From: wenzong fan <wenzong.fan@windriver.com>
To: Joe MacDonald <Joe_MacDonald@mentor.com>
Cc: openembedded-devel@lists.openembedded.org
Subject: Re: [PATCH][meta-networking] iscsi-initiator-utils: fix SELinux label for initiatorname.iscsi
Date: Wed, 4 Mar 2015 15:25:48 +0800 [thread overview]
Message-ID: <54F6B37C.6040706@windriver.com> (raw)
In-Reply-To: <20150212021749.GK30457@mentor.com>
On 02/12/2015 10:17 AM, Joe MacDonald wrote:
> Hey Wenzong,
>
> [[oe] [PATCH][meta-networking] iscsi-initiator-utils: fix SELinux label for initiatorname.iscsi] On 15.02.04 (Wed 17:33) wenzong.fan@windriver.com wrote:
>
>> From: Wenzong Fan <wenzong.fan@windriver.com>
>>
>> * /etc/iscsi/initiatorname.iscsi: etc_runtime_t -> etc_t
>>
>> This config file was created by postinstall or initscript, fix SELinux
>> label for it to remove:
>>
>> avc: denied { read } for pid=6094 comm="iscsid" \
>> name="initiatorname.iscsi" dev="sda3" ino=1057846 \
>> scontext=system_u:system_r:iscsid_t:s0-s15:c0.c1023 \
>> tcontext=system_u:object_r:etc_runtime_t:s0 tclass=file
>
> Since this is an issue that only shows up when you have SELinux on your
> system and since it is tweaking a file that is manually installed by a
> do_install() in iscsi-initiator-utils, could you re-work this as a
> bbappend in meta-selinux?
Hi Joe,
This make sense, but there's an issue that meta-networking is not
depended by meta-selinux, adding a bbappend may block the building of
meta-selinux & oe-core only.
Any suggestions about that?
Thanks
Wenzong
>
> -J.
>
>>
>> Signed-off-by: Wenzong Fan <wenzong.fan@windriver.com>
>> ---
>> .../recipes-daemons/iscsi-initiator-utils/files/initd.debian | 4 ++++
>> 1 file changed, 4 insertions(+)
>>
>> diff --git a/meta-networking/recipes-daemons/iscsi-initiator-utils/files/initd.debian b/meta-networking/recipes-daemons/iscsi-initiator-utils/files/initd.debian
>> index 99a7638..43fb348 100644
>> --- a/meta-networking/recipes-daemons/iscsi-initiator-utils/files/initd.debian
>> +++ b/meta-networking/recipes-daemons/iscsi-initiator-utils/files/initd.debian
>> @@ -39,6 +39,10 @@ start() {
>> InitiatorName=$INITIATORNAME
>> EOF
>> fi
>> +
>> + # Fix label for /etc/iscsi/initiatorname.iscsi if SELinux was enabled
>> + test ! -x /sbin/restorecon || /sbin/restorecon -F /etc/iscsi/initiatorname.iscsi
>> +
>> start-stop-daemon --start --quiet --pidfile $PIDFILE --exec $DAEMON
>> RETVAL=$?
>> starttargets
>> --
>> 1.9.1
>>
next prev parent reply other threads:[~2015-03-04 7:25 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-02-04 9:33 [PATCH][meta-networking] iscsi-initiator-utils: fix SELinux label for initiatorname.iscsi wenzong.fan
2015-02-12 2:17 ` Joe MacDonald
2015-03-04 7:25 ` wenzong fan [this message]
2015-03-04 13:39 ` Joe MacDonald
2015-03-05 7:57 ` wenzong fan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=54F6B37C.6040706@windriver.com \
--to=wenzong.fan@windriver.com \
--cc=Joe_MacDonald@mentor.com \
--cc=openembedded-devel@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox