selinux denial due to /var/lib/rabbitmq changed from being a dir into a link

Bug #1373145 reported by Giulio Fidente
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
tripleo
Fix Released
Medium
Giulio Fidente

Bug Description

audit log on fedora20 is logging an selinux AVC denial due to TripleO changing the /var/lib/rabbitmq path from being a dir into a link to /mnt/state/var/lib/rabbitmq

avc: denied { read } for pid=11188 comm="sh" name="rabbitmq" dev="sda3" ino=74002 scontext=system_u:system_r:rabbitmq_beam_t:s0 tcontext=unconfined_u:object_r:rabbitmq_var_lib_t:s0 tclass=lnk_file permissive=1

a job logging such a denial: http://logs.openstack.org/95/122095/1/check-tripleo/check-tripleo-novabm-overcloud-f20-nonha/a10fbed/logs/overcloud-controller0_logs/audit.txt.gz

Tags: selinux
Changed in tripleo:
assignee: nobody → Giulio Fidente (gfidente)
description: updated
tags: added: selinux
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to tripleo-image-elements (master)

Fix proposed to branch: master
Review: https://review.openstack.org/123591

Changed in tripleo:
status: New → In Progress
Changed in tripleo:
importance: Undecided → Medium
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to tripleo-image-elements (master)

Reviewed: https://review.openstack.org/123591
Committed: https://git.openstack.org/cgit/openstack/tripleo-image-elements/commit/?id=72d00f0d76c02942a356dad9c209db6adf1b6797
Submitter: Jenkins
Branch: master

commit 72d00f0d76c02942a356dad9c209db6adf1b6797
Author: Giulio Fidente <email address hidden>
Date: Wed Sep 24 00:12:01 2014 +0200

    Fix selinux permissions for rabbitmq_beam_t on /var/lib/rabbitmq

    Change-Id: Ib43823461e6be03ad6603d4c7cea240b90953b00
    Closes-Bug: 1373145

Changed in tripleo:
status: In Progress → Fix Committed
Jay Dobies (jdob)
Changed in tripleo:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.