Re: A question about comprovagt accessing storage nodes

Devchandra L Meetei <[email protected]> Fri, 9 May 2014 21:08:02 +0530
Newsgroups gmane.network.open-pegasus.general
Message-ID <CAKmFMKcJB-WSWmL24VTieOHKDU=kUzMP9SKS8eDvL6vSLyHYEA@mail.gmail.com>
--001a11330a74109eca04f8f96238
Content-Type: text/plain; charset=ISO-8859-1

IMO, It is upto you to decide if comprovagt should access that, which in my
belief is okay if your instrumentation need to access the /dev/dm-7. If is
your code which is trying to use the node.

If it is legitimate to access the /dev/dm-7, then the Selinux policy need
to be updated on your system. or you need to keep Selinux in
permissive/disabled mode
and the pegasus community does not ship any Selinux policy on it's own. It
is upto vendor, Redhat ships it's own and I believe IBM must be doing for
it's product too


On May 9, 2014 12:19 PM, "Sheng SH Liu" <[email protected]> wrote:

>  Hi all:
> we are using cimprovagt and get some error.
> we check the log and see following:
>
> type=AVC msg=audit(1394502919.480:2066713): avc:  denied  { getattr } for
>  pid=32761 comm="cimprovagt" path="/dev/dm-7" dev=devtmpfs ino=31093
> scontext=system_u:system_r:pegasus_t:s0
> tcontext=system_u:object_r:svirt_image_t:s0:c43,c115 tclass=blk_file
> type=SYSCALL msg=audit(1394502919.480:2066713): arch=c000003e syscall=4
> success=no exit=-13 a0=7f72b80186f0 a1=7f72f9a17040 a2=7f72f9a17040 a3=0
> items=0 ppid=19642 pid=32761 auid=4294967295 uid=0 gid=0 euid=0 suid=0
> fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="cimprovagt"
> exe="/usr/sbin/cimprovagt" subj=system_u:system_r:pegasus_t:s0 key=(null)
>
> here /dev/dm-7 is a guest storage nodes.
> Should comprovagt legitimitely be accessing guest storage nodes?
>
> Thanks!
> Best Regards!
>

--001a11330a74109eca04f8f96238
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_quote">IMO, It is upto you to decide i=
f comprovagt should access that, which in my belief is okay if your instrum=
entation need to access the /dev/dm-7. If is your code which is trying to u=
se the node.<br>
<br></div><div class=3D"gmail_quote">If it is legitimate to access the /dev=
/dm-7, then the Selinux policy need to be updated on your system. or you ne=
ed to keep Selinux in permissive/disabled mode<br></div><div class=3D"gmail=
_quote">
and the pegasus community does not ship any Selinux policy on it&#39;s own.=
 It is upto vendor, Redhat ships it&#39;s own and I believe IBM must be doi=
ng for it&#39;s product too<br><br></div><div class=3D"gmail_quote"><br>On =
May 9, 2014 12:19 PM, &quot;Sheng SH Liu&quot; &lt;<a href=3D"mailto:shengl=
[email protected]" target=3D"_blank">[email protected]</a>&gt; wrote:<br type=
=3D"attribution">
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">

<div>
<p><font face=3D"sans-serif">Hi all:</font><br>
<font face=3D"sans-serif">we are using cimprovagt and get some error.</font=
><br>
<font face=3D"sans-serif">we check the log and see following:</font><br>
<br>
<font face=3D"sans-serif">type=3DAVC msg=3Daudit(1394502919.480:2066713): a=
vc: =A0denied =A0{ getattr } for =A0pid=3D32761 comm=3D&quot;cimprovagt&quo=
t; path=3D&quot;/dev/dm-7&quot; dev=3Ddevtmpfs ino=3D31093 scontext=3Dsyste=
m_u:system_r:pegasus_t:s0 tcontext=3Dsystem_u:object_r:svirt_image_t:s0:c43=
,c115 tclass=3Dblk_file</font><br>



<font face=3D"sans-serif">type=3DSYSCALL msg=3Daudit(1394502919.480:2066713=
): arch=3Dc000003e syscall=3D4 success=3Dno exit=3D-13 a0=3D7f72b80186f0 a1=
=3D7f72f9a17040 a2=3D7f72f9a17040 a3=3D0 items=3D0 ppid=3D19642 pid=3D32761=
 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgi=
d=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 comm=3D&quot;cimprovagt&quot;=
 exe=3D&quot;/usr/sbin/cimprovagt&quot; subj=3Dsystem_u:system_r:pegasus_t:=
s0 key=3D(null)</font><br>



<br>
<font face=3D"sans-serif">here /dev/dm-7 is a guest storage nodes.</font><b=
r>
<font face=3D"sans-serif">Should comprovagt legitimitely be accessing guest=
 storage nodes?</font><br>
<br>
<font face=3D"sans-serif">Thanks!<br>
Best Regards!</font></p></div></blockquote></div>
</div>

--001a11330a74109eca04f8f96238--