Hide Forgot
Description of problem: In a chrooted sftp environment, SELinux is preventing users from uploading new files to their home directories. sftp/chroot option either runs in the old sftpd_t domain or in the sshd_t domain which is not correct. Version-Release number of selected component (if applicable): How reproducible: https://bugzilla.redhat.com/show_bug.cgi?id=729648 Steps to Reproduce: 1. 2. 3. Actual results: Expected results: Additional info:
With removed openssh-5.8p1-sftpcontext.patch and with added openssh-5.8p2-sftp-chroot.patch (similar to openssh-5.9p1-sftp-chroot.patch from Rawhide) I get this behaviour: 1. ChrootDirectory none Subsystem sftp internal-sftp system_u:system_r:sshd_t:s0-s0:c0.c1023 /usr/sbin/sshd -D system_u:system_r:sshd_t:s0-s0:c0.c1023 \_ sshd: staff [priv] system_u:system_r:sshd_t:s0-s0:c0.c1023 \_ sshd: staff@notty staff_u:staff_r:staff_t:s0 \_ sshd: staff@internal-sftp 2. ChrootDirectory none Subsystem sftp /usr/libexec/openssh/sftp-server system_u:system_r:sshd_t:s0-s0:c0.c1023 /usr/sbin/sshd -D system_u:system_r:sshd_t:s0-s0:c0.c1023 \_ sshd: staff [priv] system_u:system_r:sshd_t:s0-s0:c0.c1023 \_ sshd: staff@notty staff_u:staff_r:staff_t:s0 \_ /usr/libexec/openssh/sftp-server 3. ChrootDirectory /chroot Subsystem sftp internal-sftp system_u:system_r:sshd_t:s0-s0:c0.c1023 /usr/sbin/sshd -D system_u:system_r:sshd_t:s0-s0:c0.c1023 \_ sshd: staff [priv] system_u:system_r:chroot_user_t:s0-s0:c0.c1023 \_ sshd: staff@notty system_u:system_r:chroot_user_t:s0-s0:c0.c1023 \_ sshd: staff@internal-sftp Is this what you expect?
ad 1) yes ad 2) yes ad 3) yes
openssh-5.8p2-24.fc16 has been submitted as an update for Fedora 16. https://admin.fedoraproject.org/updates/openssh-5.8p2-24.fc16
Package openssh-5.8p2-24.fc16: * should fix your issue, * was pushed to the Fedora 16 testing repository, * should be available at your local mirror within two days. Update it with: # su -c 'yum update --enablerepo=updates-testing openssh-5.8p2-24.fc16' as soon as you are able to. Please go to the following url: https://admin.fedoraproject.org/updates/FEDORA-2012-1421/openssh-5.8p2-24.fc16 then log in and leave karma (feedback).
openssh-5.8p2-24.fc16 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report.