Bug 520983
Summary: | setroubleshoot: SELinux is preventing access to files with the label, file_t. | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | David <idht4n> |
Component: | selinux-policy | Assignee: | Daniel Walsh <dwalsh> |
Status: | CLOSED NOTABUG | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | medium | Docs Contact: | |
Priority: | low | ||
Version: | rawhide | CC: | dwalsh, jkubin, mgrepl |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | i386 | ||
OS: | Linux | ||
Whiteboard: | setroubleshoot_trace_hash:931909fbc5578d79eed3431bdef88dc5c2d225808fb2829f58466afce5160cfd | ||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2009-09-04 13:45:47 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
David
2009-09-03 01:50:22 UTC
Did you try what setroubleshoot suggests touch /.autorelabel; reboot No... I was told on the fedora-test-list to report all problems:
Adam Williamson wrote:
> The SELinux stuff now makes it extremely easy to report problems; you
> can do it just with one click on a button in sealert. Please do this for
> all SELinux alerts you see, rather than filtering through this list
> first, we want to get _all_ the reports you see. The SELinux maintainers
> are very fast about looking at reports and taking appropriate action.
So I did. Many of the warnings were after a fresh install of fedora 12
alpha, so I figured any warnings were bugs. I'll try autorelabel now.
I did the touch /.autorelabel. Not sure if it worked, because the computer became unresponsive after reboot (black screen, control alt delete did nothing... hit the power button after ~15 minutes). Still getting selinux warnings but I don't know if I've seen this one. As root execute fixfiles restore You chould see a hole bunch of "*" start to appear, Each one represents 1000 files being relabeled. It will read your entire file system and fix the labels. This could take a long time, depending on the amount of files. When it is complete, you should be able to reboot and no longer have AVC messages about file_t. |