Bug 1351358 - RFE: Load in permissive mode if relabel is planned?
Summary: RFE: Load in permissive mode if relabel is planned?
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: libselinux
Version: rawhide
Hardware: All
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Petr Lautrbach
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-06-29 20:47 UTC by Adam Williamson
Modified: 2020-07-27 20:14 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2020-07-27 20:14:25 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Bugzilla 1351352 0 unspecified CLOSED SELinux relabel fails (due to read-only / ?) on simple Fedora 24 virt-builder image 2021-02-22 00:41:40 UTC

Internal Links: 1351352

Description Adam Williamson 2016-06-29 20:47:12 UTC
I've been having lots of 'fun' between virt-builder and autorelabel lately (e.g. https://bugzilla.redhat.com/show_bug.cgi?id=1351352 ). While debugging that, this idea occurred to me, though I don't know if it's practical or if it'd open up exploit holes.

The idea's simple. selinux_init_load_policy() currently checks /etc/selinux/config and the kernel cmdline (for 'enforcing') to decide whether to load in permissive or enforcing mode. Could it also check if a relabel is expected - via the presence of /.autorelabel or 'autorelabel' on the cmdline - and load in permissive mode if so? This kinda makes sense to me (if we know the system needs relabelling, then loading in enforcing mode is obviously going to have unpredictable consequences), but I can see drawbacks too...

Comment 1 Richard W.M. Jones 2016-07-04 20:57:37 UTC
A fix for this is being discussed somewhere along this thread:

https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/CHCEGB2RUPHFCE4FVGIRO3CJYGNS75T7/

Comment 2 Fedora Admin XMLRPC Client 2016-12-05 13:55:03 UTC
This package has changed ownership in the Fedora Package Database.  Reassigning to the new owner of this component.


Note You need to log in before you can comment on or make changes to this bug.