Drop the SELinux flags for openvswitch /var/run directory
Enforcing re-labelling (:z) creates some issues when we are deploying
with DPDK.
A new SELinux policy has been added[1] in openstack-selinux, allowing
container_t to actually write in openvswitch_file_t.
The "shared" flag isn't of any use in this context, because we don't
have any sub-mounts[2] in there.
Reviewed: https:/ /review. opendev. org/695903 /git.openstack. org/cgit/ openstack/ tripleo- heat-templates/ commit/ ?id=af80a0d914d 9663079ad30c7dc df73e1060c33e7
Committed: https:/
Submitter: Zuul
Branch: master
commit af80a0d914d9663 079ad30c7dcdf73 e1060c33e7
Author: Cédric Jeanneret <email address hidden>
Date: Mon Nov 25 14:43:25 2019 +0100
Drop the SELinux flags for openvswitch /var/run directory
Enforcing re-labelling (:z) creates some issues when we are deploying
with DPDK.
A new SELinux policy has been added[1] in openstack-selinux, allowing
container_t to actually write in openvswitch_file_t.
The "shared" flag isn't of any use in this context, because we don't
have any sub-mounts[2] in there.
Also dropped a duplicate mount (/var/run == /run)
This issue is related to the following BZ: /bugzilla. redhat. com/show_ bug.cgi? id=1772025 /bugzilla. redhat. com/show_ bug.cgi? id=1776326
https:/
https:/
[1] https:/ /github. com/redhat- openstack/ openstack- selinux/ pull/46 /docs.docker. com/storage/ bind-mounts/ #configure- bind-propagatio n
[2] https:/
Change-Id: I216d7899c56941 9fdee7e30cc11af 1d68d0f7fa3
Closes-Bug: #1853844