Bug 1186046 - label ipsilon /var/lib files
Summary: label ipsilon /var/lib files
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 22
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Lukas Vrabec
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: 1227445
TreeView+ depends on / blocked
 
Reported: 2015-01-26 22:06 UTC by John Dennis
Modified: 2015-10-05 13:49 UTC (History)
6 users (show)

Fixed In Version: selinux-policy-3.13.1-126.fc22
Doc Type: Bug Fix
Doc Text:
Clone Of:
: 1227433 1227445 (view as bug list)
Environment:
Last Closed: 2015-05-26 03:35:17 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description John Dennis 2015-01-26 22:06:34 UTC
The ipsilon project would like to have the following embedded in the global SELinux policy.

semanage fcontext -a -t httpd_var_lib_t '%{_sharedstatedir}/ipsilon(/.*)?' || :
semanage fcontext -a -t var_lib_t '%{_sharedstatedir}/ipsilon(/.*)/*.conf' || :

Comment 1 Patrick Uiterwijk 2015-03-23 11:49:53 UTC
Could someone please look into this?
Ipsilon is an accepted change for Fedora 22: https://fedoraproject.org/wiki/Changes/Ipsilon

Comment 2 Lukas Vrabec 2015-03-23 12:45:14 UTC
Hi Patrick, 

So, you need label /var/lib/ipsilon(/.*)?  as httpd_var_lib_t and /var/lib/ipsilon(/.*)/*.conf as just var_lib_t?

Comment 3 Patrick Uiterwijk 2015-03-23 16:10:52 UTC
Hi Lukas,

That would be correct.

Comment 4 Patrick Uiterwijk 2015-03-30 14:33:23 UTC
Hi Lukas,

I see you didn't add this in the last change of March 23rd.
Do you have any idea when you'll be able to get an updated package into Fedora (at least F22)?

Comment 5 Patrick Uiterwijk 2015-04-20 12:26:09 UTC
Hi, any updates to this?

Comment 6 Patrick Uiterwijk 2015-04-20 12:30:16 UTC
Please note that until this is fixed, this prevents running the Ipsilon provider as is installed by default.

(Ipsilon is a feature for Fedora 22)

Comment 7 Lukas Vrabec 2015-04-21 15:12:20 UTC
I think we could make new policy for ipsilon.
I'll create some init policy, can you then send some scratch build for testing?

Comment 8 Patrick Uiterwijk 2015-04-21 19:41:38 UTC
That would be better, but might be quite complex.

Ipsilon is a mod_wsgi application that needs to be able to talk to at least:
1. Databases (possibly)
2. LDAP/Kerberos/IPA (possibly, optionally from Apache context)
3. SSSD (from Apache context)
4. Disk (configuration, possibly database(s) )

There are builds for Ipsilon-0.6.0 available in the Fedora repositories.

Feel free to ask if you need more info.

Comment 9 Patrick Uiterwijk 2015-05-08 15:13:17 UTC
Is there any progress on this?

The update would need to go out by today or tomorrow to make it to F22 stable before final freeze.

Comment 10 Miroslav Grepl 2015-05-12 14:51:05 UTC
I am adding fixes. Not sure if we can get in without blocker today?

Comment 11 Miroslav Grepl 2015-05-12 14:54:07 UTC
commit 618dd71c16680441c3914416b3998f23d50cbd71
Author: Miroslav Grepl <mgrepl>
Date:   Tue May 12 16:53:21 2015 +0200

    Add support for /var/lib/ipsilon dir and label it as httpd_var_lib_t. BZ(1186046)

Comment 12 Fedora Update System 2015-05-12 17:56:20 UTC
selinux-policy-3.13.1-126.fc22 has been submitted as an update for Fedora 22.
https://admin.fedoraproject.org/updates/selinux-policy-3.13.1-126.fc22

Comment 13 Fedora Update System 2015-05-13 08:20:12 UTC
Package selinux-policy-3.13.1-126.fc22:
* should fix your issue,
* was pushed to the Fedora 22 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing selinux-policy-3.13.1-126.fc22'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2015-8101/selinux-policy-3.13.1-126.fc22
then log in and leave karma (feedback).

Comment 14 Fedora Update System 2015-05-26 03:35:17 UTC
selinux-policy-3.13.1-126.fc22 has been pushed to the Fedora 22 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.