Skip to content

Conversation

@ca-hu
Copy link
Contributor

@ca-hu ca-hu commented Nov 14, 2025

/usr/lib/drbd/crm-fence-peer.9.sh is labelled drbd_exec_t, however the domain lands in kernel_generic_helper_t as it is not allowed to transition from kernel_t to drbd_t.

Additionally, when the domtrans succeeds, crm-fence-peer.9.sh will create entries in /proc with drbd_t label, so allowing that.

/usr/lib/drbd/crm-fence-peer.9.sh is labelled drbd_exec_t, however
the domain lands in kernel_generic_helper_t as it is not allowed
to transition from kernel_t to drbd_t.

Additionally, when the domtrans succeeds, crm-fence-peer.9.sh
will create entries in /proc with drbd_t label, so allowing that.
@rck
Copy link
Member

rck commented Nov 24, 2025

just a quick heads up: sorry this took a bit longer, we are looking into it right now

@rck rck self-assigned this Nov 24, 2025
@rck rck merged commit 1fa1bc0 into LINBIT:master Nov 25, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants