Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bugzilla DB migration completed. Please report issues to Infra team via email via or IRC
Bug 410687 - emerge fails with ACCESS DENIED on /sys/fs/selinux/context
Summary: emerge fails with ACCESS DENIED on /sys/fs/selinux/context
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Hardened (show other bugs)
Hardware: All Linux
: Normal normal with 1 vote (vote)
Assignee: Portage team
Keywords: InVCS
: 410761 (view as bug list)
Depends on:
Blocks: 409383
  Show dependency tree
Reported: 2012-04-03 18:17 UTC by Sven Vermeulen (RETIRED)
Modified: 2012-04-08 20:11 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---

Patch to (misc-functions.patch,940 bytes, patch)
2012-04-05 16:07 UTC, Sven Vermeulen (RETIRED)
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Sven Vermeulen (RETIRED) gentoo-dev 2012-04-03 18:17:11 UTC
Any use of emerge fails with:

ACCESS DENIED open_wr:  /sys/fs/selinux/context

This is because the sandbox prohibits R/W access to /sys/fs/selinux.

Reproducible: Always

It can be easily fixed by editing /etc/sandbox.conf to include RW access on /sys/fs/selinux. We need to see if we can add in this information automatically using our packages, or if we need to document it.
Comment 1 Sven Vermeulen (RETIRED) gentoo-dev 2012-04-05 15:44:12 UTC
*** Bug 410761 has been marked as a duplicate of this bug. ***
Comment 2 Sven Vermeulen (RETIRED) gentoo-dev 2012-04-05 16:07:16 UTC
@dev-portage folks...

In /usr/lib/portage/bin/, you currently allow (in sandbox) to write to /selinux. Recent SELinux systems however have their file system mounted at /sys/fs/selinux, so this location should be supported as well.
Comment 3 Sven Vermeulen (RETIRED) gentoo-dev 2012-04-05 16:07:47 UTC
Created attachment 307913 [details, diff]
Patch to

Suggested change on
Comment 5 Zac Medico gentoo-dev 2012-04-05 23:45:44 UTC
This is fixed in and 2.2.0_alpha100.
Comment 6 Paul de Vrieze (RETIRED) gentoo-dev 2012-04-08 20:11:35 UTC
If portage has this information in its own innards, should it than still be in /usr/portage/profiles/features/selinux/profile.bashrc ?