Skip to content

We should only be relabeling when on first run - #11959

Merged
openshift-merge-robot merged 1 commit into
podman-container-tools:mainfrom
rhatdan:selinux
Oct 18, 2021
Merged

We should only be relabeling when on first run#11959
openshift-merge-robot merged 1 commit into
podman-container-tools:mainfrom
rhatdan:selinux

Conversation

@rhatdan

@rhatdan rhatdan commented Oct 13, 2021

Copy link
Copy Markdown
Contributor

On the second runs, the labels should be the same so no
need to relabel.

Fixes: https://bugzilla.redhat.com/show_bug.cgi?id=2013548

Signed-off-by: Daniel J Walsh dwalsh@redhat.com

What this PR does / why we need it:

How to verify it

Which issue(s) this PR fixes:

Special notes for your reviewer:

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Oct 13, 2021
Comment thread test/system/410-selinux.bats Outdated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you add a test for the chown change too? It would be nice to have a note in the description about that change.

@Luap99

Luap99 commented Oct 14, 2021

Copy link
Copy Markdown
Member

Can you explain how this fixes the linked issue. The issue is talking about random failures during relabel. AFAIK you are allowed to relabel more than once.
This change could also cause problems for people mounting a directory on a tmpfs. After a reboot the container start will not relabel it. Would the correct fix be to look at the the current label and only relabel if it is different?

@rhatdan

rhatdan commented Oct 14, 2021

Copy link
Copy Markdown
Contributor Author

Good point on the tmpfs, as far as the linked message, it would at least make it less likely. I believe the linked issue is most likely a problem in Ceph file system not in Podman at all.

The main advantage of this fix is if a directory had a massive amount of files, the relabel will no longer be done.

@rhatdan

rhatdan commented Oct 14, 2021

Copy link
Copy Markdown
Contributor Author

Top level directory is now checked to make sure it matches the UID, before chowning and checks the label before relabeling.

@Luap99 Luap99 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@rhatdan
rhatdan force-pushed the selinux branch 3 times, most recently from 089edb3 to 5bb19ea Compare October 14, 2021 17:49
On the second runs, the labels should be the same so no
need to relabel.

Fixes: https://bugzilla.redhat.com/show_bug.cgi?id=2013548

Signed-off-by: Daniel J Walsh <dwalsh@redhat.com>
@flouthoc

Copy link
Copy Markdown
Contributor

/approve
/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Oct 18, 2021
@openshift-ci

openshift-ci Bot commented Oct 18, 2021

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: flouthoc, rhatdan

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-robot
openshift-merge-robot merged commit e0ffc43 into podman-container-tools:main Oct 18, 2021
@github-actions github-actions Bot added the locked - please file new issue/PR Assist humans wanting to comment on an old issue or PR with locked comments. label Sep 22, 2023
@github-actions github-actions Bot locked as resolved and limited conversation to collaborators Sep 22, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. locked - please file new issue/PR Assist humans wanting to comment on an old issue or PR with locked comments.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants