Bug 1976260

Summary: SELinux is preventing kexec from read access on the file /var/lib/kdump/initramfs-*kdump.img [rhel-8.4.0.z]
Product: Red Hat Enterprise Linux 8 Reporter: RHEL Program Management Team <pgm-rhel-tools>
Component: selinux-policyAssignee: Zdenek Pytela <zpytela>
Status: CLOSED ERRATA QA Contact: Milos Malik <mmalik>
Severity: high Docs Contact:
Priority: high    
Version: 8.5CC: dornelas, jniu, kfan, ltao, lvrabec, mmalik, plautrba, ruyang, ssekidde, travier
Target Milestone: betaKeywords: AutoVerified, Triaged, ZStream
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: selinux-policy-3.14.3-67.el8_4.1 Doc Type: Enhancement
Doc Text:
Feature: In the new version of the kexec-tools package, kdump checks if the initramfs image can be created in /boot. If the check fails, the /var/lib/kdump directory is used instead to create the initramfs image. Reason: On some operating systems, the /boot directory can be read-only, preventing the initramfs image file from being created in /boot. Result: SELinux supports kdump creating initramfs images in /var/lib/kdump.
Story Points: ---
Clone Of: 1965985 Environment:
Last Closed: 2021-08-10 13:12:12 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1965985    
Bug Blocks:    

Comment 13 errata-xmlrpc 2021-08-10 13:12:12 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (selinux-policy bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2021:3051