Project

General

Profile

Actions

Bug #15342

closed

"SELinux denials found" in ceph-deploy-jewel-distro-basic-mira

Added by Yuri Weinstein about 8 years ago. Updated about 7 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
% Done:

0%

Source:
Q/A
Tags:
Backport:
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
ceph-deploy
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

Run: http://pulpito.ceph.com/teuthology-2016-03-30_21:13:01-ceph-deploy-jewel-distro-basic-mira/
Jobs: all centos
Logs: http://qa-proxy.ceph.com/teuthology/teuthology-2016-03-30_21:13:01-ceph-deploy-jewel-distro-basic-mira/99943/teuthology.log

SELinuxError: SELinux denials found on ubuntu@mira108.front.sepia.ceph.com: ['type=AVC msg=audit(1459419074.854:4547): avc:  denied  { open } for  pid=16721 comm="safe_timer" path="/proc/loadavg" dev="proc" ino=4026532061 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file', 'type=AVC msg=audit(1459419073.855:4523): avc:  denied  { open } for  pid=16721 comm="safe_timer" path="/proc/loadavg" dev="proc" ino=4026532061 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file', 'type=USER_AVC msg=audit(1459418908.064:3716): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg=\'avc:  denied  { enable } for auid=1000 uid=0 gid=0 cmdline="systemctl enable ceph.target" scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=system_u:system_r:init_t:s0 tclass=service  exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? terminal=?\'', 'type=AVC msg=audit(1459419074.854:4547): avc:  denied  { search } for  pid=16721 comm="safe_timer" name="/" dev="proc" ino=1 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=dir', 'type=AVC msg=audit(1459419075.680:4596): avc:  denied  { read } for  pid=16885 comm="ms_pipe_read" laddr=172.21.8.104 lport=6803 faddr=172.21.5.132 fport=48825 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=tcp_socket', 'type=AVC msg=audit(1459419074.750:4539): avc:  denied  { write } for  pid=15056 comm="ms_pipe_write" laddr=172.21.8.104 lport=6789 faddr=172.21.5.132 fport=56940 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=tcp_socket', 'type=AVC msg=audit(1459419075.680:4595): avc:  denied  { read } for  pid=16884 comm="ms_pipe_read" laddr=172.21.8.104 lport=6802 faddr=172.21.5.132 fport=57266 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=tcp_socket', 'type=AVC msg=audit(1459419077.855:4654): avc:  denied  { read } for  pid=16721 comm="safe_timer" name="loadavg" dev="proc" ino=4026532061 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file', 'type=AVC msg=audit(1459419074.854:4547): avc:  denied  { read } for  pid=16721 comm="safe_timer" name="loadavg" dev="proc" ino=4026532061 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file', 'type=AVC msg=audit(1459419074.749:4538): avc:  denied  { read } for  pid=15055 comm="ms_pipe_read" laddr=172.21.8.104 lport=6789 faddr=172.21.5.132 fport=56940 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=tcp_socket', 'type=AVC msg=audit(1459419075.743:4598): avc:  denied  { read } for  pid=16766 comm="osd_srv_heartbt" name="loadavg" dev="proc" ino=4026532061 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file', 'type=AVC msg=audit(1459419073.855:4523): avc:  denied  { read } for  pid=16721 comm="safe_timer" name="loadavg" dev="proc" ino=4026532061 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file', 'type=AVC msg=audit(1459419074.969:4556): avc:  denied  { read } for  pid=15055 comm="ms_pipe_read" laddr=172.21.8.104 lport=6789 faddr=172.21.5.132 fport=56940 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=tcp_socket', 'type=AVC msg=audit(1459419075.743:4598): avc:  denied  { open } for  pid=16766 comm="osd_srv_heartbt" path="/proc/loadavg" dev="proc" ino=4026532061 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file', 'type=AVC msg=audit(1459419073.855:4523): avc:  denied  { search } for  pid=16721 comm="safe_timer" name="/" dev="proc" ino=1 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=dir', 'type=AVC msg=audit(1459419077.855:4654): avc:  denied  { open } for  pid=16721 comm="safe_timer" path="/proc/loadavg" dev="proc" ino=4026532061 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=file', 'type=AVC msg=audit(1459419075.743:4599): avc:  denied  { getattr } for  pid=16766 comm="osd_srv_heartbt" name="/" dev="dm-1" ino=16 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:fs_t:s0 tclass=filesystem', 'type=AVC msg=audit(1459419075.680:4597): avc:  denied  { write } for  pid=16886 comm="ms_pipe_write" laddr=172.21.8.104 lport=6802 faddr=172.21.5.132 fport=57266 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=tcp_socket', 'type=AVC msg=audit(1459419077.749:4639): avc:  denied  { append } for  pid=15010 comm="log" path=2F7661722F6C6F672F636570682F636570682D6D6F6E2E6D6972613130382E6C6F67202864656C6574656429 dev="sda1" ino=58067000 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file', 'type=AVC msg=audit(1459419073.465:4522): avc:  denied  { append } for  pid=15010 comm="log" path=2F7661722F6C6F672F636570682F636570682D6D6F6E2E6D6972613130382E6C6F67202864656C6574656429 dev="sda1" ino=58067000 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file', 'type=AVC msg=audit(1459419075.743:4598): avc:  denied  { search } for  pid=16766 comm="osd_srv_heartbt" name="/" dev="proc" ino=1 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=dir', 'type=AVC msg=audit(1459419075.743:4599): avc:  denied  { search } for  pid=16766 comm="osd_srv_heartbt" name="lib" dev="sda1" ino=57147394 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:var_lib_t:s0 tclass=dir'
Actions #1

Updated by Greg Farnum about 7 years ago

  • Status changed from New to Closed
Actions

Also available in: Atom PDF