Hide Forgot
Description of problem: In order for the fix for BZ 1899703 to not break virtiofs mounts where the underlying filesystem (and thus the virtiofs mount itself) doesn't support xattrs, an additional kernel patch is needed that makes SELinux to fall back to a genfscon rule (if any) when there is an fs_use_xattr rule, but the superblock doesn't have xattr support. The patch is currently posted at: https://lore.kernel.org/selinux/20210113123802.63563-1-omosnace@redhat.com/T/ The patch's log message contains a simple reproducer that can be used to verify that the fallback works.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Moderate: kernel security, bug fix, and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2021:4356