From: Waiman Long <longman@redhat.com>
To: Stephen Smalley <sds@tycho.nsa.gov>, Antonio Murdaca <runcom@redhat.com>
Cc: Tejun Heo <tj@kernel.org>,
selinux@tycho.nsa.gov, lkml <linux-kernel@vger.kernel.org>,
Paul Moore <paul@paul-moore.com>,
Miroslav Grepl <mgrepl@redhat.com>
Subject: Re: About commit 901ef845fa2469c ("selinux: allow per-file labeling for cgroupfs")
Date: Tue, 10 Oct 2017 10:05:17 -0400 [thread overview]
Message-ID: <89c4fc8c-1931-582c-a7f3-8aa2ef14c3c4@redhat.com> (raw)
In-Reply-To: <1507644412.30616.2.camel@tycho.nsa.gov>
On 10/10/2017 10:06 AM, Stephen Smalley wrote:
> On Fri, 2017-10-06 at 13:53 -0400, Waiman Long wrote:
>> Antonio,
>>
>> I have a question about your 4.14 upstream commit 901ef845fa2469c
>> ("selinux: allow per-file labeling for cgroupfs"). With that, I am no
>> longer able to mount the cgroup2 filesystem with a 4.14 kernel. The
>> problem is that your commit sets the SE_SBGENFS flag, which causes
>> selinux to lookup the genfs database for a filesystem type match.
>> However, the filesystem type "cgroup2" isn't in the genfs database in
>> my
>> RHEL7 based test system. The "cgroup" filesystem type is in the genfs
>> database,
>> so I have no problem with v1 cgroup mount.
>>
>> Do you know where the genfs database is defined? I need some way to
>> add cgroup2
>> as a valid genfs fstype, or I have to manually back out the commit in
>> order to
>> do my cgroup2 testing.
> It is part of the policy; you could add it via a policy module ala:
> $ cat cgroup2.cil
> (genfscon cgroup2 / (system_u object_r cgroup_t ((s0) (s0))))
>
> $ sudo semodule -i cgroup2.cil
Thanks for the workaround. I will try that next time.
> That said, the fact that you can't even mount it without that is
> arguably a bug/regression. I guess this is due to the ENOENT from
> security_genfs_sid being propagated all the way up instead of just
> leaving it unlabeled and permitting the mount to proceed.
Yes, the mount command got the ENOENT error and it printed out some
confusing message.
Cheers,
Longman
prev parent reply other threads:[~2017-10-10 14:05 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-10-06 17:53 Waiman Long
2017-10-10 14:06 ` Stephen Smalley
2017-10-10 14:05 ` Waiman Long [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=89c4fc8c-1931-582c-a7f3-8aa2ef14c3c4@redhat.com \
--to=longman@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mgrepl@redhat.com \
--cc=paul@paul-moore.com \
--cc=runcom@redhat.com \
--cc=sds@tycho.nsa.gov \
--cc=selinux@tycho.nsa.gov \
--cc=tj@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®