Bug 710437 - Satellite sync cache has inconsistent selinux type
Summary: Satellite sync cache has inconsistent selinux type
Keywords:
Status: CLOSED DEFERRED
Alias: None
Product: Red Hat Satellite 5
Classification: Red Hat
Component: Satellite Synchronization
Version: 541
Hardware: Unspecified
OS: Unspecified
low
medium
Target Milestone: ---
Assignee: Michael Mráka
QA Contact: Red Hat Satellite QA List
URL:
Whiteboard:
Depends On:
Blocks: 462714
TreeView+ depends on / blocked
 
Reported: 2011-06-03 11:52 UTC by Šimon Lukašík
Modified: 2014-07-04 13:26 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2014-07-04 13:26:10 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Šimon Lukašík 2011-06-03 11:52:40 UTC
Description of problem:
The content in /var/cache/rhn/satsync/ is created with 

    unconfined_u:object_r:spacewalk_cache_t

by satellite-sync. On the other hand selinux politics specifies

    system_u:object_r:var_t

for that directory. The selinux type for this content should be
consistent.


Version-Release number of selected component (if applicable):
RHN Satellite 5.4.0
RHN Satellite 5.4.1

How reproducible:
always

Steps to Reproduce:
1. satellite-sync some channel
2. restorecon -rvv /var/cache/rhn/
3.
  
Actual results:
Thousands of lines similar to:
  restorecon reset /var/cache/rhn/satsync/packages/38/rhn-package-620138
  context unconfined_u:object_r:spacewalk_cache_t:s0->
  system_u:object_r:var_t:s0


Expected results:
<dark silence>

Additional info:
This is revealed by each update of spacewalk-selinux.

Comment 1 Miroslav Suchý 2011-06-20 15:41:29 UTC
I could not confirm it.
Do you have some special setup? Like nfs mounted var?

Comment 2 Šimon Lukašík 2011-06-21 07:53:10 UTC
Mirek, you are right. My reproducer is incorrect. You need to have fresh
installation *or* remove

    rm -rf /var/cache/rhn/satsync/

prior the sync. The problem might appear to user, when he: (1) installs
Satellite 5.4.0, (2) Sync some arbitrary channel, (3) Runs yum update of
spacewalk-selinux.


Note You need to log in before you can comment on or make changes to this bug.