focal iscsiadm and blockdev location is wrongly mention in apparmor profi;le
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Nova Compute Charm |
Fix Released
|
High
|
James Page |
Bug Description
While going the netap integration find out that following locations of binary are wrong for focal.
/usr/sbin/blockdev
/usr/sbin/iscsiadm
/etc/multipath.conf
after adding the following entries attach the iscsi volume and detach iscsi volume works fine.
/usr/
/usr/
/etc/
Otherwise if apparnor profile is enabled the get the following DENIED messages in DMESG
Dec 3 21:03:15 node05 kernel: [21390.228906] audit: type=1400 audit(160702939
[22157.818194] audit: type=1400 audit(160703016
description: | updated |
tags: | added: field high |
Changed in charm-nova-compute: | |
status: | New → Invalid |
tags: | removed: field high |
Changed in charm-nova-compute: | |
milestone: | none → 21.04 |
status: | Fix Committed → Fix Released |
The blockdev and iscsiadm binaries should be accessible under / and /usr locations already:
/{usr/ ,}sbin/ blockdev rix, ,}sbin/ iscsiadm rix,
/{usr/
the apparmor patterns should allow that.
/etc/multipath.conf is not included.