Project

General

Profile

Actions

Bug #40743

closed

"SELinux denials found" in ceph-deploy/nautilus

Added by Yuri Weinstein almost 5 years ago. Updated about 3 years ago.

Status:
Resolved
Priority:
Urgent
Assignee:
Category:
-
Target version:
-
% Done:

0%

Source:
Q/A
Tags:
Backport:
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

Run: http://pulpito.ceph.com/sage-2019-07-11_16:58:04-ceph-deploy-master-distro-basic-mira/
Jobs: all
Logs: http://qa-proxy.ceph.com/teuthology/sage-2019-07-11_16:58:04-ceph-deploy-master-distro-basic-mira/4110688/teuthology.log

SELinux denials found on ubuntu@mira111.front.sepia.ceph.com: ['type=AVC
msg=audit(1562873206.107:6783): avc: denied { getattr } for pid=27073
comm="fn_anonymous" path="/run/udev/data/b8:16" dev="tmpfs" ino=171147
scontext=system_u:system_r:ceph_t:s0
tcontext=system_u:object_r:udev_var_run_t:s0 tclass=file permissive=1',
'type=AVC msg=audit(1562873121.637:6464): avc: denied { getattr } for
pid=25719 comm="ms_dispatch" path="/proc/kcore" dev="proc" ino=4026532068
scontext=system_u:system_r:ceph_t:s0
tcontext=system_u:object_r:proc_kcore_t:s0 tclass=file permissive=1',
'type=AVC msg=audit(1562873206.107:6782): avc: denied { read } for
pid=27073 comm="fn_anonymous" name="b8:16" dev="tmpfs" ino=171147
scontext=system_u:system_r:ceph_t:s0
tcontext=system_u:object_r:udev_var_run_t:s0 tclass=file permissive=1',
'type=AVC msg=audit(1562873220.884:6841): avc: denied { open } for
pid=27750 comm="fn_anonymous" path="/run/udev/data/b8:48" dev="tmpfs" 
ino=169443 scontext=system_u:system_r:ceph_t:s0
tcontext=system_u:object_r:udev_var_run_t:s0 tclass=file permissive=1',
'type=AVC msg=audit(1562873132.862:6512): avc: denied { getattr } for
pid=25719 comm="ms_dispatch" path="/proc/kcore" dev="proc" ino=4026532068
scontext=system_u:system_r:ceph_t:s0
tcontext=system_u:object_r:proc_kcore_t:s0 tclass=file permissive=1',
'type=AVC msg=audit(1562873220.884:6841): avc: denied { read } for
pid=27750 comm="fn_anonymous" name="b8:48" dev="tmpfs" ino=169443
scontext=system_u:system_r:ceph_t:s0
tcontext=system_u:object_r:udev_var_run_t:s0 tclass=file permissive=1',
'type=AVC msg=audit(1562873220.885:6842): avc: denied { getattr } for
pid=27750 comm="fn_anonymous" path="/run/udev/data/b8:48" dev="tmpfs" 
ino=169443 scontext=system_u:system_r:ceph_t:s0
tcontext=system_u:object_r:udev_var_run_t:s0 tclass=file permissive=1',
'type=AVC msg=audit(1562873206.107:6782): avc: denied { open } for
pid=27073 comm="fn_anonymous" path="/run/udev/data/b8:16" dev="tmpfs" 
ino=171147 scontext=system_u:system_r:ceph_t:s0
tcontext=system_u:object_r:udev_var_run_t:s0 tclass=file permissive=1']

Related issues 2 (0 open2 closed)

Related to Ceph - Bug #43064: "SELinux denials found" in ceph-deploy Resolved

Actions
Related to Ceph - Bug #44196: selinux setsched denials for 'fn_anonymous'Resolved

Actions
Actions

Also available in: Atom PDF