Red Hat Bugzilla – Bug 209853
network root leads to SELinux avc from dhclient-leases file
Last modified: 2014-03-16 23:03:02 EDT
When we're doing a boot from NFS or iscsi, we copy the dhclient lease to /dev in
the initrd. That then gets copied later in ifup-eth from /dev ->
/var/lib/dhclient. When dhclient then tries to access it, it's unable to as the
file is labeled device_t instead of dhcpc_state_t.
Should we restorecon when we do that move?
Yeah, we probably should.
If you use install instead of mv, you get this for free.
Manually tested on my iscsi guest and it works fine.
Building as 8.45.1-1.