Bug 1157252
Summary: | External luns may loose the libvirt selinux label if a udev change event is triggered | |||
---|---|---|---|---|
Product: | Red Hat Enterprise Virtualization Manager | Reporter: | Tal Nisan <tnisan> | |
Component: | vdsm | Assignee: | Nir Soffer <nsoffer> | |
Status: | CLOSED CURRENTRELEASE | QA Contact: | Elad <ebenahar> | |
Severity: | high | Docs Contact: | ||
Priority: | high | |||
Version: | 3.5.0 | CC: | amureini, bazulay, ecohen, gklein, iheim, lpeer, lsurette, mgoldboi, nsoffer, rbalakri, scohen, yeylon | |
Target Milestone: | --- | Keywords: | ZStream | |
Target Release: | 3.5.0 | |||
Hardware: | Unspecified | |||
OS: | Unspecified | |||
Whiteboard: | storage | |||
Fixed In Version: | vt8 | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | ||
Clone Of: | 1152661 | |||
: | 1157688 (view as bug list) | Environment: | ||
Last Closed: | 2015-02-16 13:40:16 UTC | Type: | Bug | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | Storage | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: | ||||
Bug Depends On: | 1152661 | |||
Bug Blocks: | 1157688 |
Description
Tal Nisan
2014-10-26 17:20:55 UTC
The 3.5 patch is merged. Moving to MODIFIED. SElinux label is kept for a direct LUN while it is attached to a running VM. [root@green-vdsb dev]# multipath -ll |grep 3514f0c5447600438 3514f0c5447600438 dm-21 XtremIO ,XtremApp [root@green-vdsb dev]# ls -Z |grep dm-21 brw-rw----. root disk system_u:object_r:fixed_disk_device_t:s0 dm-21 Started the VM: [root@green-vdsb dev]# ls -Z |grep dm-21 brw-rw----. vdsm qemu system_u:object_r:svirt_image_t:s0:c203,c878 dm-21 Changed label: [root@green-vdsb dev]# udevadm trigger --verbose --action change --property-match=3514f0c5447600438 [root@green-vdsb dev]# ls -Z |grep dm-21 brw-rw----. vdsm qemu system_u:object_r:svirt_image_t:s0:c203,c878 dm-21 Checked on iSCSI and FC Verified using rhev 3.5 vt11 Nit, iiuc, there is nothing customer-facing to document here. Can you please either confirm and set requires-doctext-, or provide the relevant documentation? Thanks! (In reply to Allon Mureinik from comment #4) > Nit, iiuc, there is nothing customer-facing to document here. > Can you please either confirm and set requires-doctext-, or provide the > relevant documentation? I agree. |