>>>>> "UM" == Uwe Menges <uwe.men...@web.de> writes:

UM> I filed https://bugzilla.redhat.com/show_bug.cgi?id=1280526 but I
UM> don't know if this is really the same cause.

Sadly that one got closed because the release was never updated to
something newer than Fedora 22.  I suspect it's still a problem.

I'll make a note in that ticket but basically if you want to use tar for
backups you have to somewhat abandon the concept of confining amanda
since it's going to have to be able to read essentially any file on the
file system.

Personally I use xfsdump for my backups, but of course that runs into
its own selinux issues.  My reccommendation is to switch just the amanda
domain to permissive:

# semanage permissive -a amanda_t

Then you can at least contain other things on your system.  I imagine
that properly fixing this would require some rather intrusive changes to
the policy to (optionally, controlled by a boolean) allow amanda_t read
access to pretty much every type.

 - J<

Reply via email to