Project

General

Profile

Actions

Bug #64616

open

selinux denials with centos9.stream

Added by Venky Shankar 3 months ago. Updated 2 months ago.

Status:
Pending Backport
Priority:
Normal
Assignee:
Category:
Testing
Target version:
% Done:

0%

Source:
Tags:
backport_processed
Backport:
quincy,reef,squid
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
fs
Component(FS):
Labels (FS):
qa, qa-failure
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

/a/vshankar-2024-02-26_10:07:12-fs-wip-vshankar-testing-20240226.064629-testing-default-smithi/7573529

SELinux denials found on ubuntu@smithi027.front.sepia.ceph.com: ['type=AVC msg=audit(1708943195.213:199): avc: denied { checkpoint_restore } for pid=1208 comm="agetty" capability=40 scontext=system_u:system_r:getty_t:s0-s0:c0.c1023 tcontext=system_u:system_r:getty_t:s0-s0:c0.c1023 tclass=capability2 permissive=1']

This shows up with fs suite using the testing kernel. The denial is `checkpoint_restore' which I believe is related to checkpointing and restoring a container. We might need to add this to ignorelist in the selinux teuthology task.


Related issues 3 (3 open0 closed)

Copied to CephFS - Backport #64755: squid: selinux denials with centos9.streamIn ProgressVenky ShankarActions
Copied to CephFS - Backport #64756: reef: selinux denials with centos9.streamIn ProgressVenky ShankarActions
Copied to CephFS - Backport #64757: quincy: selinux denials with centos9.streamIn ProgressVenky ShankarActions
Actions

Also available in: Atom PDF