Bug 711710

Summary: Rawhide\16 boot avcs selinux-policy-3.9.16-26.fc16
Product: [Fedora] Fedora Reporter: Frank Murphy <frankly3d>
Component: selinux-policyAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED NOTABUG QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: rawhideCC: dominick.grift, dwalsh, mgrepl
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-06-09 13:07:49 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Attachments:
Description Flags
Seriel Console Output
none
Seriel Console Output none

Description Frank Murphy 2011-06-08 09:04:27 UTC
Created attachment 503646 [details]
Seriel Console Output

Description of problem: boot avcs


Version-Release number of selected component (if applicable):
selinux-policy-3.9.16-26.fc16
selinux-policy-targeted-3.9.16-26.fc16

How reproducible: always since upgrade


Steps to Reproduce:
1. kernel-3*rc2
2. update latest rawhide updates
3.
  
Actual results: no boot


Expected results: boot


Additional info: Uncertain if systemd causes this, or this causes systemd problems.

Comment 1 Frank Murphy 2011-06-08 09:23:43 UTC
Created attachment 503653 [details]
Seriel Console Output

Comment 2 Frank Murphy 2011-06-09 07:38:43 UTC
This morning updates to systemd* selinux* libsemanage* still the same result.

Comment 3 Dominick Grift 2011-06-09 10:42:47 UTC
looks like you may need to relabel the filesystem. You have some unlabeled object in etc/.*

I was able this morning to boot (and shutdown):

$ uname -a
Linux localhost.localdomain 3.0-0.rc2.git0.1.fc16.x86_64 #1 SMP Wed Jun 8 05:44:30 UTC 2011 x86_64 x86_64 x86_64 GNU/Linux

$ sestatus
SELinux status:                 enabled
SELinuxfs mount:                /sys/fs/selinux
Current mode:                   enforcing
Mode from config file:          enforcing
Policy version:                 26
Policy from config file:        targeted

$ rpm -qa | grep selinux
libselinux-2.0.102-5.fc16.x86_64
libselinux-ruby-2.0.102-5.fc16.x86_64
libselinux-python-2.0.102-5.fc16.x86_64
selinux-policy-3.9.16-28.fc16.noarch
selinux-policy-targeted-3.9.16-28.fc16.noarch
libselinux-utils-2.0.102-5.fc16.x86_64

$ rpm -qa | grep semanage
libsemanage-python-2.0.46-6.fc16.x86_64
libsemanage-2.0.46-6.fc16.x86_64

$ rpm -qa | grep checkpolicy
checkpolicy-2.0.26-1.fc16.x86_64

$ rpm -qa | grep policycoreutils
policycoreutils-2.0.86-12.fc16.x86_64
policycoreutils-sandbox-2.0.86-12.fc16.x86_64
policycoreutils-python-2.0.86-12.fc16.x86_64
policycoreutils-restorecond-2.0.86-12.fc16.x86_64
policycoreutils-newrole-2.0.86-12.fc16.x86_64
policycoreutils-gui-2.0.86-12.fc16.x86_64

$ rpm -qa | grep systemd
systemd-28-3.fc16.x86_64
systemd-units-28-3.fc16.x86_64
tor-systemd-0.2.1.30-1601.fc16.noarch
systemd-sysv-28-3.fc16.x86_64

Comment 4 Frank Murphy 2011-06-09 11:02:41 UTC
(In reply to comment #3)
> looks like you may need to relabel the filesystem. You have some unlabeled
> object in etc/.*
> 

How do I relabel, when I can only boot to 3,5 with selinux=0.
Tried touch /.autoralabel;reboot after a reboot, nothing.

Comment 5 Dominick Grift 2011-06-09 11:08:01 UTC
can you not boot with enforcing=0 either?

Comment 6 Dominick Grift 2011-06-09 11:12:29 UTC
You should (almost) never need "selinux=0". Use "enforcing=0". If that does not work for kernel 3.0, then boot into a 2.* kernel and relabel: fixfiles restore, or touch /.autorelabel && reboot (just to be sure boot with enforcing=0 in a 2.* kernel. Then when the file system is relabel try to boot in a 3.0 kernel as if you would normally.

Comment 7 Frank Murphy 2011-06-09 11:14:29 UTC
(In reply to comment #5)
> can you not boot with enforcing=0 either?

For some reason had been using: setenforce=0.
Will retest.

Comment 8 Frank Murphy 2011-06-09 13:07:49 UTC
Thanks Dominick

it was a labelling problem.

Had to reboot from DVD, 
rescue install with enforcing=0 on dvd kernel line.

then fixfiles -f relabel.

Not a bug.