d1681e
From c90038f9a3e01d07f1e797c613b0863a43e06d35 Mon Sep 17 00:00:00 2001
d1681e
From: "Kaleb S. KEITHLEY" <kkeithle@redhat.com>
d1681e
Date: Mon, 17 Jul 2017 11:07:40 -0400
d1681e
Subject: [PATCH 68/74] common-ha: enable and disable selinux
d1681e
 gluster_use_execmem
d1681e
d1681e
Starting in Fedora 26 and RHEL 7.4 there are new targeted policies in
d1681e
selinux which include a tuneable to allow glusterd->ganesha-ha.sh->pcs
d1681e
to access the pcs config, i.e. gluster-use-execmem.
d1681e
d1681e
Note. rpm doesn't have a way to distinguish between RHEL 7.3 or 7.4
d1681e
or between 3.13.1-X and 3.13.1-Y so it can't be enabled for RHEL at
d1681e
this time.
d1681e
d1681e
/usr/sbin/semanage is in policycoreutils-python in RHEL (versus
d1681e
policycoreutils-python-utils in Fedora.)
d1681e
d1681e
Requires selinux-policy >= 3.13.1-160 in RHEL7. The corresponding
d1681e
version in Fedora 26 seems to be selinux-policy-3.13.1-259 or so. (Maybe
d1681e
earlier versions, but that's what was in F26 when I checked.)
d1681e
d1681e
Change-Id: Ic474b3f7739ff5be1e99d94d00b55caae4ceb5a0
d1681e
Signed-off-by: Kaleb S. KEITHLEY <kkeithle@redhat.com>
d1681e
Reviewed-on: https://review.gluster.org/17806
d1681e
Smoke: Gluster Build System <jenkins@build.gluster.org>
d1681e
CentOS-regression: Gluster Build System <jenkins@build.gluster.org>
d1681e
Reviewed-by: soumya k <skoduri@redhat.com>
d1681e
Reviewed-by: Atin Mukherjee <amukherj@redhat.com>
d1681e
---
d1681e
 extras/ganesha/scripts/ganesha-ha.sh | 6 ++++++
d1681e
 1 file changed, 6 insertions(+)
d1681e
d1681e
diff --git a/extras/ganesha/scripts/ganesha-ha.sh b/extras/ganesha/scripts/ganesha-ha.sh
d1681e
index ce5ff20..0b7642d 100644
d1681e
--- a/extras/ganesha/scripts/ganesha-ha.sh
d1681e
+++ b/extras/ganesha/scripts/ganesha-ha.sh
d1681e
@@ -984,6 +984,9 @@ main()
d1681e
         usage
d1681e
         exit 0
d1681e
     fi
d1681e
+
d1681e
+    semanage boolean -m gluster_use_execmem --on
d1681e
+
d1681e
     HA_CONFDIR=${1%/}; shift
d1681e
     local ha_conf=${HA_CONFDIR}/ganesha-ha.conf
d1681e
     local node=""
d1681e
@@ -1129,6 +1132,9 @@ $HA_CONFDIR/ganesha-ha.conf
d1681e
         ;;
d1681e
 
d1681e
     esac
d1681e
+
d1681e
+    semanage boolean -m gluster_use_execmem --off
d1681e
+
d1681e
 }
d1681e
 
d1681e
 main $*
d1681e
-- 
d1681e
1.8.3.1
d1681e