Skip to content

tentacle: qa: allowlist bpf podman denials on Rocky 10#67194

Closed
djgalloway wants to merge 1 commit intoceph:tentaclefrom
djgalloway:tent-bpf
Closed

tentacle: qa: allowlist bpf podman denials on Rocky 10#67194
djgalloway wants to merge 1 commit intoceph:tentaclefrom
djgalloway:tent-bpf

Conversation

@djgalloway
Copy link
Contributor

@djgalloway djgalloway commented Feb 3, 2026

Rocky Linux 10 logs SELinux AVCs for systemd BPF operations during container startup due to incomplete SELinux policy coverage. These AVCs occur in permissive mode, are reproducible without Ceph, and do not indicate functional failure. Tests should ignore this specific AVC class while continuing to fail on enforced denials.

(cherry picked from commit 93718d5)

Contribution Guidelines

  • To sign and title your commits, please refer to Submitting Patches to Ceph.

  • If you are submitting a fix for a stable branch (e.g. "quincy"), please refer to Submitting Patches to Ceph - Backports for the proper workflow.

  • When filling out the below checklist, you may click boxes directly in the GitHub web UI. When entering or editing the entire PR message in the GitHub web UI editor, you may also select a checklist item by adding an x between the brackets: [x]. Spaces and capitalization matter when checking off items this way.

Checklist

  • Tracker (select at least one)
    • References tracker ticket
    • Very recent bug; references commit where it was introduced
    • New feature (ticket optional)
    • Doc update (no ticket needed)
    • Code cleanup (no ticket needed)
  • Component impact
    • Affects Dashboard, opened tracker ticket
    • Affects Orchestrator, opened tracker ticket
    • No impact that needs to be tracked
  • Documentation (select at least one)
    • Updates relevant documentation
    • No doc update is appropriate
  • Tests (select at least one)
Show available Jenkins commands

You must only issue one Jenkins command per-comment. Jenkins does not understand
comments with more than one command.

Rocky Linux 10 logs SELinux AVCs for systemd BPF operations during container startup due to incomplete SELinux policy coverage. These AVCs occur in permissive mode, are reproducible without Ceph, and do not indicate functional failure. Tests should ignore this specific AVC class while continuing to fail on enforced denials.

Signed-off-by: David Galloway <david.galloway@ibm.com>
(cherry picked from commit 93718d5)
@github-actions github-actions bot added the tests label Feb 3, 2026
@github-actions github-actions bot added this to the tentacle milestone Feb 3, 2026
@djgalloway djgalloway added the DNM label Feb 4, 2026
@djgalloway
Copy link
Contributor Author

#66055 Should get backported instead

@djgalloway djgalloway closed this Feb 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant