Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 270168 - sys-apps/util-linux-2.14.2 fails while linking mount on selinux systems
Summary: sys-apps/util-linux-2.14.2 fails while linking mount on selinux systems
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Core system (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: SE Linux Bugs
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2009-05-17 11:43 UTC by Tadas
Modified: 2009-06-08 02:19 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Build Log (sys-apps:util-linux-2.14.2:20090520-011937.log,48.76 KB, text/plain)
2009-05-20 01:36 UTC, Aaron Clark
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Tadas 2009-05-17 11:43:59 UTC
http://rafb.net/p/bFsSXS26.html

Reproducible: Always




# emerge --info
Portage 2.1.6.11 (selinux/2007.0/amd64/hardened, gcc-4.1.2, glibc-2.8_p20080602-r1, 2.6.25-hardened-r7 x86_64)
=================================================================
System uname: Linux-2.6.25-hardened-r7-x86_64-AMD_Athlon-tm-_64_X2_Dual_Core_Processor_5600+-with-glibc2.2.5
Timestamp of tree: Sun, 17 May 2009 10:15:01 +0000
app-shells/bash:     3.2_p39
dev-lang/python:     2.4.4-r13, 2.5.4-r2
dev-python/pycrypto: 2.0.1-r6
sys-apps/baselayout: 1.12.11.1
sys-apps/sandbox:    1.6-r2
sys-devel/autoconf:  2.63
sys-devel/automake:  1.7.9-r1, 1.9.6-r2, 1.10.2
sys-devel/binutils:  2.18-r3
sys-devel/gcc-config: 1.4.1
sys-devel/libtool:   1.5.26
virtual/os-headers:  2.6.27-r2
ACCEPT_KEYWORDS="amd64"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-march=athlon64 -O2 -pipe"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/fonts/fonts.conf /etc/gconf /etc/php/apache2-php5/ext-active/ /etc/php/cgi-php5/ext-active/ /etc/php/cli-php5/ext-active/ /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo /etc/udev/rules.d"
CXXFLAGS="-march=athlon64 -O2 -pipe"
DISTDIR="/usr/portage/distfiles"
FEATURES="distlocks fixpackages loadpolicy parallel-fetch protect-owned sandbox selinux sesandbox sfperms strict unmerge-orphans userfetch"
GENTOO_MIRRORS="http://atviras.lt/gentoomirror/ http://distfiles.gentoo.org http://distro.ibiblio.org/pub/linux/distributions/gentoo"
LANG="lt_LT.utf8"
LDFLAGS=""
MAKEOPTS="-j3"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
SYNC="rsync://atviras.lt/gentoo-portage/"
USE="amd64 apache2 berkdb big-tables caps cli cracklib crypt ctype cups curl dri fortran gd gdbm gpm hardened hash iconv imap ipv6 isdnlog jpeg json ldap maildir midi mmx mudflap mysql mysqli ncurses nls nptl nptlonly openmp pam pcre pdo perl php pic png pppd python readline reflection rss sasl selinux session simplexml spl sqlite sqlite3 sse sse2 ssl tcpd truetype unicode vhosts xml xmlrpc xorg xpm xsl zip zlib" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x     ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3       trident usb-audio via82xx via82xx-modem ymfpci" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mmap_emul mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="actions proxy proxy_http ctions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" ELIBC="glibc" INPUT_DEVICES="keyboard mouse evdev" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" USERLAND="GNU" VIDEO_CARDS="apm ark chips cirrus cyrix dummy fbdev glint i128 i810 intel mach64      mga neomagic nv r128 radeon rendition s3 s3virge savage siliconmotion sis       sisusb tdfx tga trident tseng v4l vesa vga via vmware voodoo"
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, FFLAGS, INSTALL_MASK, LC_ALL, LINGUAS, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS, PORTDIR_OVERLAY
Comment 1 Peter Alfredsen (RETIRED) gentoo-dev 2009-05-17 11:59:59 UTC
Please attach the build.log to this bug. Pastebins expire and are no good for bug reports.
Comment 2 Davide Pesavento (RETIRED) gentoo-dev 2009-05-17 12:50:06 UTC
i686-pc-linux-gnu-gcc -std=gnu99  -fsigned-char -O2 -march=pentium4 -msse2 -mfpmath=sse -pipe -fomit-frame-pointer    -o mount mount-mount.o mount-fstab.o mount-mount_mntent.o mount-getusername.o mount-lomount.o mount-sundries.o mount-xmalloc.o mount-realpath.o mount-fsprobe.o mount-fsprobe_blkid.o   mount-env.o mount-linux_version.o mount-blkdev.o  mount-setproctitle.o -lblkid -luuid  -lselinux -lsepol
mv -f .deps/pivot_root.Tpo .deps/pivot_root.Po
i686-pc-linux-gnu-gcc -std=gnu99  -fsigned-char -O2 -march=pentium4 -msse2 -mfpmath=sse -pipe -fomit-frame-pointer    -o umount umount-umount.o umount-fstab.o umount-mount_mntent.o umount-getusername.o umount-lomount.o umount-sundries.o umount-xmalloc.o umount-realpath.o umount-fsprobe.o umount-fsprobe_blkid.o   umount-env.o umount-linux_version.o umount-blkdev.o  -lblkid -luuid
mount-mount.o: In function `.L513':
mount.c:(.text+0x1a79): undefined reference to `security_get_initial_context'
collect2: ld returned 1 exit status
make[2]: *** [mount] Error 1
make[2]: *** Waiting for unfinished jobs....
make[2]: Leaving directory `/var/tmp/portage/sys-apps/util-linux-2.14.2/work/util-linux-ng-2.14.2/mount'
make[1]: *** [all-recursive] Error 1
make[1]: Leaving directory `/var/tmp/portage/sys-apps/util-linux-2.14.2/work/util-linux-ng-2.14.2'
make: *** [all] Error 2

emerge --info:
Portage 2.1.6.11 (selinux/2007.0/x86/hardened, gcc-3.4.6, glibc-2.8_p20080602-r1, 2.6.28-hardened-r7 i686)
=================================================================                                         
System uname: Linux-2.6.28-hardened-r7-i686-Intel-R-_Pentium-R-_4_CPU_2.20GHz-with-glibc2.3.2
Timestamp of tree: Sun, 17 May 2009 10:45:01 +0000  
app-shells/bash:     3.2_p39  
dev-lang/python:     2.5.4-r2 
sys-apps/baselayout: 2.0.0  
sys-apps/openrc:     0.4.3-r2  
sys-apps/sandbox:    1.6-r2
sys-devel/autoconf:  2.63
sys-devel/automake:  1.7.9-r1, 1.10.2 
sys-devel/binutils:  2.18-r3
sys-devel/gcc-config: 1.4.1  
sys-devel/libtool:   1.5.26          
virtual/os-headers:  2.6.27-r2 
ACCEPT_KEYWORDS="x86"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-O2 -march=pentium4 -msse2 -mfpmath=sse -pipe -fomit-frame-pointer"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /var/bind"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/gconf /etc/gentoo-release /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo /etc/udev/rules.d"
CXXFLAGS="-O2 -march=pentium4 -msse2 -mfpmath=sse -pipe -fomit-frame-pointer"
DISTDIR="/usr/portage/distfiles"
FEATURES="distlocks fixpackages loadpolicy nodoc noinfo parallel-fetch protect-owned sandbox selinux sesandbox sfperms strict unmerge-orphans userfetch"
GENTOO_MIRRORS="http://mirror.switch.ch/ftp/mirror/gentoo/"
LANG="en_US.UTF-8"
LC_ALL="en_US.UTF-8"
LDFLAGS=""
MAKEOPTS="-j2"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_EXTRA_OPTS="--exclude-from=/etc/portage/rsync_excludes --human-readable --prune-empty-dirs"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
SYNC="rsync://rsync.europe.gentoo.org/gentoo-portage"
USE="bash-completion berkdb bzip2 caps cli cracklib crypt dbus dri fam gmp hardened iconv idn isdnlog jpeg kerberos ldap mailwrapper mbox midi mmx mudflap ncurses nls nptl nptlonly openmp pam pcre pic png pppd readline reflection samba sasl selinux session socks5 spl sqlite sse sse2 ssl tcpd threads truetype unicode x86 xorg zlib" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1    emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m       maestro3 trident usb-audio via82xx via82xx-modem ymfpci" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mmap_emul mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" ELIBC="glibc" INPUT_DEVICES="keyboard mouse evdev" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" USERLAND="GNU" VIDEO_CARDS="apm ark chips cirrus cyrix dummy fbdev glint i128 i740 i810 imstt intel   mach64 mga neomagic nsc nv r128 radeon rendition s3 s3virge savage    siliconmotion sis sisusb tdfx tga trident tseng v4l vesa vga via vmware         voodoo"
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, FFLAGS, INSTALL_MASK, LINGUAS, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTDIR_OVERLAY
Comment 3 Aaron Clark 2009-05-19 03:48:23 UTC
For reference, I'm seeing the exact same thing with a non-hardened kernel.

**** BUILD LOG STARTS ****

x86_64-pc-linux-gnu-gcc -std=gnu99  -fsigned-char -march=nocona -O2 -pipe    -o mount mount-mount.o mount-fstab.o mount-mount_mntent.o mount-getusername.o mount-lomount.o mount-sundries.o mount-xmalloc.o mount-realpath.o mount-fsprobe.o mount-fsprobe_blkid.o   mount-env.o mount-linux_version.o mount-blkdev.o  mount-setproctitle.o -lblkid -luuid  -lselinux -lsepol 
mv -f .deps/pivot_root.Tpo .deps/pivot_root.Po
x86_64-pc-linux-gnu-gcc -std=gnu99  -fsigned-char -march=nocona -O2 -pipe    -o umount umount-umount.o umount-fstab.o umount-mount_mntent.o umount-getusername.o umount-lomount.o umount-sundries.o umount-xmalloc.o umount-realpath.o umount-fsprobe.o umount-fsprobe_blkid.o   umount-env.o umount-linux_version.o umount-blkdev.o  -lblkid -luuid  
mount-mount.o: In function `try_mount_one':
mount.c:(.text+0x12ce): undefined reference to `security_get_initial_context'
collect2: ld returned 1 exit status
make[2]: *** [mount] Error 1
make[2]: *** Waiting for unfinished jobs....
make[2]: Leaving directory `/var/tmp/portage/sys-apps/util-linux-2.14.2/work/util-linux-ng-2.14.2/mount'
make[1]: *** [all-recursive] Error 1
make[1]: Leaving directory `/var/tmp/portage/sys-apps/util-linux-2.14.2/work/util-linux-ng-2.14.2'
make: *** [all] Error 2
 * 
 * ERROR: sys-apps/util-linux-2.14.2 failed.
 * Call stack:
 *               ebuild.sh, line   48:  Called src_compile
 *             environment, line 2185:  Called die
 * The specific snippet of code:
 *       emake || die "emake failed"
 *  The die message:
 *   emake failed
 * 
 * If you need support, post the topmost build error, and the call stack if relevant.
 * The ebuild environment file is located at '/var/tmp/portage/sys-apps/util-linux-2.14.2/temp/environment'.

