Bug 437211

Summary: gdm /tmp files relabel failure
Product: [Fedora] Fedora Reporter: Warren Togami <wtogami>
Component: selinux-policy-targetedAssignee: Daniel Walsh <dwalsh>
Status: CLOSED RAWHIDE QA Contact: Ben Levenson <benl>
Severity: low Docs Contact:
Priority: low    
Version: rawhide   
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2008-05-07 15:25:15 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Warren Togami 2008-03-12 21:56:20 UTC
selinux-policy-3.3.1-16.fc9.noarch
gdm-2.21.9-3.fc9.i386

1) Boot with selinux=0
2) Login with gdm to a desktop
3) Reboot
4) Boot with selinux=0 and enforcing
5) gdm fails!  You can't login!

Workaround
1) Erase everything in /tmp
2) Restart gdm

Could this possibly be fixed with selinux-policy?

Sorry I don't know exactly what caused this failure.

Comment 1 Dominick Grift 2008-03-13 09:41:28 UTC
Traditionally the file contexts have explicitely excluded relabelling anything
under /tmp. The reason for this is that if some highly classified data is in a
file in /tmp it would not be appropriate to relabel it to a default label (of
which incidentally there really isn't one for strict or MLS policies and even
for targeted there is no single label that works in all situations). So a
"fixfiles relabel" operation will offer to remove all files under /tmp



Comment 2 Colin Walters 2008-03-13 13:28:04 UTC
A default per-user /tmp would solve this.




Comment 3 Daniel Walsh 2008-03-13 22:07:06 UTC
Relabeling everything used to delete all the files in /tmp, which would fix the
problem and cause gdm to recreate the files on start.  But this was removed
since it was considered to destructive.

Comment 4 Daniel Walsh 2008-05-07 15:25:15 UTC
Added 
+    	rm -rf /tmp/gconfd-* /tmp/pulse-* /tmp/orbit-*
to fixfiles on autorelabel

policycoreutils-2.0.47-2