Bug 509834
Summary: | sVirt changing file context impacts other access | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Gene Czarcinski <gczarcinski> |
Component: | selinux-policy-targeted | Assignee: | Daniel Walsh <dwalsh> |
Status: | CLOSED WONTFIX | QA Contact: | Ben Levenson <benl> |
Severity: | medium | Docs Contact: | |
Priority: | low | ||
Version: | 11 | CC: | markmc |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2009-08-13 18:30:22 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Gene Czarcinski
2009-07-06 13:43:54 UTC
*** Bug 508865 has been marked as a duplicate of this bug. *** svirt is designed to change the context of the image files and other devices that it will use. If you want to allow httpd to share virtual image content then you need to write policy to allow it to read virtual images, or turn svirt off (not recommended.) I could add a boolean to allow this share virtual content via httpd if you believe this will be real common. (In reply to comment #2) > I could add a boolean to allow this share virtual > content via httpd if you believe this will be real common. So this would allow httpd access virt_content_t ? Gene: would that work for you? (Otherwise, from what dwalsh is saying, I think we should close this as WONTFIX) I am satisfied with the way things work with the rawhide packages which have been made available for Fedora 11 (the preview set). Reseting the context after use works for me. It is not a matter of WONTFIX but more (IMHO) of BEENFIXED Gene what change are you referring too? I was primarily concerned about ISO image files. When I first started using qemu-kvm-libvirt, the context for the ISO file was changed and then left changed when the guest terminated or the ISO image file was disconnected. I then started using the virt-preview set of packages when they appeared and, at that time, the context was reset to its "normal" value when the guest was done with that image. I understand the need to change the context and, since I am only using these image files during install, I can live with the context change for that "brief" period of time. |