Project

General

Profile

Actions

Bug #40683

closed

selinux allow ceph_t to call sudo

Added by Torben Hørup almost 5 years ago. Updated over 4 years ago.

Status:
Can't reproduce
Priority:
Urgent
Assignee:
-
Category:
-
Target version:
% Done:

0%

Source:
Tags:
Backport:
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

Since device management relies on being able to run smartctl via sudo, ceph-selinux should allow the call to sudo


Related issues 3 (3 open0 closed)

Related to Ceph - Bug #44940: type=AVC msg=audit(1585577327.298:6404): avc: denied { sys_resource } for pid=27385 comm="sudo" capability=24 scontext=system_u:system_r:ceph_t:s0 tcontext=system_u:system_r:ceph_t:s0 tclass=capability permissive=1New

Actions
Related to Ceph - Bug #44942: type=AVC msg=audit(1585577327.422:6424): avc: denied { nlmsg_relay } for pid=27385 comm="sudo" scontext=system_u:system_r:ceph_t:s0 tcontext=system_u:system_r:ceph_t:s0 tclass=netlink_audit_socket permissive=1New

Actions
Related to Ceph - Bug #44944: type=AVC msg=audit(1585577327.422:6421): avc: denied { open } for pid=27385 comm="sudo" path="/run/utmp" dev="tmpfs" ino=1191 scontext=system_u:system_r:ceph_t:s0 tcontext=system_u:object_r:initrc_var_run_t:s0 tclass=file permissive=1New

Actions
Actions

Also available in: Atom PDF