Red Hat Bugzilla – Bug 1316278
incorrect SELinux label on /sys/fs/cgroup and restorecon fails with "Read-only file system"
Last modified: 2017-08-16 03:51:36 EDT
Description of problem:
(originally reported on the CentOS bug tracker and someone suggested that I should report here instead)
/sys/fs/cgroup is currently assigned the incorrect SELinux label of
but restorecon reports that it should be
restorecon is unable to fix the issue as it returns an error: Read-only file system
Version-Release number of selected component (if applicable):
selinux-policy 3.13.1 (release 60.el7_2.3, Based off of reference policy: Checked out revision 2.20091117)
Steps to Reproduce:
1. run ls -aZ /sys/fs/cgroup to verify directory has label of system_u:object_r:tmpfs_t:s0
2. run sudo restorecon -v /sys/fs/cgroup to correct the label
You will see the following error message:
restorecon set context /sys/fs/cgroup->system_u:object_r:cgroup_t:s0 failed:'Read-only file system'
restorecon should have have corrected the label of /sys/fs/cgroup to system_u:object_r:cgroup_t
You can confirm the correct label here:
I cannot remember. But I don't think so.
This should be fixed in systemd code.
Could you add labeling for /sys/fs/cgroup dir cgroup_t ?