From a6b04352b72e38744ddf3395bf15232e5e7e7393 Mon Sep 17 00:00:00 2001 From: Olaf Hering Date: Fri, 19 Dec 2014 12:25:27 +0100 Subject: [PATCH] tools/hotplug: remove SELinux options from var-lib-xenstored.mount Using SELinux mount options per default breaks several systems. Either the context= mount option is not known at all to the kernel, as reported for ArchLinux. Or the default value "none" is unknown to SELinux, as reported for Fedora. In both cases the unit will fail. The proper place to specify mount options is /etc/fstab. Apparently systemd is kind enough to use values from there even if Options= or What= is specified in a .mount file. Remove XENSTORED_MOUNT_CTX, the reference to a non-existent EnvironmentFile and trim default Options= for the mount point. The removed code was first mentioned in the patch referenced below, with the following description: ... * Some systems define the selinux context in the systemd Option for the /var/lib/xenstored tmpfs: Options=mode=755,context="system_u:object_r:xenstored_var_lib_t:s0" For the upstream version we remove that and let systems specify the context on their system /etc/default/xenstored or /etc/sysconfig/xenstored $XENSTORED_MOUNT_CTX variable ... It is nowhere stated (on xen-devel) what "Some systems" means, which is unfortunately common practice in nearly all opensource projects. http://lists.xenproject.org/archives/html/xen-devel/2014-03/msg02462.html Signed-off-by: Olaf Hering Acked-by: Ian Jackson Cc: Stefano Stabellini Acked-by: Ian Campbell Cc: Wei Liu Cc: Anthony PERARD Cc: M A Young Cc: Luis R. Rodriguez Release-Acked-by: Konrad Rzeszutek Wilk Signed-off-by: Konrad Rzeszutek Wilk --- tools/hotplug/Linux/systemd/var-lib-xenstored.mount.in | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/tools/hotplug/Linux/systemd/var-lib-xenstored.mount.in b/tools/hotplug/Linux/systemd/var-lib-xenstored.mount.in index d5e04db03d..11a7d50edc 100644 --- a/tools/hotplug/Linux/systemd/var-lib-xenstored.mount.in +++ b/tools/hotplug/Linux/systemd/var-lib-xenstored.mount.in @@ -6,9 +6,7 @@ ConditionPathExists=/proc/xen/capabilities RefuseManualStop=true [Mount] -Environment=XENSTORED_MOUNT_CTX=none -EnvironmentFile=-@CONFIG_DIR@/@CONFIG_LEAF_DIR@/xenstored What=xenstore Where=@XEN_LIB_STORED@ Type=tmpfs -Options=mode=755,context="$XENSTORED_MOUNT_CTX" +Options=mode=755 -- 2.30.2