openshift / os

89 stars 107 forks source link

`/sysroot` and `/boot/efi` have `unlabeled_t` selinux labels #1599

Open dustymabe opened 1 month ago

dustymabe commented 1 month ago

This is a downstream issue corresponding to:

This affects 4.16+.

[core@cosa-devsh ~]$ ls -ldZ /boot/efi /sysroot 
drwxr-xr-x. 2 root root system_u:object_r:unlabeled_t:s0 1024 May 21 21:05 /boot/efi
drwxr-xr-x. 4 root root system_u:object_r:unlabeled_t:s0   93 Aug  1  2022 /sysroot
HuijingHei commented 1 month ago

And files & dirs under /sysroot have unlabeled_t:

[root@cosa-devsh ~]# ls -alZ /sysroot/
total 8
drwxr-xr-x.  4 root root system_u:object_r:unlabeled_t:s0   93 Aug  1  2022 .
drwxr-xr-x. 12 root root system_u:object_r:root_t:s0      4096 Jan  1  1970 ..
-rw-r--r--.  1 root root system_u:object_r:unlabeled_t:s0 1483 Aug  1  2022 .aleph-version.json
lrwxrwxrwx.  1 root root system_u:object_r:unlabeled_t:s0   19 Aug  1  2022 .coreos-aleph-version.json -> .aleph-version.json
drwxr-xr-x.  2 root root system_u:object_r:unlabeled_t:s0    6 Sep  3 23:28 boot
drwxr-xr-x.  5 root root system_u:object_r:unlabeled_t:s0   62 Sep  4 03:14 ostree