From owner-freebsd-security@FreeBSD.ORG Mon Feb 9 10:25:14 2009 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id B8926106564A; Mon, 9 Feb 2009 10:25:14 +0000 (UTC) (envelope-from BORJAMAR@SARENET.ES) Received: from proxypop2.sarenet.es (proxypop2.sarenet.es [194.30.0.95]) by mx1.freebsd.org (Postfix) with ESMTP id 790318FC13; Mon, 9 Feb 2009 10:25:14 +0000 (UTC) (envelope-from BORJAMAR@SARENET.ES) Received: from [127.0.0.1] (matahari.sarenet.es [192.148.167.18]) by proxypop2.sarenet.es (Postfix) with ESMTP id D13D073408; Mon, 9 Feb 2009 11:25:12 +0100 (CET) Message-Id: <5CFEFF94-39B2-4CB6-9797-1F6B9EF73D41@SARENET.ES> From: Borja Marcos To: Robert Watson In-Reply-To: Content-Type: text/plain; charset=US-ASCII; format=flowed; delsp=yes Content-Transfer-Encoding: 7bit Mime-Version: 1.0 (Apple Message framework v930.3) Date: Mon, 9 Feb 2009 11:25:09 +0100 References: <5F581D71-E6BF-487D-91F0-67EA6A21BA6E@SARENET.ES> X-Mailer: Apple Mail (2.930.3) Cc: freebsd-security@freebsd.org Subject: Re: MAC subsystem and ZFS? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 09 Feb 2009 10:25:15 -0000 On Feb 7, 2009, at 11:21 PM, Robert Watson wrote: >> I'm trying to upgrade the configuration of some web services, >> already using the MAC subsystem, to use ZFS instead of UFS, but I >> see that ZFS doesn't support MAC labels, even for a whole >> filesystem, which would be fine for me, I don't need multilabel >> support. >> >> Any ideas? Have I missed anything? > > Hmmm. Sounds like a bug -- all file systems should be able to > operate in single-label mode, even if they don't support EAs and > multilabel mode. Could you describe the symptoms you're > experiencing in a bit more detail? Indeed I can :) Sorry for the delay, a human nose-irritating virus, for which no known AV software exists, apart from patience, has kept me a bit parked this weekend :) I can read the MAC label from a ZFS dataset, but cannot change it. Example follows: # zfs create pool/test (indeed I can read the default label applied when creating it) # getfmac pool/test pool/test: biba/high,mls/low (but I cannot change it) # setfmac biba/equal,mls/equal /pool/test setfmac: labeling not supported in /pool/test (just in case it's a confusion because of being under "/pool", I try changing the mountpoint, still no success) # mkdir /testing # zfs set mountpoint=/testing pool/test # setfmac biba/equal,mls/equal /testing setfmac: labeling not supported in /testing This is a 7.1.RELEASE-p2 system. Thank you very much, Borja.