Bug 1767401 - allow cephfs to provide contexts via xattr
Summary: allow cephfs to provide contexts via xattr
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 32
Hardware: Unspecified
OS: Unspecified
high
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: 1767402
TreeView+ depends on / blocked
 
Reported: 2019-10-31 11:41 UTC by Jeff Layton
Modified: 2020-04-08 09:26 UTC (History)
5 users (show)

Fixed In Version: selinux-policy-3.14.5-28.fc32
Clone Of:
: 1767402 (view as bug list)
Environment:
Last Closed: 2020-04-08 09:26:38 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)
allow ceph to use xattrs to set policy (1.62 KB, patch)
2019-10-31 11:42 UTC, Jeff Layton
no flags Details | Diff

Description Jeff Layton 2019-10-31 11:41:27 UTC
cephfs recently grew the ability to handle selinux contexts via its xattr infrastructure:

    https://github.com/uli/kernel/commit/ac6713ccb5a6d13b59a2e3fda4fb049a2c4e0af2

Fix the selinux-policy to allow this to work instead of setting a context on the whole mountpoint.

Comment 1 Jeff Layton 2019-10-31 11:42:49 UTC
Created attachment 1631015 [details]
allow ceph to use xattrs to set policy

Comment 2 Lukas Vrabec 2019-10-31 16:40:44 UTC
PR merged: 

commit 862368c92def52e3bccce571a46cd99dce34fc78 (HEAD -> rawhide, origin/rawhide)
Author: Jeff Layton <jlayton>
Date:   Wed Oct 30 14:12:06 2019 -0400

    Allow cephfs to use xattrs for storing contexts
    
    cephfs recently gained the ability to store SELinux contexts in an xattr
    (like most local filesystems). Change the policy to allow for this.
    
    Signed-off-by: Jeff Layton <jlayton>

Comment 3 Fedora Admin XMLRPC Client 2020-01-23 16:24:21 UTC
This package has changed maintainer in the Fedora.
Reassigning to the new maintainer of this component.

Comment 4 Ben Cotton 2020-02-11 17:27:11 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 32 development cycle.
Changing version to 32.

Comment 5 Zdenek Pytela 2020-04-08 09:26:38 UTC
Fix for the issue reported is a part of the current package version.


Note You need to log in before you can comment on or make changes to this bug.