]> git.ipfire.org Git - thirdparty/systemd.git/commit
core/namespace: relabel bind mount source based on the target path
authorMichal Sekletar <msekleta@redhat.com>
Tue, 21 Jan 2025 14:31:14 +0000 (15:31 +0100)
committerLennart Poettering <lennart@poettering.net>
Fri, 7 Feb 2025 11:24:31 +0000 (12:24 +0100)
commita128273f7b5e50ce5929ccabda5c2810b7eedd2d
treee35621c589315b7faae027a96270a80548df20d2
parentbe4f4c4343f05f2b53deb326c241c6031c36c911
core/namespace: relabel bind mount source based on the target path

Some bind mounts, e.g. /tmp bind mount when PrivateTmp=disconnected,
must be explicitly relabeled because now it would have incorrect SELinux
label. /tmp is expected to have well-known SELinux label, tmp_t. Now it
has label inherited from the source directory of the bind mount.
src/core/namespace.c