Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-34205

Unknown toplevel directories are labeled default_t

    • None
    • None
    • rhel-sst-bootc
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None

      Creating arbitrary new toplevel directories (e.g. `/app` or `aimodel`) will result in the default SELinux label `default_t`. Most domains are denied access to this.

      We should either:

      • Change the SELinux policy to make the generic fallback case be usr_t
      • We could do just this in the bootc container stack (perhaps preferable to start); but implementing that is a bit ugly

              walters@redhat.com Colin Walters
              walters@redhat.com Colin Walters
              Colin Walters Colin Walters
              Wei Shi Wei Shi
              Gabriela Necasova Gabriela Necasova
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated: