Bug 133380 - rc.sysinit needs extra parameter when running restorecon for SE Linux
rc.sysinit needs extra parameter when running restorecon for SE Linux
Status: CLOSED RAWHIDE
Product: Fedora
Classification: Fedora
Component: initscripts (Show other bugs)
3
All Linux
medium Severity medium
: ---
: ---
Assigned To: Bill Nottingham
Brock Organ
:
Depends On:
Blocks: FC3SELinux
  Show dependency treegraph
 
Reported: 2004-09-23 12:53 EDT by Russell Coker
Modified: 2014-03-16 22:48 EDT (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2004-09-23 14:32:02 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)

  None (edit)
Description Russell Coker 2004-09-23 12:53:25 EDT
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (compatible; Konqueror/3.3; Linux) (KHTML, like Gecko)

Description of problem:
/sbin/restorecon  /dev/* 2> /dev/null

The above line is currently in rc.sysinit to label tmpfs /dev.  It needs to be replaced with the below line to allow LVM systems to boot with strict policy.

/sbin/restorecon  /dev/* /dev/*/* 2> /dev/null


Version-Release number of selected component (if applicable):
7.82-1

How reproducible:
Always

Steps to Reproduce:
Install the strict policy on a system with LVM root and watch it fail to boot in enforcing mode.

Additional info:
Comment 1 Russell Coker 2004-09-23 13:15:13 EDT
/sbin/restorecon  /dev/* /dev/.udev.tdb /dev/*/* 2> /dev/null 
 
Actually it should be the above.  Sorry, I fixed one bug only to 
find another. 
 
Also don't bother testing the fix, with the current policy in 
rawhide it probably won't work anyway (any situation in which it's 
needed things won't work). 
Comment 2 Bill Nottingham 2004-09-23 14:32:02 EDT
Fixed in CVS.

Note You need to log in before you can comment on or make changes to this bug.