Project

General

Profile

Actions

Bug #16678

closed

selinux polocy related errors in syslog during ceph-selinux package install

Added by Russell Islam almost 8 years ago. Updated over 7 years ago.

Status:
Closed
Priority:
High
Assignee:
Category:
-
Target version:
-
% Done:

0%

Source:
other
Tags:
Backport:
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

I got the following error while installing ceph-selinux.

kernel: SELinux: Permission audit_read in class capability2 not defined in
policy.
kernel: SELinux: Class binder not defined in policy.
kernel: SELinux: the above unknown classes and permissions will be allowed

command to reproduce the error:
/usr/sbin/semodule -i /usr/share/selinux/packages/ceph.pp

Then check the output in syslog.

Info:
These are object classes and av permissions that were introduced in the
newer kernel, but ceph-selinux policy is for the older kernel and thus does
not know these new object classes and av permissions. So they will just be
ignored (allowed). So other than a few warnings it really does not
affect anything or change the behavior of the policy I believe.

But we could just get rid of this warnings.

The issue is in later kernel i.e in may case 4.1.12.

Not reproducible in 3.8 or 3.10 kernel.

Actions

Also available in: Atom PDF