This service will be undergoing maintenance at 00:00 UTC, 2016-08-01. It is expected to last about 1 hours
Bug 729563 - F16Alpha install does not have selinux enabled!
F16Alpha install does not have selinux enabled!
Status: CLOSED ERRATA
Product: Fedora
Classification: Fedora
Component: anaconda (Show other bugs)
16
Unspecified Unspecified
unspecified Severity unspecified
: ---
: ---
Assigned To: Anaconda Maintenance Team
Fedora Extras Quality Assurance
RejectedBlocker, AcceptedNTH
:
Depends On:
Blocks: F16Alpha-accepted/F16AlphaFreezeExcept
  Show dependency treegraph
 
Reported: 2011-08-10 03:48 EDT by Jens Petersen
Modified: 2011-08-18 18:25 EDT (History)
9 users (show)

See Also:
Fixed In Version: anaconda-16.14.6-1.fc16
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2011-08-18 18:25:04 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)
anaconda.log from Alpha RC3 DVD installation with enforcing=0 (23.62 KB, text/x-log)
2011-08-10 10:09 EDT, Sandro Mathys
no flags Details

  None (edit)
Description Jens Petersen 2011-08-10 03:48:04 EDT
Description of problem:
Installing F16 Alpha from DVD or net install results
in a system with selinux disabled.

Version-Release number of selected component (if applicable):
FC16 Alpha RC3

How reproducible:
every time

Steps to Reproduce:
1. install Alpha from net or dvd
  
Actual results:
selinux is disabled

Expected results:
selinux to be enforcing
Comment 1 Adam Williamson 2011-08-10 03:58:51 EDT
proposing as alpha blocker so we can discuss whether we should have a criterion for this, and if so, at which stage.

selinux is disabled by /etc/selinux/config , which is part of selinux-policy package, and rpm -V selinux-policy doesn't complain, so it seems selinux disabled actually is the package default - is this a package bug, or is it supposed to be that way and anaconda should override it at install time or smth? CCing Dan for clarification.
Comment 2 Adam Williamson 2011-08-10 04:00:35 EDT
oh, seems rpm -V doesn't complain whatever you do to the file. i guess it intentionally ignores config files. i'll poke into the package to see what the default really is.
Comment 3 Mads Kiilerich 2011-08-10 04:28:11 EDT
This might have been caused by the move of /selinux to /sys/fs/, and this might thus be a consequence/duplicate of bug 728576.
Comment 4 Sandro Mathys 2011-08-10 07:08:25 EDT
FWIW:
[root@localhost ~]# grep selinux anaconda-ks.cfg 
selinux --disabled

This is on a freshly installed system, set up with the Alpha RC3 DVD.
Comment 5 Chris Lumens 2011-08-10 09:59:58 EDT
Please attach /var/log/anaconda/anaconda.log to this bug report.  Thanks.
Comment 6 Sandro Mathys 2011-08-10 10:09:14 EDT
Created attachment 517619 [details]
anaconda.log from Alpha RC3 DVD installation with enforcing=0
Comment 7 Chris Lumens 2011-08-10 10:36:25 EDT
Are you sure that's the right log?  I'd expect if that were the case, I'd see enforcing=0 on the command line there at the top.  Did you set it at tty2 or something?

Also yes, I'm wondering if comment #3 has it right too.  There are a couple places in anaconda where we refer to /selinux.  I've got a patch along those lines that I need to test out.
Comment 8 Sandro Mathys 2011-08-10 11:21:18 EDT
I'm 100% sure it's the correct log. What I'm not sure about right now whether I needed enforcing=0 for the DVD too or only for the live media installs. By the way, this issue can be observed with both, live media and dvd installs.

I'm also 100% sure the installed system had selinux disabled when I first booted it. I then rebooted it into permissive mode (without relabeling) and generated attachment #517580 [details] for bug #728863 which might or might not be connected to this bug.
Comment 9 Daniel Walsh 2011-08-10 11:23:37 EDT
Anaconda should be using selinux python bindings rather the hard coding paths if possible.


import selinux
if selinux.is_selinux_enabled():
    print "You made dan happy"
Comment 10 Adam Williamson 2011-08-10 11:59:43 EDT
I didn't need enforcing=0 to install from DVD. for me, installing from DVD with next, next, next, next works, and reproduces this bug. I can provide a log if you're worried about Sandro's.
Comment 11 Daniel Walsh 2011-08-10 12:04:26 EDT
Right the problem again is hard coding of /selinux.  Which Chris is working to fix.
Comment 12 Chris Lumens 2011-08-10 13:31:40 EDT
Anyone want to give updates=http://clumens.fedorapeople.org/729563.img a try?  It worked for me in a brief test.
Comment 13 Ray Strode [halfline] 2011-08-10 17:15:25 EDT
I thought is_selinux_enabled could return 3 possible values? shouldn't it be

if selinux.is_selinux_enabled() > 0:
    print "You made dan happy"

?
Comment 14 Tim Flink 2011-08-10 17:20:41 EDT
Discussed in the 2011-08-10 Fedora 16 go/no-go meeting. Since there are no release criteria stating that SELinux must be enabled, rejected as a blocker. However, it was accepted as an NTH bug for Fedora 16 alpha.
Comment 15 Tim Flink 2011-08-10 20:57:12 EDT
(In reply to comment #12)
> Anyone want to give updates=http://clumens.fedorapeople.org/729563.img a try? 
> It worked for me in a brief test.

I tried it on a default graphical i686 netinstall and SELinux is enabled by default with no apparent AVC issues.
Comment 16 Fedora Update System 2011-08-11 11:49:33 EDT
anaconda-16.14.4-1.fc16 has been submitted as an update for Fedora 16.
https://admin.fedoraproject.org/updates/anaconda-16.14.4-1.fc16
Comment 17 Fedora Update System 2011-08-12 00:22:48 EDT
Package anaconda-16.14.4-1.fc16:
* should fix your issue,
* was pushed to the Fedora 16 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing anaconda-16.14.4-1.fc16'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/anaconda-16.14.4-1.fc16
then log in and leave karma (feedback).
Comment 18 Fedora Update System 2011-08-15 12:55:19 EDT
anaconda-16.14.5-1.fc16 has been submitted as an update for Fedora 16.
https://admin.fedoraproject.org/updates/anaconda-16.14.5-1.fc16
Comment 19 Sandro Mathys 2011-08-16 03:49:40 EDT
Just installed F16 Alpha RC4 x86_64 from DVD and this issue seems to be fixed.
Comment 20 Fedora Update System 2011-08-16 16:14:30 EDT
anaconda-16.14.6-1.fc16 has been submitted as an update for Fedora 16.
https://admin.fedoraproject.org/updates/anaconda-16.14.6-1.fc16
Comment 21 Fedora Update System 2011-08-17 10:55:04 EDT
Package anaconda-16.14.6-1.fc16:
* should fix your issue,
* was pushed to the Fedora 16 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing anaconda-16.14.6-1.fc16'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/anaconda-16.14.6-1.fc16
then log in and leave karma (feedback).
Comment 22 Adam Williamson 2011-08-17 12:28:06 EDT
biff-baff!
Comment 23 Fedora Update System 2011-08-18 18:24:03 EDT
anaconda-16.14.6-1.fc16 has been pushed to the Fedora 16 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.