Actions
Bug #30465
closedPulpcore services run unconfined in SELinux
Status:
Closed
Priority:
Normal
Assignee:
Category:
Foreman modules
Target version:
Difficulty:
Triaged:
Yes
Description
Currently the services run unconfined because pulpcore-selinux only labels /usr/{local,lib/pulp}/bin/{gunicorn,rq} but RPM packages install to /usr/bin/{gunicorn,rq}. Labelling those with pulpcore_exec_t feels incorrect so I'm suggesting to introduce /usr/libexec/pulpcore/{gunicorn,rq} wrappers with the correct SELinux labels.
Updated by The Foreman Bot over 4 years ago
- Status changed from New to Ready For Testing
- Assignee set to Ewoud Kohl van Wijngaarden
- Pull request https://github.com/theforeman/puppet-pulpcore/pull/116 added
Updated by Ewoud Kohl van Wijngaarden over 4 years ago
- Target version set to 2.2.0
- Triaged changed from No to Yes
Updated by Eric Helms over 4 years ago
- Target version changed from 2.2.0 to 2.3.0
Updated by Ewoud Kohl van Wijngaarden about 4 years ago
- Status changed from Ready For Testing to Closed
Applied in changeset puppet-pulpcore|d9eec934b5ee278128b00f87479c9f5ea7fc08f5.
Actions