Project

General

Profile

Actions

Bug #23843

closed

avc: denied { block_suspend } for pid=34841 comm="msgr-worker-1"

Added by Vasu Kulkarni almost 6 years ago. Updated almost 6 years ago.

Status:
Duplicate
Priority:
High
Assignee:
Category:
-
Target version:
-
% Done:

0%

Source:
Tags:
Backport:
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

http://pulpito.ceph.com/teuthology-2018-04-23_03:59:02-ceph-deploy-master-distro-basic-mira/2429455/


SELinux denials found on ubuntu@mira071.front.sepia.ceph.com: ['type=AVC msg=audit(1524457202.160:5420): avc: denied { read open } for pid=34774 comm="sh" path="/usr/sbin/ldconfig" dev="sda1" ino=685 scontext=system_u:system_r:ceph_t:s0 tcontext=system_u:object_r:ldconfig_exec_t:s0 tclass=file', 'type=AVC msg=audit(1524457202.982:5425): avc: denied { block_suspend } for pid=34841 comm="msgr-worker-1" capability=36 scontext=system_u:system_r:ceph_t:s0 tcontext=system_u:system_r:ceph_t:s0 tclass=capability2', 'type=AVC msg=audit(1524457160.719:5391): avc: denied { block_suspend } for pid=34304 comm="msgr-worker-1" capability=36 scontext=system_u:system_r:ceph_t:s0 tcontext=system_u:system_r:ceph_t:s0 tclass=capability2', 'type=AVC msg=audit(1524457202.160:5420): avc: denied { execute } for pid=34774 comm="sh" name="ldconfig" dev="sda1" ino=685 scontext=system_u:system_r:ceph_t:s0 tcontext=system_u:object_r:ldconfig_exec_t:s0 tclass=file', 'type=AVC msg=audit(1524457201.677:5413): avc: denied { block_suspend } for pid=34700 comm="msgr-worker-2" capability=36 scontext=system_u:system_r:ceph_t:s0 tcontext=system_u:system_r:ceph_t:s0 tclass=capability2', 'type=AVC msg=audit(1524457202.160:5420): avc: denied { execute_no_trans } for pid=34774 comm="sh" path="/usr/sbin/ldconfig" dev="sda1" ino=685 scontext=system_u:system_r:ceph_t:s0 tcontext=system_u:object_r:ldconfig_exec_t:s0 tclass=file'] 


Related issues 1 (0 open1 closed)

Is duplicate of Ceph - Bug #22302: selinux denials with ceph-deploy/ceph-volume lvm deviceResolvedBoris Ranto12/02/2017

Actions
Actions #1

Updated by Boris Ranto almost 6 years ago

This is also fixed by the latest SELinux update:

https://github.com/ceph/ceph/pull/20118

Actions #2

Updated by Boris Ranto almost 6 years ago

  • Status changed from New to Resolved

The PR was merged.

Actions #3

Updated by Ken Dreyer almost 6 years ago

  • Status changed from Resolved to Duplicate
Actions #4

Updated by Ken Dreyer almost 6 years ago

  • Related to Bug #22302: selinux denials with ceph-deploy/ceph-volume lvm device added
Actions #5

Updated by Ken Dreyer almost 6 years ago

  • Related to deleted (Bug #22302: selinux denials with ceph-deploy/ceph-volume lvm device)
Actions #6

Updated by Ken Dreyer almost 6 years ago

  • Is duplicate of Bug #22302: selinux denials with ceph-deploy/ceph-volume lvm device added
Actions

Also available in: Atom PDF