Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 768552 - env-update change /etc/ labels
Summary: env-update change /etc/ labels
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: SELinux (show other bugs)
Hardware: AMD64 Linux
: Normal normal (vote)
Assignee: SE Linux Bugs
Depends on:
Reported: 2021-02-03 19:26 UTC by Alexander Weber
Modified: 2022-08-20 11:28 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Weber 2021-02-03 19:26:21 UTC
I am beginner with selinux, still in permissive mode. After system update I see the next exceptions in dmesg:

[554417.234763] audit: type=1400 audit(1612379151.820:3902): avc:  denied  { map } for  pid=27484 comm="exim" path="/etc/" dev="mmcblk0p2" ino=542639 scontext=system_u:system_r:exim_t tcontext=root:object_r:etc_t tclass=file permissive=1
[554439.302701] audit: type=1400 audit(1612379173.886:3913): avc:  denied  { map } for  pid=27489 comm="sshd" path="/etc/" dev="mmcblk0p2" ino=542639 scontext=system_u:system_r:sshd_t tcontext=root:object_r:etc_t tclass=file permissive=1

Found out the env-update breaks the labels on /etc/

Reproducible: Always

Steps to Reproduce:
# ls -lZ /etc/
-rw-r--r--. 1 root root root:object_r:etc_t 39699  3. Feb 20:22 /etc/
# restorecon /etc/
# ls -lZ /etc/
-rw-r--r--. 1 root root root:object_r:ld_so_cache_t 39699  3. Feb 20:22 /etc/
# env-update 
>>> Regenerating /etc/
# ls -lZ /etc/
-rw-r--r--. 1 root root root:object_r:etc_t 39699  3. Feb 20:23 /etc/

Actual Results:  
As you see the label ld_so_cache_t gets lost and replaced by etc_t

Expected Results:  
env-update should keep or restore the ld_so_cache_t label