Project

General

Profile

Actions

Bug #30465

closed

Pulpcore services run unconfined in SELinux

Added by Ewoud Kohl van Wijngaarden over 3 years ago. Updated over 3 years ago.

Status:
Closed
Priority:
Normal
Category:
Foreman modules
Target version:
Difficulty:
Triaged:
Yes
Fixed in Releases:
Found in Releases:

Description

Currently the services run unconfined because pulpcore-selinux only labels /usr/{local,lib/pulp}/bin/{gunicorn,rq} but RPM packages install to /usr/bin/{gunicorn,rq}. Labelling those with pulpcore_exec_t feels incorrect so I'm suggesting to introduce /usr/libexec/pulpcore/{gunicorn,rq} wrappers with the correct SELinux labels.

Actions #1

Updated by The Foreman Bot over 3 years ago

  • Status changed from New to Ready For Testing
  • Assignee set to Ewoud Kohl van Wijngaarden
  • Pull request https://github.com/theforeman/puppet-pulpcore/pull/116 added
Actions #2

Updated by Ewoud Kohl van Wijngaarden over 3 years ago

  • Target version set to 2.2.0
  • Triaged changed from No to Yes
Actions #3

Updated by Eric Helms over 3 years ago

  • Target version changed from 2.2.0 to 2.3.0
Actions #4

Updated by Ewoud Kohl van Wijngaarden over 3 years ago

  • Status changed from Ready For Testing to Closed
Actions #5

Updated by Tomer Brisker over 3 years ago

  • Fixed in Releases 2.3.0 added
Actions

Also available in: Atom PDF