Project

General

Profile

Bug #6283

Katello ping controller executes init scripts

Added by Dominic Cleal about 5 years ago. Updated 12 months ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
API
Target version:
Difficulty:
medium
Triaged:
Yes
Bugzilla link:
Team Backlog:
Fixed in Releases:
Found in Releases:

Description

Cloned from https://bugzilla.redhat.com/show_bug.cgi?id=1105085
Model class app/models/katello/ping.rb executes /etc/init.d/katello-jobs. This is security concern.

I am allowing this in our SELinux policy for now, because katello-jobs service will be removed for GA and it will be replaced by dynflow engine. All other services are checked with their API, I expect the same for dynflow so no services are needed to be executed at all.

Please remove this exec for GA once dynflow engine replace katello-jobs. Once this task is done, please raise a BZ on SELinux component to remove the rules.

PM: Please waive this for GA not Beta.


Related issues

Blocks SELinux - Refactor #6284: Remove Passenger/init_exec_script_files policyNew
Blocked by Katello - Refactor #6297: Remove katello-jobsClosed2014-06-19

Associated revisions

Revision b58a527e (diff)
Added by Ivan Necas almost 5 years ago

Fixes #6283 - Use the Dynflow API to find out if the foreman_tasks is running

Instead of spawning process to find out the katello jobs was running

History

#1 Updated by Dominic Cleal about 5 years ago

  • Blocks Refactor #6284: Remove Passenger/init_exec_script_files policy added

#2 Updated by Eric Helms almost 5 years ago

#3 Updated by Eric Helms almost 5 years ago

  • Target version set to 49
  • Difficulty set to medium
  • Triaged set to Yes

#4 Updated by Christine Fouant almost 5 years ago

  • Assignee set to Christine Fouant

#5 Updated by Christine Fouant almost 5 years ago

  • Status changed from New to Assigned

#6 Updated by Eric Helms almost 5 years ago

  • Target version changed from 49 to 54

#7 Updated by Ivan Necas almost 5 years ago

  • Assignee changed from Christine Fouant to Ivan Necas

#8 Updated by Eric Helms almost 5 years ago

  • Pull request https://github.com/Katello/katello/pull/4564 added
  • Pull request deleted ()

#9 Updated by Eric Helms almost 5 years ago

  • Status changed from Assigned to Ready For Testing

#10 Updated by Eric Helms almost 5 years ago

  • Target version changed from 54 to 55

#11 Updated by Eric Helms almost 5 years ago

  • Legacy Backlogs Release (now unused) set to 13

#12 Updated by Ivan Necas almost 5 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100

Also available in: Atom PDF