Project

General

Profile

Actions

Bug #43703

closed

selinux vs logrotate

Added by Sage Weil over 4 years ago. Updated about 4 years ago.

Status:
Resolved
Priority:
Urgent
Assignee:
Category:
cephadm
Target version:
% Done:

0%

Source:
Tags:
Backport:
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

SELinux denials found on ubuntu@smithi083.front.sepia.ceph.com: ['type=AVC msg=audit(1579471681.869:7055): avc: denied { getattr } for pid=116238 comm="logrotate" path="/var/log/ceph/f6fde62a-3b05-11ea-99db-001a4aab830c/ceph-mgr.y.log" dev="sda1" ino=395962 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:container_file_t:s0 tclass=file permissive=1', 'type=AVC msg=audit(1579471681.868:7054): avc: denied { read } for pid=116238 comm="logrotate" name="f6fde62a-3b05-11ea-99db-001a4aab830c" dev="sda1" ino=394431 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:container_file_t:s0 tclass=dir permissive=1']

see bz https://bugzilla.redhat.com/show_bug.cgi?id=1775303

Actions

Also available in: Atom PDF