Bug 725976 - selinux policy tries to fix initrd labels
Summary: selinux policy tries to fix initrd labels
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: dracut
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Harald Hoyer
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-07-27 08:23 UTC by Nicolas Mailhot
Modified: 2011-08-31 16:10 UTC (History)
11 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-08-31 16:10:28 UTC
Type: ---


Attachments (Terms of Use)
screenshot (1.61 MB, image/png)
2011-07-27 09:48 UTC, Nicolas Mailhot
no flags Details

Description Nicolas Mailhot 2011-07-27 08:23:24 UTC
selinux policy tries to change initrd selinux labels, even though the initrd is mounted read only and can not be modified

$ rpm -qa selinux* dracut* kernel*|sort
dracut-011-15.git20110720.noarch
kernel-3.0.0-1.fc16.x86_64
kernel-headers-3.0.0-1.fc16.x86_64
selinux-policy-3.10.0-10.fc16.noarch
selinux-policy-targeted-3.10.0-10.fc16.noarch

Comment 1 Nicolas Mailhot 2011-07-27 09:48:24 UTC
Created attachment 515459 [details]
screenshot

Comment 2 Daniel Walsh 2011-07-29 14:44:04 UTC
Did you force an autorelebal?

Comment 3 Daniel Walsh 2011-07-29 14:45:03 UTC
This might be systemd attempting to do this?  How did you set this up?

Comment 4 Nicolas Mailhot 2011-07-30 09:40:59 UTC
(In reply to comment #2)
> Did you force an autorelebal?

It occurs both with and without forcing autorelabels

(In reply to comment #3)
> This might be systemd attempting to do this?  How did you set this up?

I booted. It's more obvious without rhbg quiet on the kernel command line

Comment 5 Harald Hoyer 2011-08-03 10:33:35 UTC
Hmm, with rawhide, the initramfs is kept in /run/initramfs for the shutdown procedure. Can restorecond just wait until /run is mounted rw again?

Comment 6 Daniel Walsh 2011-08-03 15:47:49 UTC
This is not restorecond, this is systemd executing a restorecon on /run and /dev I believe.

Comment 7 Lennart Poettering 2011-08-21 12:39:09 UTC
systemd is relabelling /run here. Harald, why is /run mounted r/o here?

Comment 8 Harald Hoyer 2011-08-22 09:06:20 UTC
(In reply to comment #7)
> systemd is relabelling /run here. Harald, why is /run mounted r/o here?

It's not r/o .. dracut just creates incorrect symlinks! 

dracut-013-4 should be used!!

Comment 10 Lennart Poettering 2011-08-31 16:10:28 UTC
dracut 13-4 is stable since a while, hence closing.


Note You need to log in before you can comment on or make changes to this bug.