Bug 163668
Summary: | RFE for local adaptation | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Jonathan S. Shapiro <shap> |
Component: | selinux-policy-targeted | Assignee: | Daniel Walsh <dwalsh> |
Status: | CLOSED NOTABUG | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 4 | Keywords: | Security |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2005-09-19 20:17:09 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Jonathan S. Shapiro
2005-07-20 03:53:45 UTC
Two things. First you can put custom file context in /etc/selinux/targeted/contexts/files/file_context.local Which will survice a policy update. Also genhomedircon should be picking up the fact that you have users in the /guest directory and label it correctly. Do you have users in your passwd files with /guest as the root of the home dir? You should see definition in file_contexts.homedirs? Theoretically Issue 1 and 2 should be handled by this. Issue three should not happen. Do you have a mismatch between the default kernel and the policy? Dan Now that I think about it, genhomedircon probably *is* working for the home directories. I'm unclear when genhomedircon runs, however, and that would be useful to know. I'll try file_context.local for case 2 and see how that goes. Issue three definitely *does* happen. Now that you raise the kernel versioning issue, it occurs to me that in many of the cases where I have observed this problem, the selinux policy and the kernel have been upgraded simultaneously by yum and the selinux policy postinstall then failed as described in the other bug that I filed. Not sure if that is related or not. Genhomedircon is run when you upgrade the policy. Also if you are customizing policy-sources it is also run Any update on this bug? I've made some definite progress using file_context.local; that was very helpful. There remains the issue of "treat this directory like that one" for Xen installs, but I propose that we should handle that with a separate bug report. Given which, I'm content to close this bug. |