Bug 2213605
Summary: | SELinux labels RIPE Atlas Probe/Anchor's /usr/sbin/ripe-atlas process as zebra_t | |||
---|---|---|---|---|
Product: | Red Hat Enterprise Linux 9 | Reporter: | Robert Scheck <redhat-bugzilla> | |
Component: | selinux-policy | Assignee: | Nobody <nobody> | |
Status: | CLOSED ERRATA | QA Contact: | Milos Malik <mmalik> | |
Severity: | medium | Docs Contact: | ||
Priority: | urgent | |||
Version: | 9.2 | CC: | apeetham, dbodnarc, fkrska, lvrabec, mmalik, zpytela | |
Target Milestone: | beta | Keywords: | Triaged, ZStream | |
Target Release: | 9.3 | |||
Hardware: | x86_64 | |||
OS: | Linux | |||
Whiteboard: | ||||
Fixed In Version: | selinux-policy-38.1.18-1.el9 | Doc Type: | Bug Fix | |
Doc Text: |
Cause: The policy contained the /usr/sbin/rip.* regex which was too broad and matched also binaries from other components, which leads to mislabeling of ripe-atlas
Consequence: SELinux labels RIPE Atlas Probe/Anchor's /usr/sbin/ripe-atlas process as zebra_t
Fix: Label only /usr/sbin/ripd and ripngd with zebra_exec_t
Result: Other binaries are not labeled as zebra_t
|
Story Points: | --- | |
Clone Of: | ||||
: | 2229992 (view as bug list) | Environment: | ||
Last Closed: | 2023-11-07 08:52:30 UTC | Type: | Bug | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: | ||||
Bug Depends On: | ||||
Bug Blocks: | 2229992 |
Description
Robert Scheck
2023-06-08 17:04:20 UTC
Commit to backport: b91d9a5b6 (HEAD -> rawhide, upstream/rawhide) Label only /usr/sbin/ripd and ripngd with zebra_exec_t Zdenek, is there a realistic chance for a backport to RHEL 9.2.z, if I file a RHBZ and a case via CEE/GSS? (In reply to Robert Scheck from comment #4) > Zdenek, is there a realistic chance for a backport to RHEL 9.2.z, if I file > a RHBZ and a case via CEE/GSS? There needs to be justification for accepting such a request. I opened case 03565036 at the Red Hat customer portal and provided a justification there. In the end, we need the fix in RHEL 9.3 GA and RHEL 9.2.z. Please let me know if something else is needed. Dmitri, Please follow your organization workflow to request a z-stream backport, it's not done manually. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (selinux-policy bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2023:6617 |