[Expired for neutron because there has been no activity for 60 days.]
** Changed in: neutron
Status: Incomplete => Expired
--
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to neutron.
https://bugs.launchpad.net/bugs/1498151
Title:
neutron-server on restart is triggering AVCs on a number of files
Status in neutron:
Expired
Bug description:
using delorian installed via packstack --allinone I noticed that if we
restart neutron-server it generates a number of AVCs for getattr on 87
files
neutron==7.0.0.0b4.dev223
sample of a few entries from /var/log/audit.log from centos 7
type=AVC msg=audit(1442855709.922:10594): avc: denied { getattr } for
pid=16273 comm="neutron-server" path="/usr/bin/hostname" dev="dm-0"
ino=67231056 scontext=system_u:system_r:neutron_t:s0
tcontext=system_u:object_r:hostname_exec_t:s0 tclass=file
type=AVC msg=audit(1442855709.922:10595): avc: denied { getattr } for
pid=16273 comm="neutron-server" path="/usr/bin/fusermount" dev="dm-0"
ino=70253714 scontext=system_u:system_r:neutron_t:s0
tcontext=system_u:object_r:fusermount_exec_t:s0 tclass=file
type=AVC msg=audit(1442855709.922:10596): avc: denied { getattr } for
pid=16273 comm="neutron-server" path="/usr/bin/glance-api" dev="dm-0"
ino=69439463 scontext=system_u:system_r:neutron_t:s0
tcontext=system_u:object_r:glance_api_exec_t:s0 tclass=file
type=AVC msg=audit(1442855709.922:10597): avc: denied { getattr } for
pid=16273 comm="neutron-server" path="/usr/bin/glance-registry" dev="dm-0"
ino=69439474 scontext=system_u:system_r:neutron_t:s0
tcontext=system_u:object_r:glance_registry_exec_t:s0 tclass=file
type=AVC msg=audit(1442855709.923:10598): avc: denied { getattr } for
pid=16273 comm="neutron-server" path="/usr/bin/glance-scrubber" dev="dm-0"
ino=69439476 scontext=system_u:system_r:neutron_t:s0
tcontext=system_u:object_r:glance_scrubber_exec_t:
To manage notifications about this bug go to:
https://bugs.launchpad.net/neutron/+bug/1498151/+subscriptions
--
Mailing list: https://launchpad.net/~yahoo-eng-team
Post to : [email protected]
Unsubscribe : https://launchpad.net/~yahoo-eng-team
More help : https://help.launchpad.net/ListHelp