Bug ID 1011265: Failover script cannot read /config/partitions/ after upgrade

Last Modified: Jan 20, 2023

Bug Tracker

Affected Product:  See more info
BIG-IP Install/Upgrade, TMOS(all modules)

Known Affected Versions:
14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.5, 14.1.0.6, 14.1.2, 14.1.2.1, 14.1.2.2, 14.1.2.3, 14.1.2.4, 14.1.2.5, 14.1.2.6, 14.1.2.7, 14.1.2.8, 14.1.3, 14.1.3.1, 14.1.4, 14.1.4.1, 14.1.4.2, 14.1.4.3, 14.1.4.4, 14.1.4.5, 14.1.4.6, 14.1.5, 14.1.5.1, 14.1.5.2, 14.1.5.3

Opened: Apr 14, 2021
Severity: 3-Major

Symptoms

After upgrading, failover does not work correctly. An error is encountered in /var/log/audit/log: type=AVC msg=audit(1617263442.711:206): avc: denied { read } for pid=17187 comm="active" name="partitions" dev="dm-11" ino=259 scontext=system_u:system_r:f5config_failover_t:s0 tcontext=system_u:object_r:f5config_t:s0 tclass=dir

Impact

Failover does not complete. Floating IP addresses do not move to the active device.

Conditions

-- High availability (HA) environment configured -- Devices are upgraded to version 14.1.4 -- A failover occurs

Workaround

Tmsh modify sys db failover.selinuxallowscripts enable

Fix Information

None

Behavior Change