SELinux has defined the new glusterd_brick_t label to support a server side policy of glusterfs. Use of this label should allow enablement of SELinux (e.g., enforcing mode) on glusterfs servers. Bug 1016138 covers the evolution of the server side selinux policy for glusterfs. To avoid the confusion and overhead of manual labelling each time a brick is created, add a hook script that labels the brick directory automatically on volume creation. The hook script can be included by users/admins/packagers as necessary if selinux support is desired.
REVIEW: http://review.gluster.org/6630 (extras/hook-scripts: add post-create script to label bricks for selinux) posted (#1) for review on master by Brian Foster (bfoster)
REVIEW: http://review.gluster.org/6630 (extras/hook-scripts: add post-create script to label bricks for selinux) posted (#2) for review on master by Brian Foster (bfoster)
REVIEW: http://review.gluster.org/6630 (extras/hook-scripts: selinux brick file context management scripts) posted (#3) for review on master by Brian Foster (bfoster)
REVIEW: http://review.gluster.org/6630 (extras/hook-scripts: selinux brick file context management scripts) posted (#4) for review on master by Brian Foster (bfoster)
REVIEW: http://review.gluster.org/6630 (extras/hook-scripts: SELinux brick file context management scripts) posted (#5) for review on master by Niels de Vos (ndevos)
This bug was accidentally moved from POST to MODIFIED via an error in automation, please see mmccune with any questions
REVIEW: http://review.gluster.org/6630 (extras/hook-scripts: SELinux brick file context management scripts) posted (#6) for review on master by jiffin tony Thottan (jthottan)
REVIEW: http://review.gluster.org/6630 (extras/hook-scripts: SELinux brick file context management scripts) posted (#7) for review on master by jiffin tony Thottan (jthottan)
REVIEW: https://review.gluster.org/6630 (extras/hook-scripts: SELinux brick file context management scripts) posted (#8) for review on master by Niels de Vos (ndevos)
REVIEW: https://review.gluster.org/6630 (extras/hook-scripts: SELinux brick file context management scripts) posted (#9) for review on master by Niels de Vos (ndevos)
REVIEW: https://review.gluster.org/6630 (extras/hook-scripts: SELinux brick file context management scripts) posted (#10) for review on master by Niels de Vos (ndevos)
REVIEW: https://review.gluster.org/6630 (extras/hook-scripts: SELinux brick file context management scripts) posted (#11) for review on master by Niels de Vos (ndevos)
COMMIT: https://review.gluster.org/6630 committed in master by Kaleb KEITHLEY (kkeithle) ------ commit 859669759f7fa0f2114add13660ce3bf16c77f30 Author: Brian Foster <bfoster> Date: Thu Jan 2 14:03:18 2014 -0500 extras/hook-scripts: SELinux brick file context management scripts The SELinux policy for gluster defines the glusterd_brick_t type to support server side SELinux (e.g., server side labels). Add convenience hook scripts that users/packagers can install to ensure that new bricks are labeled correctly. The volume create hook script adds a new SELinux file context for each brick path and runs a restorecon to label the brick. The volume delete hook removes the per-brick SELinux file context. Change-Id: I5f102db5382d813c4d822ff74e873a7a669b41db BUG: 1047975 Signed-off-by: Brian Foster <bfoster> Signed-off-by: Niels de Vos <ndevos> Signed-off-by: Jiffin Tony Thottan <jthottan> Reviewed-on: https://review.gluster.org/6630 Smoke: Gluster Build System <jenkins.org> NetBSD-regression: NetBSD Build System <jenkins.org> CentOS-regression: Gluster Build System <jenkins.org> Reviewed-by: Kaleb KEITHLEY <kkeithle>
This bug is getting closed because a release has been made available that should address the reported issue. In case the problem is still not fixed with glusterfs-3.12.0, please open a new bug report. glusterfs-3.12.0 has been announced on the Gluster mailinglists [1], packages for several distributions should become available in the near future. Keep an eye on the Gluster Users mailinglist [2] and the update infrastructure for your distribution. [1] http://lists.gluster.org/pipermail/announce/2017-September/000082.html [2] https://www.gluster.org/pipermail/gluster-users/