This bug has been copied from bug #875839 and has been proposed to be backported to 6.3 z-stream (EUS).
Fixed in selinux-policy-3.7.19-155.el6_3.7 I am just going to create a new errata. Also this will need to be tested by OpenShift folks.
Some tests: F18: # sesearch -A -t openshift_t -c process -p transition |wc -l 9 # sesearch -A -t openshift_app_t -c process -p transition |wc -l 6 RHEL6.3.z # sesearch -A -t openshift_t -c process -p transition |wc -l 9 # sesearch -A -t openshift_app_t -c process -p transition |wc -l 6 F18: # grep shift /etc/selinux/targeted/contexts/files/file_contexts |wc -l 31 RHEL6.3.z # grep shift /etc/selinux/targeted/contexts/files/file_contexts |wc -l F18: # getsebool -a |grep "dns\|stick" httpd_run_stickshift --> off httpd_verify_dns --> off RHEL6.3.z: #getsebool -a |grep "dns\|stick" httpd_run_stickshift --> off httpd_verify_dns --> off
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHEA-2012-1471.html