neutron-l3-agent can't be started because of apparmor DENIED
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Neutron Gateway Charm |
New
|
Undecided
|
Unassigned |
Bug Description
This commit introduced apparmor issue.
https:/
But from Yoga, below commit is included and the issue is gone.
https:/
So the same issue will be happening in Wallaby and Xena.
However, still we have potential issue with aa2f05870106d04
If some function calls this, there must be the same issue.
apparmor may include proper profile for this.
###################
After upgrading neutron from Ussuri to Xena(not ovn), the customer's neutron-l3-agent can't be restarted because of below error [1]
This is because vrrp_pcount = linux_utils.
https:/
We may put entry to apparmor profile for /proc
but I also find below commit
https:/
which is not included in Xena, it is removing code using get_process_
get_process_
https:/
https:/
Also, if we backport it. it could be fixed as well.
Could you please give any advice for this issue?
Thanks a lot.
[1]
ERROR neutron Traceback (most recent call last):
ERROR neutron File "/usr/bin/
ERROR neutron sys.exit(main())
ERROR neutron File "/usr/lib/
ERROR neutron l3_agent.main()
ERROR neutron File "/usr/lib/
ERROR neutron server = neutron_
ERROR neutron File "/usr/lib/
ERROR neutron service_obj = cls(host, binary, topic, manager,
ERROR neutron File "/usr/lib/
ERROR neutron self.manager = manager_
ERROR neutron File "/usr/lib/
ERROR neutron super(L3NATAgen
ERROR neutron File "/usr/lib/
ERROR neutron self._check_
ERROR neutron File "/usr/lib/
ERROR neutron vrrp_pcount = linux_utils.
ERROR neutron File "/usr/lib/
ERROR neutron return len([p for p in psutil.
ERROR neutron File "/usr/lib/
ERROR neutron return len([p for p in psutil.
ERROR neutron File "/usr/lib/
ERROR neutron a = set(pids())
ERROR neutron File "/usr/lib/
ERROR neutron ret = sorted(
ERROR neutron File "/usr/lib/
ERROR neutron return [int(x) for x in os.listdir(
ERROR neutron PermissionError: [Errno 13] Permission denied: b'/proc'
tags: | added: sts |
description: | updated |
description: | updated |
description: | updated |
As wallaby also has the same code but it didn't have the same issue, I'm analyzing further.