Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-27503

Remove `PrivateUsers` directive from the nm-cloud-setup systemd unit

    • NetworkManager-1.46.0-3.el9_4
    • Major
    • sst_network_management
    • ssg_networking
    • 2
    • False
    • Hide

      None

      Show
      None
    • No
    • NMT - RHEL-9.5 DTM 4
    • Approved Exception
    • Hide

      Given the RHEL 9.4 NM package

      When looking at the nm-cloud-setup system unit

      Then it does not contain PrivateUsers=yes

       

      Given a RHEL 9.4 system

      When running the task from the other peoples CI

      Then there are no selinux denials.

       

      Definition of Done:

      • The implementation meets the acceptance criteria
      • The change is part of RHEL-9.4 NetworkManager downstream build
      • Scratch build is created and tested there are no more selinux denials
      Show
      Given the RHEL 9.4 NM package When looking at the nm-cloud-setup system unit Then it does not contain PrivateUsers=yes   Given a RHEL 9.4 system When running the task from the other peoples CI Then there are no selinux denials.   Definition of Done: The implementation meets the acceptance criteria The change is part of RHEL-9.4 NetworkManager downstream build Scratch build is created and tested there are no more selinux denials
    • Pass

      Nm-cloud-setup systemd unit was changed to include PrivateUsers=yes, and this makes the process start in a different user namespace: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/6fb4af730012441adbbc99e87ae137195d7109a5

      This change is causing the avc denial described in RHEL-24346 and as this is a blocker for osbuild-composer testing on AWS on RHEL-9.4, we need to remove the PrivateUsers=yes directive in downstream. selinux team will then allow the permission in selinux-policy during RHEL 9.5 development cycle.

            ferferna Fernando Fernandez Mancera
            rh-ee-sfaye Stanislas Faye
            Fernando Fernandez Mancera Fernando Fernandez Mancera
            Vladimir Benes Vladimir Benes
            Votes:
            0 Vote for this issue
            Watchers:
            10 Start watching this issue

              Created:
              Updated:
              Resolved: