Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

selinux: Update policy to grant additional access #7971

Merged
merged 2 commits into from Mar 15, 2016
Merged

Conversation

b-ranto
Copy link
Contributor

@b-ranto b-ranto commented Mar 8, 2016

This adds dac_override capability and ability to manage var_lock_t labelled locks.

EDIT: No need to bump the version and relabel the files as we do not change any context of the files, we just allow additional access.

Fixes: #14870
Signed-off-by: Boris Ranto <branto@redhat.com>
We currently create the ceph lock by an unconfined process (ceph-disk).
Unconfined processes inherit the context from the parrent directory.
This allows ceph daemons to access the files with context inherrited
from the parent directory (/var/lock | /run/lock).

Signed-off-by: Boris Ranto <branto@redhat.com>
@liewegas
Copy link
Member

passed rados teuthology run

@liewegas liewegas changed the title Update SELinux policy to grant additional access selinus: Update policy to grant additional access Mar 15, 2016
@liewegas liewegas changed the title selinus: Update policy to grant additional access selinux: Update policy to grant additional access Mar 15, 2016
liewegas added a commit that referenced this pull request Mar 15, 2016
selinux: Update policy to grant additional access
@liewegas liewegas merged commit 15fc71a into master Mar 15, 2016
@liewegas liewegas deleted the wip-selinux-update branch March 15, 2016 12:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
2 participants