pcp
[Top] [All Lists]

[Bug 1381127] PCP SELinux issues

To: pcp@xxxxxxxxxxx
Subject: [Bug 1381127] PCP SELinux issues
From: bugzilla@xxxxxxxxxx
Date: Tue, 04 Oct 2016 05:45:19 +0000
Auto-submitted: auto-generated
Delivered-to: pcp@xxxxxxxxxxx
In-reply-to: <bug-1381127-355098@xxxxxxxxxxxxxxxxxxx>
References: <bug-1381127-355098@xxxxxxxxxxxxxxxxxxx>
https://bugzilla.redhat.com/show_bug.cgi?id=1381127

Nathan Scott <nathans@xxxxxxxxxx> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |dominick.grift@xxxxxxxxx,
                   |                            |dwalsh@xxxxxxxxxx,
                   |                            |lvrabec@xxxxxxxxxx,
                   |                            |mgrepl@xxxxxxxxxx,
                   |                            |plautrba@xxxxxxxxxx,
                   |                            |pmoore@xxxxxxxxxx
          Component|pcp                         |selinux-policy
           Assignee|nathans@xxxxxxxxxx          |lvrabec@xxxxxxxxxx



--- Comment #1 from Nathan Scott <nathans@xxxxxxxxxx> ---
Auditing Marko's attached log shows there's a few categories of failures.

The first lot are wierd things like PCP commands or shell scripts not being
able to run system utilities like chown, kill, hostname, which, etc.  I'm
unsure what to do with those, will leave for SELinux folk to advise.

Then there's a bunch of new ones, due to things we've changed in PCP I think. 
We added a libvirt PMDA to PCP, and there's a few attempted accesses to libvirt
config files that are failing.  We've changed some internal PCP shell
functions, and one of them is accessing tmp files incorrectly (this one I've
fixed now & will merged into upstream PCP shortly).

Then there's some persistent issues - things link /var/log/pcp/pmcd/pmcd.log
not being accessible when it should be, likewise the /var/lib/pcp/pmns/root
file.  These look like selinux-policy issues once more, so will leave for
SElinux folk to advise us further there too.

-- 
You are receiving this mail because:
You are on the CC list for the bug.
Unsubscribe from this bug 
https://bugzilla.redhat.com/token.cgi?t=jSQYR8kxm7&a=cc_unsubscribe
<Prev in Thread] Current Thread [Next in Thread>