Project

General

Profile

Actions

Bug #9407

closed

memcached plugin not working with selinux enabled

Added by Gerwin Krist almost 10 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Plugins
Target version:
Difficulty:
easy
Triaged:
Fixed in Releases:
Found in Releases:

Description

The memcached plugin is not working because passenger is not allowed to connect memcache_port_t

Reproduce:
  • Just install the ruby193-rubygem-foreman_memcache package and configure it to localhost
  • login on Foreman
Result:
  • In production log: DalliError: No server available
  • selinux logs: ruby system_u:system_r:passenger_t:s0 42 tcp_socket name_connect system_u:object_r:memcache_port_t:s0 denied 16180

Solutions

  1. setsebool -P passenger_can_connect_all=on (personally my last resort solution)
  2. Create a selinux module (See below)
module passenger_can_connect_memcache 1.0;

require {
        type passenger_t;
        type memcache_port_t;
        class tcp_socket name_connect;
}

#============= passenger_t ==============

#!!!! This avc can be allowed using the boolean 'passenger_can_connect_all'
allow passenger_t memcache_port_t:tcp_socket name_connect;

Related issues 1 (0 open1 closed)

Related to SELinux - Bug #9772: selinux should enable memcache pluginDuplicate03/15/2015Actions
Actions #1

Updated by Dominic Cleal almost 10 years ago

  • Project changed from Foreman to SELinux
  • Category changed from 56 to Plugins
Actions #2

Updated by The Foreman Bot almost 7 years ago

  • Status changed from New to Ready For Testing
  • Assignee set to Sean O'Keeffe
  • Pull request https://github.com/theforeman/foreman-selinux/pull/76 added
Actions #3

Updated by Anonymous almost 7 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100
Actions #4

Updated by Lukas Zapletal over 6 years ago

  • Translation missing: en.field_release set to 330
Actions #5

Updated by Lukas Zapletal over 6 years ago

  • Related to Bug #9772: selinux should enable memcache plugin added
Actions #6

Updated by Anonymous over 6 years ago

  • Target version deleted (1.18.0)
Actions

Also available in: Atom PDF