All of lore.kernel.org
 help / color / mirror / Atom feed
From: Vivek Goyal <vgoyal@redhat.com>
To: Ondrej Mosnacek <omosnace@redhat.com>
Cc: Paul Moore <paul@paul-moore.com>,
	James Carter <jwcart2@gmail.com>,
	SElinux list <selinux@vger.kernel.org>,
	Stephen Smalley <stephen.smalley.work@gmail.com>,
	Daniel Walsh <dwalsh@redhat.com>,
	Zdenek Pytela <zpytela@redhat.com>
Subject: Re: virtiofs and its optional xattr support vs. fs_use_xattr
Date: Tue, 5 Jan 2021 09:21:48 -0500	[thread overview]
Message-ID: <20210105142148.GA3200@redhat.com> (raw)
In-Reply-To: <CAFqZXNtSbFBPCTu+aOUt7JKaR_Gk1kAJ0ewgV1Ds8HhpyfafQg@mail.gmail.com>

On Tue, Jan 05, 2021 at 03:00:31PM +0100, Ondrej Mosnacek wrote:

[..]
> > > > > > > Okay, so I'll look into switching between use_xattr and use_genfs
> > > > > > > based on the availability of xattr support and the presence of
> > > > > > > corresponding rules in the policy. Thanks everyone for the fruitful
> > > > > > > discussion!
> > > > > >
> > > > > > Hi Ondrej,
> > > > > >
> > > > > > So this is now purely a policy change and no changes required in kernel?
> > > > > > If yes, then the patch Dan Walsh proposed, is that good enough or
> > > > > > it needs to be done in a different way.
> > > > >
> > > > > No, this needs a kernel change in SELinux to interpret the policy
> > > > > rules slightly differently *and* basically Dan's patch (modulo the
> > > > > typo in the genfscon keyword).
> > > >
> > > > Ok, thanks. Is this kernel change something you will be able to take
> > > > care of. I am afraid that I don't know enough to make this change.
> > >
> > > Yes, it's already on my todo list ;) But it might take some time as
> > > there are a lot of things competing for my attention right now...
> >
> > Hi Ondrej,
> >
> > Sorry to bother you on this. Just curious, if you got a chance to make
> > progress on this. Will like to solve the issue of SELinux blocking package
> > installation on virtiofs in VM based containers.
> 
> Hi,
> 
> I had a go at it today and I already have a tentative patch. So far
> it's passing my initial testing so I should be able to post it to the
> list soon.

Awesome. Looking forward to the final patch.

Vivek


      reply	other threads:[~2021-01-05 14:23 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-12-07 14:42 virtiofs and its optional xattr support vs. fs_use_xattr Ondrej Mosnacek
2020-12-07 15:03 ` Paul Moore
2020-12-07 20:52   ` Vivek Goyal
2020-12-07 20:52     ` [Virtio-fs] " Vivek Goyal
2020-12-07 21:06     ` Harry G. Coin
2020-12-07 21:22     ` Dominick Grift
2020-12-07 21:22       ` [Virtio-fs] " Dominick Grift
2020-12-08 14:33       ` Vivek Goyal
2020-12-08 14:33         ` [Virtio-fs] " Vivek Goyal
2020-12-08 15:13         ` Dominick Grift
2020-12-08 15:13           ` [Virtio-fs] " Dominick Grift
2020-12-08 23:41     ` Paul Moore
2020-12-08 23:41       ` [Virtio-fs] " Paul Moore
2020-12-07 17:17 ` James Carter
2020-12-08 23:45   ` Paul Moore
2020-12-09 15:37     ` James Carter
2020-12-10  2:39       ` Paul Moore
2020-12-10  9:29         ` Ondrej Mosnacek
2020-12-10 22:17           ` Vivek Goyal
2020-12-10 22:24             ` Ondrej Mosnacek
2020-12-10 22:30               ` Vivek Goyal
2020-12-11  9:15                 ` Ondrej Mosnacek
2020-12-11 13:29                   ` Vivek Goyal
2021-01-04 20:14                   ` Vivek Goyal
2021-01-05 14:00                     ` Ondrej Mosnacek
2021-01-05 14:21                       ` Vivek Goyal [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20210105142148.GA3200@redhat.com \
    --to=vgoyal@redhat.com \
    --cc=dwalsh@redhat.com \
    --cc=jwcart2@gmail.com \
    --cc=omosnace@redhat.com \
    --cc=paul@paul-moore.com \
    --cc=selinux@vger.kernel.org \
    --cc=stephen.smalley.work@gmail.com \
    --cc=zpytela@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.