All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH][meta-networking] iscsi-initiator-utils: fix SELinux label for initiatorname.iscsi
@ 2015-02-04  9:33 wenzong.fan
  2015-02-12  2:17 ` Joe MacDonald
  0 siblings, 1 reply; 5+ messages in thread
From: wenzong.fan @ 2015-02-04  9:33 UTC (permalink / raw)
  To: openembedded-devel

From: Wenzong Fan <wenzong.fan@windriver.com>

* /etc/iscsi/initiatorname.iscsi: etc_runtime_t -> etc_t

This config file was created by postinstall or initscript, fix SELinux
label for it to remove:

  avc: denied { read } for pid=6094 comm="iscsid" \
  name="initiatorname.iscsi" dev="sda3" ino=1057846 \
  scontext=system_u:system_r:iscsid_t:s0-s15:c0.c1023 \
  tcontext=system_u:object_r:etc_runtime_t:s0 tclass=file

Signed-off-by: Wenzong Fan <wenzong.fan@windriver.com>
---
 .../recipes-daemons/iscsi-initiator-utils/files/initd.debian          | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/meta-networking/recipes-daemons/iscsi-initiator-utils/files/initd.debian b/meta-networking/recipes-daemons/iscsi-initiator-utils/files/initd.debian
index 99a7638..43fb348 100644
--- a/meta-networking/recipes-daemons/iscsi-initiator-utils/files/initd.debian
+++ b/meta-networking/recipes-daemons/iscsi-initiator-utils/files/initd.debian
@@ -39,6 +39,10 @@ start() {
 InitiatorName=$INITIATORNAME
 EOF
 	fi
+
+	# Fix label for /etc/iscsi/initiatorname.iscsi if SELinux was enabled
+	test ! -x /sbin/restorecon || /sbin/restorecon -F /etc/iscsi/initiatorname.iscsi
+
 	start-stop-daemon --start --quiet --pidfile $PIDFILE --exec $DAEMON
 	RETVAL=$?
 	starttargets
-- 
1.9.1



^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2015-03-05  7:57 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-02-04  9:33 [PATCH][meta-networking] iscsi-initiator-utils: fix SELinux label for initiatorname.iscsi wenzong.fan
2015-02-12  2:17 ` Joe MacDonald
2015-03-04  7:25   ` wenzong fan
2015-03-04 13:39     ` Joe MacDonald
2015-03-05  7:57       ` wenzong fan

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.