Bug 2015845
Summary: | [RHEL 8.4] Backport container-selinux policy to allow spc_t domains to set bpf rules on any domain [rhel-8.4.0.z] | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 8 | Reporter: | RHEL Program Management Team <pgm-rhel-tools> |
Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> |
Status: | CLOSED ERRATA | QA Contact: | Milos Malik <mmalik> |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | 8.4 | CC: | acardace, fdeutsch, lvrabec, mmalik, mtessun, plautrba, qe-baseos-security, sgott, ssekidde, toneata, zpytela |
Target Milestone: | rc | Keywords: | AutoVerified, Triaged, ZStream |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | selinux-policy-3.14.3-67.el8_4.3 | Doc Type: | Bug Fix |
Doc Text: |
Cause:
The policy does not allow super privileged containers set bpf rules on other domains.
Consequence:
Kubernetes does not fully operate with cgroups v2.
Fix:
The rule to allow the unconfined_domain_type attribute to set bpf rules on other domains was added to the policy.
Result:
Kubernetes operate fully with cgroups v2.
|
Story Points: | --- |
Clone Of: | 1991443 | Environment: | |
Last Closed: | 2021-12-16 14:51:17 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1991443 | ||
Bug Blocks: |
Comment 14
errata-xmlrpc
2021-12-16 14:51:17 UTC
|