RHEL 8.4 - No private unshared labels
Hi, I have a RHEL 8.4 box , totally updated, using the "container-tools" module (with the default rolling stream) and noticed that there's no distinction between creating a volume with "z" or "Z". If I use "Z" I never get a "private unshared label" in the corresponding folder (no MLS fields). Is this really not available in RHEL 8.4 or am I missing something? Thanks, Jorge
On 9/20/21 23:20, Jorge Fábregas wrote:
Hi,
I have a RHEL 8.4 box , totally updated, using the "container-tools" module (with the default rolling stream) and noticed that there's no distinction between creating a volume with "z" or "Z". If I use "Z" I never get a "private unshared label" in the corresponding folder (no MLS fields).
Is this really not available in RHEL 8.4 or am I missing something?
Thanks, Jorge _______________________________________________ Podman mailing list -- podman@lists.podman.io To unsubscribe send an email to podman-leave@lists.podman.io
Please show me an example. $ mkdir /tmp/foobar $ podman run -v /tmp/foobar:/tmp/foobar:Z ubi8 ls -Zd /tmp/foobar system_u:object_r:container_file_t:s0:c937,c994 /tmp/foobar $ podman run -v /tmp/foobar:/tmp/foobar:z ubi8 ls -Zd /tmp/foobar system_u:object_r:container_file_t:s0 /tmp/foobar
On 9/21/21 5:18 AM, Daniel Walsh wrote:
Please show me an example.
$ mkdir /tmp/foobar $ podman run -v /tmp/foobar:/tmp/foobar:Z ubi8 ls -Zd /tmp/foobar system_u:object_r:container_file_t:s0:c937,c994 /tmp/foobar $ podman run -v /tmp/foobar:/tmp/foobar:z ubi8 ls -Zd /tmp/foobar system_u:object_r:container_file_t:s0 /tmp/foobar
Hi Dan, Yes, that does work but it doesn't for named volumes. I forgot to mention that bit. Here are the tests on RHEL 8.4: # bind mounts https://ibb.co/jwYrSML # named volume https://ibb.co/1rQ2C10 If I do the last test on Fedora 33 it *does* creates the "private unshared label". HTH, Jorge
On 9/21/21 09:28, Jorge Fábregas wrote:
On 9/21/21 5:18 AM, Daniel Walsh wrote:
Please show me an example.
$ mkdir /tmp/foobar $ podman run -v /tmp/foobar:/tmp/foobar:Z ubi8 ls -Zd /tmp/foobar system_u:object_r:container_file_t:s0:c937,c994 /tmp/foobar $ podman run -v /tmp/foobar:/tmp/foobar:z ubi8 ls -Zd /tmp/foobar system_u:object_r:container_file_t:s0 /tmp/foobar Hi Dan,
Yes, that does work but it doesn't for named volumes. I forgot to mention that bit.
Here are the tests on RHEL 8.4:
# bind mounts https://ibb.co/jwYrSML
# named volume https://ibb.co/1rQ2C10
If I do the last test on Fedora 33 it *does* creates the "private unshared label".
HTH, Jorge _______________________________________________ Podman mailing list -- podman@lists.podman.io To unsubscribe send an email to podman-leave@lists.podman.io
Named volumes are expected to be shared and default to it.
On 9/21/21 10:50 AM, Daniel Walsh wrote:
What did you see before and what do you see now?
The point is that if you create a named-volume (with "Z") on RHEL 8.4 you don't get a private unshared label. If you do the same on Fedora 33 you *do get* a private unshared label. My question is: why the inconsistency? Thanks, Jorge
On 9/21/21 10:56, Jorge Fábregas wrote:
On 9/21/21 10:50 AM, Daniel Walsh wrote:
What did you see before and what do you see now? The point is that if you create a named-volume (with "Z") on RHEL 8.4 you don't get a private unshared label.
If you do the same on Fedora 33 you *do get* a private unshared label.
My question is: why the inconsistency?
Thanks, Jorge _______________________________________________ Podman mailing list -- podman@lists.podman.io To unsubscribe send an email to podman-leave@lists.podman.io
Not sure, must have fixed an issue and this got removed. I am still debating in my head whether or not the :Z should be accepted.
On 9/21/21 2:05 PM, Daniel Walsh wrote:
Not sure, must have fixed an issue and this got removed. I am still debating in my head whether or not the :Z should be accepted.
I see. For me, the user should be in control and if he chooses to use upper-case "z" then let it be; no matter if it's a bind-mount or a named volume ...as it is currently on Fedora. Thanks. My 2 cents! Jorge
On 9/21/21 14:45, Jorge Fábregas wrote:
On 9/21/21 2:05 PM, Daniel Walsh wrote:
Not sure, must have fixed an issue and this got removed. I am still debating in my head whether or not the :Z should be accepted. I see. For me, the user should be in control and if he chooses to use upper-case "z" then let it be; no matter if it's a bind-mount or a named volume ...as it is currently on Fedora.
Thanks.
My 2 cents! Jorge _______________________________________________ Podman mailing list -- podman@lists.podman.io To unsubscribe send an email to podman-leave@lists.podman.io
Sure, the default right now is "z". Open an issue on this, and I am sure we can make it happen, or even better open a PR to allow it.
participants (2)
-
Daniel Walsh -
Jorge Fábregas