Bug 118975 - staff_t can loopback mount but sysadm_t can't
staff_t can loopback mount but sysadm_t can't
Product: Fedora
Classification: Fedora
Component: policy (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Daniel Walsh
Depends On:
Blocks: FC2Blocker
  Show dependency treegraph
Reported: 2004-03-23 10:15 EST by Tim Waugh
Modified: 2007-11-30 17:10 EST (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2004-04-19 13:57:16 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Tim Waugh 2004-03-23 10:15:18 EST
Description of problem:
Trying this sort of thing:

mount -oloop,ro boot.iso /mnt/cdrom

works as staff_t but not as sysadm_t.  Is that intentional?

Version-Release number of selected component (if applicable):
Comment 1 Daniel Walsh 2004-03-24 16:42:10 EST
The problem is the staff is not transitioning and sysadm, is.  So in
the case of sysadm you are running under mount_t context (Which is
correct?)  In the case of staff you are running under staff_t context.
 In this version of selinux staff_t is all powerfull, in the future it
will not be.  So this is a bug in that mount is not able to read the
file it is trying to mount.

Problem is with mount -o bind and mount -oloop almost any
file/directory can be a source or destination of mounting.

Comment 2 Mike McLean 2004-03-25 18:22:55 EST
So what is the correct way to perform a loopback mount with selinux?
Comment 3 Colin Walters 2004-04-19 13:57:16 EDT
staff_t transitions now into a mount domain too, so this bug is fixed
as far as I can see.

Mike:  I just added a new type, sysadm_mount_source_t that you can use
for loopback devices.  So the correct way is now:

chcon -t sysadm_mount_source_t foo.iso
mount -o loop foo.iso /mnt/cdrom

This will be in the next policy upload.
Comment 4 Mike McLean 2004-04-19 14:30:27 EDT
What about loopback mounting an iso that is on an RO-mounted NFS

Note You need to log in before you can comment on or make changes to this bug.