Project

General

Profile

Actions

Bug #11572

closed

Add support for openscap spool files

Added by Gerwin Krist over 9 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Plugins
Target version:
-
Difficulty:
trivial
Triaged:
No
Fixed in Releases:
Found in Releases:

Description

Foreman-Openscap using /var/spool/foreman-proxy/openscap/ to store uploaded ARF reports. Uploads from client fail because an AVC:

1360. 08/26/2015 13:48:14 ruby system_u:system_r:foreman_proxy_t:s0 2 dir write system_u:object_r:var_spool_t:s0 denied 242934
1361. 08/26/2015 13:48:14 ruby system_u:system_r:foreman_proxy_t:s0 2 dir add_name system_u:object_r:var_spool_t:s0 denied 242934
1362. 08/26/2015 13:48:14 ruby system_u:system_r:foreman_proxy_t:s0 2 file create system_u:object_r:var_spool_t:s0 denied 242934
1363. 08/26/2015 13:48:14 ruby system_u:system_r:foreman_proxy_t:s0 2 file write open system_u:object_r:var_spool_t:s0 denied 242934
1364. 08/26/2015 13:49:02 ruby system_u:system_r:foreman_proxy_t:s0 83 dir create system_u:object_r:var_spool_t:s0 denied 242942

Current type context:
matchpathcon /var/spool/foreman-proxy/openscap
/var/spool/foreman-proxy/openscap system_u:object_r:var_spool_t:s0

Possible solution:
An addon to the foreman-proxy module with:

require {
        type foreman_proxy_t;
        type var_spool_t;
        class dir { write create add_name };
        class file { write create open };
}

#============= foreman_proxy_t ==============
allow foreman_proxy_t var_spool_t:dir { write create add_name };
allow foreman_proxy_t var_spool_t:file { write create open };

or adding a fcontext to the fcontext database.

Actions #1

Updated by Dominic Cleal over 9 years ago

  • Project changed from Foreman to SELinux
  • Category changed from 56 to Plugins
Actions #2

Updated by The Foreman Bot over 6 years ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/theforeman/foreman-selinux/pull/82 added
Actions #3

Updated by Lukas Zapletal over 6 years ago

  • Subject changed from [openscap] default spool directory has wrong type context to Add support for openscap spool files
Actions #4

Updated by Dirk Götz over 6 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100
Actions #5

Updated by Tomer Brisker over 6 years ago

  • Fixed in Releases 1.19.0 added
Actions

Also available in: Atom PDF