Bug 1782615
Summary: | Incomplete SELinux policy for virt_qemu_ga_t | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 7 | Reporter: | sawozny |
Component: | qemu-guest-agent | Assignee: | Marc-Andre Lureau <marcandre.lureau> |
Status: | CLOSED WONTFIX | QA Contact: | xiagao |
Severity: | low | Docs Contact: | |
Priority: | unspecified | ||
Version: | 7.6 | CC: | jinzhao, juzhang, lijin, marcandre.lureau |
Target Milestone: | rc | ||
Target Release: | --- | ||
Hardware: | x86_64 | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2020-02-03 15:48:50 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1779358 | ||
Bug Blocks: |
Description
sawozny
2019-12-11 23:58:44 UTC
Seeing as the dependent bz was closed as wontfix, so doing the same here. Seems as though the SElinux level adjustments for RHEL7 would require more justification and a workaround exists (writing a custom policy), thus there are no plans to alter the RHEL7 default policies to resolve. I don't agree that this should be closed as a won't fix, but not being a RH customer I'm only shouting into the wind. There is a clear gap in default policy that is not related to custom work, but will be found by any user who tries to snapshot and quiesce a machine with a USED off-disk mount point. When I hear people push back against setting SELinux to enforce and then see demonstrable out-of-the-box policy errors going unfixed I really can't blame them for feeling that way. But at least this bug is now part of the public record and people affected by it will know the cause and how to work around it when they encounter it. I predict it will eventually be "discovered" and fixed in policy but probably only when an actual RH customer pushes the point. In the meantime, I have my workaround so while I'm disappointed in this result, I thank everyone involved for their time. |