Project

General

Profile

Actions

Bug #9972

closed

foreman_openscap don't work with SELinux in enforcing mode

Added by Baptiste Agasse about 9 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
Normal
Target version:
-
Difficulty:
Triaged:
No
Fixed in Releases:
Found in Releases:

Description

Katello 2.2 + foreman 1.8RC2 + foreman_openscap (ruby193-rubygem-openscap.noarch 0.4.2-2.el7) on CentOS 7.

foreman didn't start when foreman_openscap plugin is installed with SELinux in enforcing mode (selinux-policy.noarch 3.12.1-153.el7_0.13, katello-selinux.noarch 2.2.1-1.el7, foreman-selinux.noarch 1.8.0-0.1.RC2.el7)

type=AVC msg=audit(1427808795.006:1501): avc:  denied  { execmem } for  pid=825 comm="ruby" scontext=system_u:system_r:passenger_t:s0 tcontext=system_u:system_r:passenger_t:s0 tclass=process
type=SYSCALL msg=audit(1427808795.006:1501): arch=c000003e syscall=10 success=no exit=-13 a0=7ffd5b3ac000 a1=1000 a2=5 a3=7fffb96072f0 items=0 ppid=822 pid=825 auid=4294967295 uid=995 gid=992 euid=995 suid=995 fsuid=995 egid=992 sgid=992 fsgid=992 tty=(none) ses=4294967295 comm="ruby" exe="/opt/rh/ruby193/root/usr/bin/ruby" subj=system_u:system_r:passenger_t:s0 key=(null)
Actions

Also available in: Atom PDF