Project

General

Profile

Actions

Bug #44701

closed

ganesha selinux denial

Added by Sage Weil about 4 years ago. Updated about 4 years ago.

Status:
Resolved
Priority:
Urgent
Assignee:
-
Category:
-
Target version:
-
% Done:

0%

Source:
Tags:
Backport:
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

SELinux denials found on ubuntu@smithi003.front.sepia.ceph.com: ['type=AVC msg=audit(1584729832.089:6233): avc: denied { ioctl } for pid=38081 comm="ganesha.nfsd" path="/etc/ganesha/ganesha.conf" dev="dm-0" ino=33595550 ioctlcmd=0x5401 scontext=system_u:system_r:container_t:s0:c383,c519 tcontext=unconfined_u:object_r:ceph_var_lib_t:s0 tclass=file permissive=1', 'type=AVC msg=audit(1584729832.089:6232): avc: denied { read } for pid=38081 comm="ganesha.nfsd" name="ganesha.conf" dev="dm-0" ino=33595550 scontext=system_u:system_r:container_t:s0:c383,c519 tcontext=unconfined_u:object_r:ceph_var_lib_t:s0 tclass=file permissive=1', 'type=AVC msg=audit(1584729832.089:6232): avc: denied { open } for pid=38081 comm="ganesha.nfsd" path="/etc/ganesha/ganesha.conf" dev="dm-0" ino=33595550 scontext=system_u:system_r:container_t:s0:c383,c519 tcontext=unconfined_u:object_r:ceph_var_lib_t:s0 tclass=file permissive=1']

/a/sage-2020-03-20_18:11:52-rados:cephadm-wip-sage4-testing-2020-03-20-1159-distro-basic-smithi/4873473
Actions #1

Updated by Sebastian Wagner about 4 years ago

  • Status changed from New to Resolved
  • Pull request ID set to 34098
Actions

Also available in: Atom PDF