Project

General

Profile

Actions

Bug #6283

closed

Katello ping controller executes init scripts

Added by Dominic Cleal over 10 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
API
Target version:
Difficulty:
medium
Triaged:
Yes
Fixed in Releases:
Found in Releases:

Description

Cloned from https://bugzilla.redhat.com/show_bug.cgi?id=1105085
Model class app/models/katello/ping.rb executes /etc/init.d/katello-jobs. This is security concern.

I am allowing this in our SELinux policy for now, because katello-jobs service will be removed for GA and it will be replaced by dynflow engine. All other services are checked with their API, I expect the same for dynflow so no services are needed to be executed at all.

Please remove this exec for GA once dynflow engine replace katello-jobs. Once this task is done, please raise a BZ on SELinux component to remove the rules.

PM: Please waive this for GA not Beta.


Related issues 2 (0 open2 closed)

Blocks SELinux - Refactor #6284: Remove Passenger/init_exec_script_files policyClosedActions
Blocked by Katello - Refactor #6297: Remove katello-jobsClosedIvan Necas06/19/2014Actions
Actions #1

Updated by Dominic Cleal over 10 years ago

  • Blocks Refactor #6284: Remove Passenger/init_exec_script_files policy added
Actions #2

Updated by Eric Helms over 10 years ago

Actions #3

Updated by Eric Helms over 10 years ago

  • Target version set to 49
  • Difficulty set to medium
  • Triaged set to Yes
Actions #4

Updated by Christine Fouant over 10 years ago

  • Assignee set to Christine Fouant
Actions #5

Updated by Christine Fouant over 10 years ago

  • Status changed from New to Assigned
Actions #6

Updated by Eric Helms over 10 years ago

  • Target version changed from 49 to 54
Actions #7

Updated by Ivan Necas over 10 years ago

  • Assignee changed from Christine Fouant to Ivan Necas
Actions #8

Updated by Eric Helms over 10 years ago

  • Pull request https://github.com/Katello/katello/pull/4564 added
  • Pull request deleted ()
Actions #9

Updated by Eric Helms over 10 years ago

  • Status changed from Assigned to Ready For Testing
Actions #10

Updated by Eric Helms over 10 years ago

  • Target version changed from 54 to 55
Actions #11

Updated by Eric Helms over 10 years ago

  • Translation missing: en.field_release set to 13
Actions #12

Updated by Ivan Necas over 10 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100
Actions

Also available in: Atom PDF