**** BUILD LOG ENDS ****

Portage 2.1.6.11 (selinux/2007.0/amd64, gcc-4.3.2, glibc-2.8_p20080602-r1, 2.6.28-gentoo-r5 x86_64)
=================================================================
System uname: Linux-2.6.28-gentoo-r5-x86_64-Intel-R-_Core-TM-2_CPU_T5600_@_1.83GHz-with-glibc2.2.5
Timestamp of tree: Sat, 16 May 2009 13:45:01 +0000
app-shells/bash:     3.2_p39
dev-lang/python:     2.5.4-r2
sys-apps/baselayout: 1.12.11.1
sys-apps/sandbox:    1.6-r2
sys-devel/autoconf:  2.63
sys-devel/automake:  1.10.2
sys-devel/binutils:  2.18-r3
sys-devel/gcc-config: 1.4.1
sys-devel/libtool:   1.5.26
virtual/os-headers:  2.6.27-r2
ACCEPT_KEYWORDS="amd64"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-march=nocona -O2 -pipe"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/gconf /etc/php/apache2-php5/ext-active/ /etc/php/cgi-php5/ext-active/ /etc/php/cli-php5/ext-active/ /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo /etc/udev/rules.d"
CXXFLAGS="-march=nocona -O2 -pipe"
DISTDIR="/usr/portage/distfiles"
FEATURES="distlocks fixpackages loadpolicy parallel-fetch protect-owned sandbox selinux sesandbox sfperms strict unmerge-orphans userfetch"
GENTOO_MIRRORS="ftp://gentoo.arcticnetwork.ca/pub/gentoo/ http://mirror.csclub.uwaterloo.ca/gentoo-distfiles/ ftp://distro.ibiblio.org/pub/linux/distributions/gentoo/"
LDFLAGS=""
MAKEOPTS="-j2"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
SYNC="rsync://alexandria/gentoo-portage"
USE="acpi amd64 apic berkdb cli cracklib dri fortran gdbm iconv isdnlog midi mmx mudflap ncurses nls nptl nptlonly openmp pam pcre perl pppd python readline reflection selinux session spl sse sse2 ssl tcpd unicode xorg zlib" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x   ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3       trident usb-audio via82xx via82xx-modem ymfpci" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mmap_emul mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" ELIBC="glibc" INPUT_DEVICES="keyboard mouse evdev" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" USERLAND="GNU" VIDEO_CARDS="apm ark chips cirrus cyrix dummy fbdev glint i128 i810 intel mach64  mga neomagic nv r128 radeon rendition s3 s3virge savage siliconmotion sis       sisusb tdfx tga trident tseng v4l vesa vga via vmware voodoo"
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, FFLAGS, INSTALL_MASK, LANG, LC_ALL, LINGUAS, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS, PORTDIR_OVERLAY
Comment 4 SpanKY gentoo-dev 2009-05-19 07:07:02 UTC
post the full build log as an attachment

i dont have any selinux systems, but apparently mount needs security_get_initial_context and the selinux libraries are not providing it
Comment 5 Maxim Britov 2009-05-19 07:40:50 UTC
I checked sources of libselinux.
security_get_initial_context present in libselinux-2.x, but not present in currently stable libselinux-1.x
Yes, I have same issue on stable tree.
Comment 6 Aaron Clark 2009-05-20 01:36:27 UTC
Created attachment 191863 [details]
Build Log
Comment 7 Aaron Clark 2009-05-20 01:46:33 UTC
Note: I am running my system in permissive, so this should not be a policy issue.

~ $ sestatus
SELinux status:                 enabled
SELinuxfs mount:                /selinux
Current mode:                   permissive
Mode from config file:          permissive
Policy version:                 24
Policy from config file:        targeted
Comment 10 SpanKY gentoo-dev 2009-05-23 21:14:44 UTC
ive applied the fix from upstream to 2.14.2 and 2.15-r1
Comment 11 Aaron Clark 2009-06-08 02:19:38 UTC
Just following up on this, I resync'd shortly after the fix was applied and util-linux emerged fine.  I have had no issues with it since updating so the fix appears to be good.