Project

General

Profile

Actions

Bug #32023

closed

Denial when installing on CentOS 8 Stream

Added by Lukas Zapletal almost 3 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
Normal
Category:
General Foreman
Target version:
Difficulty:
Triaged:
Yes
Fixed in Releases:
Found in Releases:

Description

There is the following denial on CO8Stream:

type=AVC msg=audit(1614873402.173:1566): avc: denied { getattr } for pid=30429 comm="httpd" path="/etc/puppetlabs/puppet/ssl/certs/centos8-stream-foreman-nightly.wisse.example.com.pem" dev="vda1" ino=33568393 scontext=system_u:system_r:httpd_t:s0 tcontext=unconfined_u:object_r:puppet_etc_t:s0 tclass=file permissive=0

This drills down to a problem with a different rule - ipa-selinux don't need to be installed by default and thus relevant macro will not expand correctly.

Actions #1

Updated by The Foreman Bot almost 3 years ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/theforeman/foreman-selinux/pull/125 added
Actions #2

Updated by The Foreman Bot almost 3 years ago

  • Fixed in Releases 2.5.0 added
Actions #3

Updated by Ewoud Kohl van Wijngaarden almost 3 years ago

  • Target version set to 2.4.0

I think this is a good candidate for a cherry pick to 2.4 which would likely be the first version to support Stream.

Actions #4

Updated by Anonymous almost 3 years ago

  • Status changed from Ready For Testing to Closed
Actions #5

Updated by Tomer Brisker almost 3 years ago

  • Fixed in Releases 2.4.0 added
  • Fixed in Releases deleted (2.5.0)
Actions #6

Updated by Tomer Brisker over 2 years ago

  • Target version changed from 2.4.0 to 2.3.5
Actions #7

Updated by Tomer Brisker over 2 years ago

  • Fixed in Releases 2.3.5 added
Actions

Also available in: Atom PDF