Project

General

Profile

Actions

Bug #19408

closed

selinux failures from updatedb

Added by John Spray about 7 years ago. Updated almost 3 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
% Done:

0%

Source:
Tags:
Backport:
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

http://pulpito.ceph.com/jspray-2017-03-29_01:19:13-multimds-wip-jcsp-testing-20170328-testing-basic-smithi/958259

2017-03-29T06:15:37.286 INFO:teuthology.orchestra.run.smithi033.stdout:type=AVC msg=audit(1490766425.203:8435): avc:  denied  { read write } for  pid=16651 comm="updatedb" name="mlocate.db" dev="sda1" ino=26476607 scontext=system_u:system_r:locate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1
2017-03-29T06:15:37.286 INFO:teuthology.orchestra.run.smithi033.stdout:type=AVC msg=audit(1490766425.203:8435): avc:  denied  { open } for  pid=16651 comm="updatedb" path="/var/lib/mlocate/mlocate.db" dev="sda1" ino=26476607 scontext=system_u:system_r:locate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1
2017-03-29T06:15:37.286 INFO:teuthology.orchestra.run.smithi033.stdout:type=AVC msg=audit(1490766425.214:8436): avc:  denied  { lock } for  pid=16651 comm="updatedb" path="/var/lib/mlocate/mlocate.db" dev="sda1" ino=26476607 scontext=system_u:system_r:locate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1
2017-03-29T06:15:37.286 INFO:teuthology.orchestra.run.smithi033.stdout:type=AVC msg=audit(1490766436.331:8437): avc:  denied  { unlink } for  pid=16651 comm="updatedb" name="mlocate.db" dev="sda1" ino=26476607 scontext=system_u:system_r:locate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1
Actions #1

Updated by John Spray about 7 years ago

And perhaps related:
http://pulpito.ceph.com/jspray-2017-03-29_01:15:31-fs-wip-16523-distro-basic-smithi/958099

2017-03-29T03:15:39.115 INFO:teuthology.orchestra.run.smithi004.stdout:type=AVC msg=audit(1490757181.361:281339): avc:  denied  { read } for  pid=24336 comm="logrotate" name="logrotate.status" dev="sda1" ino=27265562 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file
2017-03-29T03:15:39.116 INFO:teuthology.orchestra.run.smithi004.stdout:type=AVC msg=audit(1490757181.361:281339): avc:  denied  { open } for  pid=24336 comm="logrotate" path="/var/lib/logrotate/logrotate.status" dev="sda1" ino=27265562 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file
2017-03-29T03:15:39.116 INFO:teuthology.orchestra.run.smithi004.stdout:type=AVC msg=audit(1490757181.373:281340): avc:  denied  { create } for  pid=24336 comm="logrotate" name="logrotate.status.tmp" scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file
2017-03-29T03:15:39.116 INFO:teuthology.orchestra.run.smithi004.stdout:type=AVC msg=audit(1490757181.373:281340): avc:  denied  { write } for  pid=24336 comm="logrotate" path="/var/lib/logrotate/logrotate.status.tmp" dev="sda1" ino=27265592 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file
2017-03-29T03:15:39.116 INFO:teuthology.orchestra.run.smithi004.stdout:type=AVC msg=audit(1490757181.373:281341): avc:  denied  { setattr } for  pid=24336 comm="logrotate" name="logrotate.status.tmp" dev="sda1" ino=27265592 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file
2017-03-29T03:15:39.116 INFO:teuthology.orchestra.run.smithi004.stdout:type=AVC msg=audit(1490757181.410:281342): avc:  denied  { rename } for  pid=24336 comm="logrotate" name="logrotate.status.tmp" dev="sda1" ino=27265592 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file
2017-03-29T03:15:39.116 INFO:teuthology.orchestra.run.smithi004.stdout:type=AVC msg=audit(1490757181.410:281342): avc:  denied  { unlink } for  pid=24336 comm="logrotate" name="logrotate.status" dev="sda1" ino=27265562 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file
Actions #2

Updated by Sage Weil almost 3 years ago

  • Status changed from New to Closed
Actions

Also available in: Atom PDF