Bug 1340542

Summary: Need backported fix for install_exec_t (or rpm_exec_t) for rpm-ostreed
Product: Red Hat Enterprise Linux 7 Reporter: Colin Walters <walters>
Component: selinux-policyAssignee: Lukas Vrabec <lvrabec>
Status: CLOSED ERRATA QA Contact: Milos Malik <mmalik>
Severity: urgent Docs Contact:
Priority: urgent    
Version: 7.2CC: lvrabec, mgrepl, mmalik, plautrba, pvrabec, ssekidde
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: selinux-policy-3.13.1-77.el7 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-11-04 02:29:55 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Colin Walters 2016-05-27 19:14:30 UTC
See:
https://bugzilla.redhat.com/show_bug.cgi?id=1309075
and
https://github.com/projectatomic/rpm-ostree/pull/292

This is now an active time bomb in RHELAH 7.

Can we:

0) Ensure this is fixed in 7.3
1) Backport the fix into the current stable 7.2 SELinux policy package
2) Tag that package into the RHELAH 7 stream
3) Remember to un-tag the override when rebasing to 7.3

Comment 1 Colin Walters 2016-05-27 19:15:09 UTC
Related to this...as I discussed in the PR, is there a reason we're not using rpm_t as PackageKit already does?

Comment 4 Colin Walters 2016-06-01 14:45:45 UTC
(In reply to Colin Walters from comment #1)
> Related to this...as I discussed in the PR, is there a reason we're not
> using rpm_t as PackageKit already does?

Can someone reply to this aspect please?

And related to this, can the policy be changed to set this *both* on /usr/bin/rpm-ostree and /usr/libexec/rpm-ostreed (which may not exist after the above linked PR lands)

Comment 16 errata-xmlrpc 2016-11-04 02:29:55 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2283.html