Project

Profile

Help

Issue #7922

closed

additional AVC denials

Added by bmclaugh over 3 years ago. Updated over 3 years ago.

Status:
CLOSED - NOTABUG
Priority:
Normal
Assignee:
-
Category:
-
Sprint/Milestone:
-
Start date:
Due date:
Estimated time:
Severity:
2. Medium
Version:
Platform Release:
OS:
Triaged:
No
Groomed:
No
Sprint Candidate:
No
Tags:
SELinux
Sprint:
Quarter:

Description

I'm working on a feature for galaxy_ng where collections are imported and sanity tested in a container via podman. This resulted in additional avc denials in the audit log related to podman which need to be accounted for. I've attached a text file with the applicable section of log.


Files

avc-denials.txt (222 KB) avc-denials.txt bmclaugh, 12/04/2020 03:56 PM
Actions #1

Updated by dkliban@redhat.com over 3 years ago

Which Pulp API are you using when these AVC denials are produced?

Actions #2

Updated by bmclaugh over 3 years ago

This occurs when pulp_ansible is processing an uploaded collection [1] when galaxy_importer is configured to run ansible_test via Podman.

[1] https://github.com/pulp/pulp_ansible/blob/master/pulp_ansible/app/tasks/collections.py#L150

Actions #3

Updated by dkliban@redhat.com over 3 years ago

  • Category deleted (Installer - Moved to GitHub issues)
Actions #4

Updated by bmbouter over 3 years ago

I'm not sure Pulp can readily solve this problem because the calls don't occur from code Pulp maintains. Since galaxy_importer is having changes occur that require additional selinux updates, can you all reach out to the SELinux team to extend the policy https://github.com/pulp/pulpcore-selinux to handle those calls also? I'll message some sharing info about the process of how to do that.

Actions #5

Updated by fao89 over 3 years ago

  • Status changed from NEW to CLOSED - NOTABUG

Also available in: Atom PDF