This service will be undergoing maintenance at 00:00 UTC, 2017-10-23 It is expected to last about 30 minutes
Bug 977477 - AVC denials when using openvswitch logrotate
AVC denials when using openvswitch logrotate
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: selinux-policy (Show other bugs)
6.5
All Linux
urgent Severity urgent
: rc
: ---
Assigned To: Miroslav Grepl
Milos Malik
: ZStream
Depends On: 977415
Blocks:
  Show dependency treegraph
 
Reported: 2013-06-24 12:12 EDT by Ludek Smid
Modified: 2016-04-26 12:19 EDT (History)
8 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Previously, the logrotate daemon rotated logs and tried to update the process ID (PID) in the "/var/run/openvswitch/ovs-vswitchd.pid" configuration, which caused AVC denials. Usually, the logrotate script sends a SIGHUP to a daemon to order it to reopen log files after they were rotated. This update revises the openvswitch policy, and AVC denials no longer occur in the described scenario.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-06-27 14:06:42 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Ludek Smid 2013-06-24 12:12:22 EDT
This bug has been copied from bug #977415 and has been proposed
to be backported to 6.4 z-stream (EUS).
Comment 8 Miroslav Grepl 2013-06-25 07:05:39 EDT
There are builds for testing

https://brewweb.devel.redhat.com/taskinfo?taskID=5938843

on RHEL6.4.z
Comment 9 Milos Malik 2013-06-26 06:03:06 EDT
The reproducer:
# service ntpd stop
* modify following lines in /etc/anacrontab
  RANDOM_DELAY=1
  1       1       cron.daily              nice run-parts /etc/cron.daily
# service auditd stop
# rm -f /var/log/audit/audit.log
# service auditd start
# rm -f /var/log/openvswitch/*
# service openvswitch restart
# rm -f /var/spool/anacron/cron.daily
# killall anacron
* modify following lines in /var/lib/logrotate.status
  "/var/log/openvswitch/ovsdb-server.log" 2013-6-06
  "/var/log/openvswitch/ovs-vswitchd.log" 2013-6-06
# date 06260300
# tail -f /var/log/cron
(wait 2 minutes)
# ausearch -m avc -m selinux_err -i
Comment 14 errata-xmlrpc 2013-06-27 14:06:42 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2013-1000.html

Note You need to log in before you can comment on or make changes to this bug.