Bug 1464489

Summary: RFE: backport SELinux/InfiniBand userspace support
Product: Red Hat Enterprise Linux 7 Reporter: Paul Moore <pmoore>
Component: libsepolAssignee: Petr Lautrbach <plautrba>
Status: CLOSED ERRATA QA Contact: Milos Malik <mmalik>
Severity: low Docs Contact:
Priority: unspecified    
Version: 7.5CC: jzarsky, lvrabec, mgrepl, mmalik, mthacker, plautrba, pmoore, vmojzis
Target Milestone: rcKeywords: FutureFeature
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 1466274 1466276 (view as bug list) Environment:
Last Closed: 2018-04-10 12:51:11 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1464478, 1523309    
Bug Blocks: 1449326, 1464484, 1466274, 1466276    

Description Paul Moore 2017-06-23 14:22:10 UTC
Description of problem:
Backport the SELinux userspace patches to enable the InfiniBand access controls.  See BZ #1449326 for the RHEL-7.x customer request.

Additional info:

Additional patches may also be necessary, but at a minimum the backport should include the upstream commits below:

 a2fe1861 semanage: Fix manpage author for ibpkey and ibendport pages.
 b217ffd7 semanage: Update man pages for infiniband
 9a3d2c7a semanage: Update semanage to allow runtime labeling of ibendports
 6a7a5aaf semanage: Update semanage to allow runtime labeling of Infiniband Pkeys
 28663ff1 libsepol: Add IB end port handling to CIL
 118c0cd1 libsepol: Add ibendport ocontext handling
 5bc05dd2 checkpolicy: Add support for ibendportcon labels
 e564f7b5 libsepol: Add Infiniband Pkey handling to CIL
 9fbb3112 libsepol: Add ibpkey ocontext handling
 5b203145 checkpolicy: Add support for ibpkeycon labels

Comment 6 errata-xmlrpc 2018-04-10 12:51:11 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:0764