Bug 984903

Summary: system-config-kdump needs write access to /boot/efi/EFI/redhat/grub.cfg
Product: Red Hat Enterprise Linux 6 Reporter: Martin Milata <mmilata>
Component: selinux-policyAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED ERRATA QA Contact: Michal Trunecka <mtruneck>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 6.4CC: dwalsh, ebenes, mmalik, mmilata, mtruneck, rwright
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: selinux-policy-3.7.19-210.el6 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-11-21 10:45:41 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 977981    

Description Martin Milata 2013-07-16 10:26:59 UTC
This is RHEL6 counterpart to Fedora bug #984549.

In order to fix #977981, system-config-kdump must be permitted to access the bootloader configuration on systems that boot using EFI. In particular, s-c-kdump (and grubby which is invoked by s-c-kdump) needs write access to /boot/efi/EFI/redhat/grub.cfg. It might be relevant that the EFI partition on /boot/efi has FAT32 file system.

Let me know if you want any other information, I have borrowed EFI-capable laptop to try things out on.

Comment 4 Michal Trunecka 2013-08-09 07:23:43 UTC
Martin, could you please check if the bug is fixed in the current policy?
(selinux-policy-3.7.19-210.el6.noarch or higher)

You can get the selinux-policy packages from Brew or from here:
http://people.redhat.com/dwalsh/SELinux/RHEL6/noarch/

Comment 5 Martin Milata 2013-08-16 09:11:31 UTC
(In reply to Michal Trunecka from comment #4)
> Martin, could you please check if the bug is fixed in the current policy?

I'm sorry, I already returned the EFI laptop I tested this on.

Comment 6 Michal Trunecka 2013-08-16 09:22:06 UTC
Ok, we'll leave just as policy check.

Comment 8 errata-xmlrpc 2013-11-21 10:45:41 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2013-1598.html

Comment 9 Randy Wright 2013-11-22 16:46:37 UTC
(In reply to errata-xmlrpc from comment #8)
I've read the erratum at http://rhn.redhat.com/errata/RHBA-2013-1598.html but I'm unclear on whether the selinux policy changes described in this erratum will be included in future RHEL6.x versions.  Can you clarify please when these policy changes are integrated into new versions?

Comment 10 Miroslav Grepl 2013-11-25 12:26:46 UTC
-fs_read_dos_files(kdumpgui_t)
+fs_manage_dos_files(kdumpgui_t)

has been added to RHEL6.5. So s-c-kdump is allowed to manage files on dosfs_t.