Re: Selinux policy error in syslog

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi Muminul,

Are you running with all the latest updates?

Do you still experience issues with kernel 3.10.0-327.22.2.el7 ?

- Ken

On Wed, Jul 13, 2016 at 12:46 PM, Muminul Islam Russell
<misla011@xxxxxxx> wrote:
> Hello,
>
> I got the following error while installing ceph-selinux.
>
> kernel: SELinux:  Permission audit_read in class capability2 not defined in
> policy.
> kernel: SELinux:  Class binder not defined in policy.
> kernel: SELinux: the above unknown classes and permissions will be allowed
>
> command to reproduce the error:
> /usr/sbin/semodule -i /usr/share/selinux/packages/ceph.pp
>
> Then check the output in syslog.
>
> Info:
> These are object classes and av permissions that were introduced in the
> newer kernel, but ceph-selinux policy is for the older kernel and thus does
> not know these new object classes and av permissions. So they will just be
> ignored (allowed). So other than a few warnings it really does not
> affect anything or change the behavior of the policy I believe.
>
> But we could just get rid of this warnings.
>
> Thanks,
> Muminul
> --
> To unsubscribe from this list: send the line "unsubscribe ceph-devel" in
> the body of a message to majordomo@xxxxxxxxxxxxxxx
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
--
To unsubscribe from this list: send the line "unsubscribe ceph-devel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html



[Index of Archives]     [CEPH Users]     [Ceph Large]     [Information on CEPH]     [Linux BTRFS]     [Linux USB Devel]     [Video for Linux]     [Linux Audio Users]     [Yosemite News]     [Linux Kernel]     [Linux SCSI]
  Powered by Linux