Bug 144513
Summary: | RFE: Prompt user to relabel samba share | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Ivan Gyurdiev <ivg231> |
Component: | system-config-samba | Assignee: | Nils Philippsen <nphilipp> |
Status: | CLOSED NOTABUG | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | rawhide | CC: | dwalsh |
Target Milestone: | --- | Keywords: | FutureFeature |
Target Release: | --- | ||
Hardware: | i386 | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Enhancement | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2006-09-27 23:46:34 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Ivan Gyurdiev
2005-01-07 21:18:49 UTC
I should note that samba_share_t is now a customizable file type in selinux, which means it will survive a restorecon. What's the status of this bug? This is not as easy as it seems. What happens if a labeled part of the system wants to be shared via samba. IE I want to share /var/log. I don't want to relabel that samba_share_t. Dan Well, if you don't relabel it, it won't work properly. Maybe the user should be warned if relabeling from a system context. I was interested in a way to autogenerate mixed types on the fly that merge access rules. Someone wrote a script for that on the selinux list, but the discussion didn't go anywhere from there. Is this still an issue and is it solvable in s-c-samba? Yes the place to solve this is s-c-samba. Basically if you create a new directory tree that you wish to share via samba (Not Home Directory or existing files, you should label it samba_share_t.) Might not be as big a problem since setroubleshoot tells the user the same thing. Dan Is this type consistent throughout all the policies we offer (not only the one we support, i.e. targeted)? Yes, the problem is s-c-samba figuring out whether to relabel the directory tree or not. I am thinking we may want to punt on this and allow setroubleshoot to handle it. Or at most advise them of what SELinux would require. You can look at man selinux_samba for a good definition of what SELinux will do with samba. |