Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1384319 - vmconsole raise invalid file selinux context
vmconsole raise invalid file selinux context
Status: CLOSED WONTFIX
Product: ovirt-vmconsole
Classification: oVirt
Component: General (Show other bugs)
master
Unspecified Unspecified
unspecified Severity unspecified (vote)
: ovirt-4.0.5
: ---
Assigned To: Francesco Romani
Nikolai Sednev
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2016-10-13 02:21 EDT by Sandro Bonazzola
Modified: 2016-11-14 02:01 EST (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Known Issue
Doc Text:
A bug in oVirt Live ISO creation causes wrong SELinux labeling. Within the ISO, some files get the wrong context upon boot. This can be avoided by running oVirt Live in permissive mode; you can still use oVirt Live, but be aware that SELinux is not enforcing.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-10-14 06:09:40 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: Virt
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
sbonazzo: ovirt‑4.0.z?
rule-engine: planning_ack?
rule-engine: devel_ack?
rule-engine: testing_ack?


Attachments (Terms of Use)

  None (edit)
Description Sandro Bonazzola 2016-10-13 02:21:00 EDT
While building ovirt-live, noticed the following error:

/etc/selinux/targeted/contexts/files/file_contexts: has invalid context system_u:object_r:ovirt_vmconsole_exec_t:s0

Please check vmconsole packaging since it may be causing wrong selinux labeling on the system.

See http://jenkins.ovirt.org/job/ovirt-live_4.0-create-iso/57/artifact/output/iso.log
Comment 1 Michal Skrivanek 2016-10-14 03:34:49 EDT
is it a regression?
does it run a proper rpm installation in a mock environment, including post-install script? that one registers the new policy. If it just runs a plain chroot deploy of rpms and then tries to label it it is going to fail (and it always did). ovirt-vmconsole-proxy may need to be declared as a build requirement then
Comment 2 Sandro Bonazzola 2016-10-14 04:56:08 EDT
(In reply to Michal Skrivanek from comment #1)
> is it a regression?

Probably yes, because in the 3.6 build of oVirt Live it didn't happen:
http://jenkins.ovirt.org/job/ovirt-live_3.6-create-iso/47/artifact/output/iso.log


> does it run a proper rpm installation in a mock environment, including
> post-install script? that one registers the new policy.

It's a livecd creation instance so it's a clean installation in an isolated environment previously completely empty.

> If it just runs a
> plain chroot deploy of rpms and then tries to label it it is going to fail
> (and it always did). ovirt-vmconsole-proxy may need to be declared as a
> build requirement then
Comment 3 Michal Skrivanek 2016-10-14 05:08:39 EDT
I suppose it's related to the issue during installation of that policy:
  Installing: selinux-policy               ################### [650/1303]semodule: SELinux policy is not managed or store cannot be accessed.
 

Same problem is in 3.6 but it may be that the livecd creation didn't do relabeling in 3.6. Is that possible? If so, it might be a limitation/bug of livecd tool that it can't do proper selinux labeling during creation. Then we need to do it on bootup - is that how it was working in 3.6?
Comment 4 Michal Skrivanek 2016-10-14 06:09:40 EDT
there seems to be some issue with building the iso as the policy doesn't get installed properly, but when testing final iso it was there correctly more or less (well, there were many other files with wrong context upon boot when I tried restorevcon -Rv /). But we anyway run livecd in Permissive mode, likely because of all these issues and we do not want to waste time relabeling on boot for live cd...so let's close it as a known issue

Note You need to log in before you can comment on or make changes to this bug.