Project

General

Profile

Actions

Bug #44216

closed

Nautilus: selinux denials SELinuxError for ceph_mgr on httpd

Added by Yuri Weinstein about 4 years ago. Updated about 4 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
-
Target version:
-
% Done:

0%

Source:
Q/A
Tags:
Backport:
mimic, luminous
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
ceph-ansible, ceph-deploy
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

Run: http://pulpito.ceph.com/yuriw-2020-02-18_16:25:00-ceph-deploy-nautilus-distro-basic-mira/
Jobs: '4778014', '4778022', '4778034', '4778018', '4778062', '4778042', '4778044', '4778010', '4778026', '4778046', '4778054', '4778030', '4778038', '4778066'
Logs: http://qa-proxy.ceph.com/teuthology/yuriw-2020-02-18_16:25:00-ceph-deploy-nautilus-distro-basic-mira/4778010/teuthology.log

2020-02-18T18:14:45.008 INFO:teuthology.orchestra.run.mira084.stdout:type=AVC msg=audit(1582049526.898:5431): avc:  denied  { search } for  pid=2310 comm="ceph-mgr" name="httpd" dev="sda1" ino=82020 scontext=system_u:system_r:ceph_t:s0 tcontext=system_u:object_r:httpd_config_t:s0 tclass=dir permissive=1
2020-02-18T18:14:45.025 DEBUG:teuthology.task.selinux:ubuntu@mira084.front.sepia.ceph.com has 1 denials
2020-02-18T18:14:45.026 ERROR:teuthology.run_tasks:Manager failed: selinux
Traceback (most recent call last):
  File "/home/teuthworker/src/git.ceph.com_git_teuthology_master/teuthology/run_tasks.py", line 159, in run_tasks
    suppress = manager.__exit__(*exc_info)
  File "/home/teuthworker/src/git.ceph.com_git_teuthology_master/teuthology/task/__init__.py", line 136, in __exit__
    self.teardown()
  File "/home/teuthworker/src/git.ceph.com_git_teuthology_master/teuthology/task/selinux.py", line 158, in teardown
    self.get_new_denials()
  File "/home/teuthworker/src/git.ceph.com_git_teuthology_master/teuthology/task/selinux.py", line 208, in get_new_denials
    denials=new_denials[remote.name])
SELinuxError: SELinux denials found on ubuntu@mira107.front.sepia.ceph.com: ['type=AVC msg=audit(1582049398.726:5723): avc:  denied  { getattr } for  pid=3862 

Related issues 3 (1 open2 closed)

Related to devops - Bug #24220: luminous: selinux denials from ceph-osd and ms_dispatch/httpdNewBoris Ranto

Actions
Copied to Ceph - Backport #44983: mimic: Nautilus: selinux denials SELinuxError for ceph_mgr on httpdResolvedBrad HubbardActions
Copied to Ceph - Backport #44984: luminous: Nautilus: selinux denials SELinuxError for ceph_mgr on httpdResolvedBrad HubbardActions
Actions

Also available in: Atom PDF