Bug 208275 - chroot problems with selinux and olpc
chroot problems with selinux and olpc
Product: Fedora
Classification: Fedora
Component: libselinux (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Daniel Walsh
Ben Levenson
Depends On:
Blocks: OLPCTracker
  Show dependency treegraph
Reported: 2006-09-27 11:07 EDT by David Zeuthen
Modified: 2013-03-05 22:47 EST (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2006-11-28 09:29:40 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description David Zeuthen 2006-09-27 11:07:25 EDT
Description of problem:

For OLPC builds we install the desired OS in a chroot on the build machine. We
use yum that in turn uses rpm.

We want to use SELinux on the OLPC machine. The SELinux policy for OLPC may be
tailor-made for OLPC.

The build machine may or may not run SELinux. The build machine may be running
RHEL4. It may run FC5.

As such, the SELinux policy that controls file labels may differ in the
installed OS vs. the OS running on the build machine.

What I'm seeing today is that this only works if the SELinux policy on build
machine matches the SELinux policy of the installed OS. 

Is there a magic option to give e.g. /sbin/fixfiles so it uses the policy in the
chroot instead of that in /selinux (which is bind mounted in the chroot)?

The only alternative I can think of right now includes using qemu to boot the
installed kernel and have a initrd that runs /sbin/fixfiles.

This affects livecd generation too (I have a livecd generator that works with
SELinux, it uses the ext3 file system on a loopback device).

Please advise. Thanks.
Comment 1 Daniel Walsh 2006-09-27 15:17:59 EDT
setfiles /etc/selinux/targeted/contexts/file_contexts /

should get you what you want

fixfiles restore in the chroot should do the above.
Comment 2 Christopher Blizzard 2006-10-03 10:32:41 EDT
David, are you going to make changes to the build scripts to support this? 
Sounds like it's resolved other than making the change.
Comment 3 David Zeuthen 2006-10-03 10:49:10 EDT
Yea, I talked to dwalsh in the hallway about this yesterday. It works very
nicely for me on Rawhide, want to test on RHEL4 too since that is our build
Comment 4 Christopher Blizzard 2006-10-03 20:20:46 EDT
Great, let me know how those tests go.

Note You need to log in before you can comment on or make changes to this bug.