Bug 2088441
Summary: | /usr/lib/systemd/systemd-socket-proxyd is not labeled appropriately, making the tool unusable | |||
---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8 | Reporter: | Renaud Métrich <rmetrich> | |
Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> | |
Status: | CLOSED ERRATA | QA Contact: | Milos Malik <mmalik> | |
Severity: | medium | Docs Contact: | Jan Fiala <jafiala> | |
Priority: | medium | |||
Version: | 8.6 | CC: | jafiala, lvrabec, mharri, mmalik, zpytela | |
Target Milestone: | rc | Keywords: | AutoVerified, Triaged | |
Target Release: | 8.8 | Flags: | pm-rhel:
mirror+
|
|
Hardware: | All | |||
OS: | Linux | |||
Whiteboard: | ||||
Fixed In Version: | selinux-policy-3.14.3-113.el8 | Doc Type: | Enhancement | |
Doc Text: |
.New SELinux policy for `systemd-socket-proxyd`
Because the `systemd-socket-proxyd` service requires particular resources usage, a new policy with the required rules was added to the `selinux-policy` packages. As a result, the service runs in its SELinux domain.
|
Story Points: | --- | |
Clone Of: | ||||
: | 2141606 (view as bug list) | Environment: | ||
Last Closed: | 2023-05-16 09:03:44 UTC | Type: | Bug | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: | ||||
Bug Depends On: | ||||
Bug Blocks: | 2141606 | |||
Deadline: | 2022-10-24 |
Description
Renaud Métrich
2022-05-19 12:59:27 UTC
We now need to sync with systemd to find an appropriate context. Something similar to what squid can do probably. Commit to backport: commit ea2da5e990b89f95cbfdebdda0b932e8c860c49d (HEAD -> rawhide, upstream/rawhide) Author: (GalaxyMaster) <galaxy4public.github.com> Date: Mon Nov 9 00:50:12 2020 +1100 added policy for systemd-socket-proxyd Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (selinux-policy bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2023:2965 |