Thursday, 2018-08-30

*** olivierb_ has joined #openstack-dib07:47
*** hwoarang has joined #openstack-dib07:49
olivierb_ianw yolanda, could you please add your comments to https://review.openstack.org/#/c/559485 ? Many thanks08:32
ianwolivierb_: i was discussing something that looks extremely similar with eandersson today08:39
ianware you running in a docker container?08:40
olivierb_ianw not at all, either VirtualBox VM either baremetal machine08:40
olivierb_both having same behaviour08:40
olivierb_do you mean that the CI jobs are running in containers ?08:41
ianwno they are not08:43
ianwhttp://paste.openstack.org/show/729091/08:45
ianwwas his suggestion.  this wsa inside a docker container, where the selinux sysfs directory was there, but not populated08:45
olivierb_this is what I thought but just wanted to be sure08:45
olivierb_both VM and baremetal are running Ubuntu xenial minimal set of packages without selinux installed/configured08:47
olivierb_only the following packages:08:47
olivierb_libselinux1:amd64 libsemanage-common libsemanage1:amd64 libsepol1:amd64 python-selinux08:47
olivierb_tried to diff the running processes in CI machine as well as list of packages to see diffs but nothing showed up real clear08:48
olivierb_https://review.openstack.org/59136608:48
ianwthe other thing was https://github.com/fedora-selinux/selinux/blob/master/policycoreutils/setfiles/setfiles.c#L11208:49
olivierb_yes, indeed, reading this code too, I was thinking that may be under some condition I do not know about it may have the mass_relabel set off therefore not going into open call which most probably lead to my error08:52
olivierb_but I am definitely way off being a selinux knowledgeable person08:52
ianwolivierb_ : what happens if you actually install auditd on the building system?08:59
*** noama has joined #openstack-dib09:00
olivierb_ianw will try this in the next few hours09:02
ianwi think it uses a netlink socket?  which would be available within the chroot ... if the setfiles version didn't have that exit(-1) commented out ...09:03
*** jesusaur has joined #openstack-dib09:33
*** hwoarang has quit IRC11:20
*** hwoarang has joined #openstack-dib11:20
*** rnm has joined #openstack-dib11:34
*** rnm is now known as rmart0411:36
*** rmart04 has quit IRC11:40
*** rnm has joined #openstack-dib11:40
*** rnm has quit IRC11:42
*** rnm has joined #openstack-dib11:42
*** rnm is now known as rmart0411:43
*** hwoarang has quit IRC11:46
*** hwoarang has joined #openstack-dib11:46
olivierb_ianw tried to install and launch auditd on my xenial installation14:14
olivierb_apt-get install auditd audispd-plugins14:15
olivierb_sudo systemctl start auditd14:15
olivierb_sudo systemctl status auditd14:15
olivierb_Condition: start condition failed at Thu 2018-08-30 16:11:04 CEST; 3s ago14:15
olivierb_           ConditionKernelCommandLine=!audit=0 was not met14:15
olivierb_will try to reboot after enabling audit=1 in grub14:17
olivierb_auditd now functional on my system, retrying to build image14:21
olivierb_ianw however please note that unless I have badly launched the jobs in https://review.openstack.org/591366 your CI xenial system does not run auditd either14:22
olivierb_or if I badly checked the list of running processes14:22
olivierb_ianw ok after several tests with audit=0 and audit=1 and auditd installed on my xenial system I confirm that CentOS image generation succeeds when audit=1 and fails when audit=014:39
olivierb_so would it make sense to update https://review.openstack.org/#/c/559485 with a test for grep audit=1 /proc/cmdline ???14:40
olivierb_however from a "conceptual" point of view, I do not understand why building an image (whatever it is and on whatever system) should depend (read succeed or fail) depending on its "kernel settings"14:42
olivierb_please advise14:43
*** olivier__ has joined #openstack-dib15:21
*** olivierb_ has quit IRC15:22
*** olivier__ has quit IRC15:46
*** olivierb_ has joined #openstack-dib15:48
*** noama has quit IRC16:30
*** rmart04 has quit IRC16:41
*** olivier__ has joined #openstack-dib19:19
*** olivierb_ has quit IRC19:20
*** olivier__ has quit IRC19:54
*** rmart04 has joined #openstack-dib20:45
*** rmart04 has quit IRC21:16

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!