: 2013-06-27 14:06:42 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2013:1000 normal SHIPPED_LIVE selinux-policy bug fix update 2013-06-27 18:05:25 EDT

  None (edit)
Description Ludek Smid 2013-06-24 12:12:22 EDT
This bug has been copied from bug #977415 and has been proposed
to be backported to 6.4 z-stream (EUS).
Comment 8 Miroslav Grepl 2013-06-25 07:05:39 EDT
There are builds for testing


on RHEL6.4.z
Comment 9 Milos Malik 2013-06-26 06:03:06 EDT
The reproducer:
# service ntpd stop
* modify following lines in /etc/anacrontab
  1       1       cron.daily              nice run-parts /etc/cron.daily
# service auditd stop
# rm -f /var/log/audit/audit.log
# service auditd start
# rm -f /var/log/openvswitch/*
# service openvswitch restart
# rm -f /var/spool/anacron/cron.daily
# killall anacron
* modify following lines in /var/lib/logrotate.status
  "/var/log/openvswitch/ovsdb-server.log" 2013-6-06
  "/var/log/openvswitch/ovs-vswitchd.log" 2013-6-06
# date 06260300
# tail -f /var/log/cron
(wait 2 minutes)
# ausearch -m avc -m selinux_err -i
Comment 14 errata-xmlrpc 2013-06-27 14:06:42 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.