Bug 725976

Summary: selinux policy tries to fix initrd labels
Product: [Fedora] Fedora Reporter: Nicolas Mailhot <nicolas.mailhot>
Component: dracutAssignee: Harald Hoyer <harald>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: rawhideCC: dwalsh, harald, johannbg, jonathan, kay, lpoetter, metherid, mgrepl, mschmidt, notting, plautrba
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-08-31 16:10:28 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Attachments:
Description Flags
screenshot none

Description Nicolas Mailhot 2011-07-27 08:23:24 UTC
selinux policy tries to change initrd selinux labels, even though the initrd is mounted read only and can not be modified

$ rpm -qa selinux* dracut* kernel*|sort
dracut-011-15.git20110720.noarch
kernel-3.0.0-1.fc16.x86_64
kernel-headers-3.0.0-1.fc16.x86_64
selinux-policy-3.10.0-10.fc16.noarch
selinux-policy-targeted-3.10.0-10.fc16.noarch

Comment 1 Nicolas Mailhot 2011-07-27 09:48:24 UTC
Created attachment 515459 [details]
screenshot

Comment 2 Daniel Walsh 2011-07-29 14:44:04 UTC
Did you force an autorelebal?

Comment 3 Daniel Walsh 2011-07-29 14:45:03 UTC
This might be systemd attempting to do this?  How did you set this up?

Comment 4 Nicolas Mailhot 2011-07-30 09:40:59 UTC
(In reply to comment #2)
> Did you force an autorelebal?

It occurs both with and without forcing autorelabels

(In reply to comment #3)
> This might be systemd attempting to do this?  How did you set this up?

I booted. It's more obvious without rhbg quiet on the kernel command line

Comment 5 Harald Hoyer 2011-08-03 10:33:35 UTC
Hmm, with rawhide, the initramfs is kept in /run/initramfs for the shutdown procedure. Can restorecond just wait until /run is mounted rw again?

Comment 6 Daniel Walsh 2011-08-03 15:47:49 UTC
This is not restorecond, this is systemd executing a restorecon on /run and /dev I believe.

Comment 7 Lennart Poettering 2011-08-21 12:39:09 UTC
systemd is relabelling /run here. Harald, why is /run mounted r/o here?

Comment 8 Harald Hoyer 2011-08-22 09:06:20 UTC
(In reply to comment #7)
> systemd is relabelling /run here. Harald, why is /run mounted r/o here?

It's not r/o .. dracut just creates incorrect symlinks! 

dracut-013-4 should be used!!

Comment 10 Lennart Poettering 2011-08-31 16:10:28 UTC
dracut 13-4 is stable since a while, hence closing.