Bug 700244

Summary: Some files on nfs mounted home dirs still get wrong labels
Product: Red Hat Enterprise Linux 5 Reporter: Orion Poplawski <orion>
Component: selinux-policyAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED CURRENTRELEASE QA Contact: BaseOS QE Security Team <qe-baseos-security>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 5.6CC: dwalsh
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-04-28 18:46:46 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Orion Poplawski 2011-04-27 21:04:42 UTC
Description of problem:

I'm periodically running /sbin/restorecon -R -v /export/home on our EL 5.6 NFS home directory server.  I'm seeing messages like the following periodically:

/sbin/restorecon reset /export/home/kwan/.lyxpipe.in context system_u:object_r:user_home_dir_t:s0->user_u:object_r:user_home_t:s0
/sbin/restorecon reset /export/home/kwan/.lyxpipe.out context system_u:object_r:user_home_dir_t:s0->user_u:object_r:user_home_t:s0

Version-Release number of selected component (if applicable):
selinux-policy-2.4.6-300.el5

Comment 1 Orion Poplawski 2011-04-27 21:21:57 UTC
/sbin/restorecon reset /export/home/riggin/.#NSF_bio.tex context system_u:object_r:user_home_dir_t:s0->user_u:object_r:user_home_t:s0

Comment 2 Daniel Walsh 2011-04-28 11:54:34 UTC
Miroslav in RHEL6 we have

optional_policy(`
	userdom_user_home_dir_filetrans_user_home_content(kernel_t, { file dir })
')

Do we have this in RHEL5?

This would still be broken and until we get some of the file name transition stuff we are adding in F16, it would be the best we can do, if it works.

Comment 3 Orion Poplawski 2011-04-28 16:01:41 UTC
FWIW - Things are a *lot* better now with 5.6 than with 5.5, so it seems something changed there.

Comment 4 Miroslav Grepl 2011-04-28 16:27:39 UTC
Well, we are missing this in RHEL5.

Comment 5 Daniel Walsh 2011-04-28 18:46:46 UTC
Orion I am closing this as fixed (Well fixes as best we can.)  And you triggered me to make a whole series of changes to Fedora 16 to make this much better.