Project

General

Profile

Actions

action #178822

closed

coordination #127031: [saga][epic] openQA for SUSE customers

coordination #138365: [epic] openQA works in SELinux enforced environments

openQA in openQA tests failing with unreachable webUI, possibly due to SELinux size:S

Added by okurz about 1 month ago. Updated 20 days ago.

Status:
Resolved
Priority:
High
Assignee:
Category:
Regressions/Crashes
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:

Description

Observation

From #178642-8 as szarate found out

I wonder if this is more about selinux... https://openqa.opensuse.org/tests/4917476#step/dashboard/7 is the same error that I'm having on my Tumbleweed installation of openQA (after updating just today)

and the logs are showing constant denies from selinux:

ket permissive=0
type=AVC msg=audit(1741786133.379:949): avc:  denied  { name_connect } for  pid=3901 comm="httpd-prefork" dest=9526 scontext=system_u:system_r:httpd_t:s0 tcontext=system_u:object_r:openqa_port_t:s0 tclass=tcp_socket permissive=0
type=AVC msg=audit(1741786133.379:950): avc:  denied  { name_connect } for  pid=16186 comm="httpd-prefork" dest=9526 scontext=system_u:system_r:httpd_t:s0 tcontext=system_u:object_r:openqa_port_t:s0 tclass=tcp_socket permissive=0
type=AVC msg=audit(1741786133.379:951): avc:  denied  { name_connect } for  pid=16186 comm="httpd-prefork" dest=9526 scontext=system_u:system_r:httpd_t:s0 tcontext=system_u:object_r:openqa_port_t:s0 tclass=tcp_socket permissive=0
type=AVC msg=audit(1741786133.379:952): avc:  denied  { name_connect } for  pid=3901 comm="httpd-prefork" dest=9526 scontext=system_u:system_r:httpd_t:s0 tcontext=system_u:object_r:openqa_port_t:s0 tclass=tcp_socket permissive=0

See
https://openqa.opensuse.org/tests/4914440#step/dashboard/6

Further details

Always latest result in this scenario: latest

Suggestions

Out of scope

  • Complete SELinux profiles for openQA - this could be a follow-up ticket resulting from this ticket, though

Related issues 3 (1 open2 closed)

Related to openQA Project (public) - action #180002: openQA-in-openQA test fails in dashboard with 403 Forbidden size:SResolvedemiler2025-04-032025-04-22

Actions
Copied from openQA Project (public) - action #178642: openQA in openQA tests failing with 503 errors and timeouts due to misbehaving MirrorCache / CDN auto_review:"retry.*zypper.*ref && zypper --no-cd -n in openQA-worker.*timed out" size:SResolvedlivdywan2025-03-11

Actions
Copied to openQA Project (public) - action #180029: [openqa-in-openqa] Can we call configure-web-proxy in "install_from_git" and remove the selinux workaround?New2025-04-04

Actions
Actions

Also available in: Atom PDF