Bug 1265699 - autofs only creates files with default_t SElinux context
autofs only creates files with default_t SElinux context
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: autofs (Show other bugs)
All Linux
medium Severity medium
: rc
: ---
Assigned To: Ian Kent
Filesystem QE
Depends On:
  Show dependency treegraph
Reported: 2015-09-23 09:48 EDT by Stanislav Zidek
Modified: 2015-09-24 19:37 EDT (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2015-09-24 19:37:32 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Stanislav Zidek 2015-09-23 09:48:27 EDT
Description of problem:
I was testing slightly complex scenario involving connecting by ssh to a machine that has home directories of users on NFS fs accessed through autofs. The problem was that sshd could not read users' authorized_keys file because of their default_t context

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. create nfs share
2. configure it to be mounted by autofs
3. check SElinux contexts of mounted files

Actual results:
drwxr-xr-x. root root unconfined_u:object_r:default_t:s0 /home/nfs

Expected results:
drwxr-xr-x. root root system_u:object_r:nfs_t:s0       /home/nfs/

Additional info:

* /etc/auto.master contains:
/home /etc/auto.nfs

* cat /etc/auto.nfs
nfs -fstype=nfs4,rw,async,soft,intr,fscontext=system_u:object_r:nfs_t:s0

(I tried context, fscontext and defcontext)
Comment 1 Ian Kent 2015-09-24 04:00:00 EDT
Once mounted autofs is not involved in mounted file system

Are you sure that this doesn't happen if the nfs file
system is manually mounted?

Can you provide a full debug log so we can check that the
context option is being correctly passed to the mount of
the nfs file system?

Note You need to log in before you can comment on or make changes to this bug.