mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* About commit 901ef845fa2469c ("selinux: allow per-file labeling for cgroupfs")
@ 2017-10-06 17:53 Waiman Long
  2017-10-10 14:06 ` Stephen Smalley
  0 siblings, 1 reply; 3+ messages in thread
From: Waiman Long @ 2017-10-06 17:53 UTC (permalink / raw)
  To: Antonio Murdaca; +Cc: Paul Moore, Stephen Smalley, selinux, Tejun Heo, lkml

Antonio,

I have a question about your 4.14 upstream commit 901ef845fa2469c
("selinux: allow per-file labeling for cgroupfs"). With that, I am no
longer able to mount the cgroup2 filesystem with a 4.14 kernel. The
problem is that your commit sets the SE_SBGENFS flag, which causes
selinux to lookup the genfs database for a filesystem type match.
However, the filesystem type "cgroup2" isn't in the genfs database in my
RHEL7 based test system. The "cgroup" filesystem type is in the genfs database,
so I have no problem with v1 cgroup mount.

Do you know where the genfs database is defined? I need some way to add cgroup2
as a valid genfs fstype, or I have to manually back out the commit in order to
do my cgroup2 testing.

Thanks,
Longman

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2017-10-10 14:05 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-10-06 17:53 About commit 901ef845fa2469c ("selinux: allow per-file labeling for cgroupfs") Waiman Long
2017-10-10 14:06 ` Stephen Smalley
2017-10-10 14:05   ` Waiman Long

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®