Bug 119237 - home directory has wrong selinux attributes after being created by s-c-u
Summary: home directory has wrong selinux attributes after being created by s-c-u
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: system-config-users
Version: rawhide
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Brent Fox
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2004-03-26 22:09 UTC by Gene Czarcinski
Modified: 2007-11-30 22:10 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2004-04-15 20:22:22 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Gene Czarcinski 2004-03-26 22:09:38 UTC
Description of problem:

This was for a clean install of development snapshot dated 25 March.

If you manually edit /etc/security/selinux/src/policy/users and add a
definition for an admin user, when you create this user with s-c-u,
the selinux attributes are wrong and you cannot login until you run
"fixfiles relabel" or "make relabel".

This is likely related to other similar reports.

Comment 1 Benjmain Youngdahl 2004-03-30 03:50:01 UTC
I have experienced this problem in FC2 Test2, specifically I had to do:
/usr/sbin/setfiles /etc/security/selinux/file_contexts /home
to be able to log on as a user after creating the user via s-c-u.

I should credit:
http://people.redhat.com/kwade/fedora-docs/selinux-faq-en/
for helping me understand the problem and fix.

Shouldn't s-c-u automatically do something like that after creating
the user account?  

Comment 2 Brent Fox 2004-04-15 20:22:22 UTC
I added the SELinux widgets to the UI before the libuser bits to
actually create the user roles has been created.  The bits haven't
been added to libuser yet, so the widgets don't currently do anything.
 I will wire them up as soon as libuser is SELinux aware.

Comment 3 Gene Czarcinski 2004-04-15 20:31:50 UTC
If this is not going to happen before FC2 final, maybe this report
should be change to an RFE as a "tickler" for FC3.


Note You need to log in before you can comment on or make changes to this bug.