Label the filesystem for SELinux at build time
All checks were successful
build image / build (push) Successful in 25m5s
All checks were successful
build image / build (push) Successful in 25m5s
The image booted. Kernel came up, the device tree loaded — UFS, display,
WiFi and IPA all probed as platform devices — framebuffer console came up, root
mounted off USB and systemd started. Then:
systemd[1]: Unable to fix SELinux security context of /dev/tty..: Permission denied
(x hundreds)
systemd[1]: Too many messages being logged to kmsg, ignoring
[!!!!!!] Failed to allocate manager object.
The filesystem had no SELinux labels. mke2fs -d carries security.* xattrs
across faithfully, but nothing had ever set them: the tree came from dnf, not
from a running SELinux system. I had relied on /.autorelabel, which cannot
work here — PID 1 dies long before anything acts on the flag.
Label the tree with setfiles instead, after the bind mounts are torn down (or
it would walk the builder's /proc) and before /boot is split out, so /boot's
files are labelled along with everything else. Verified in a privileged
container beforehand that security.selinux xattrs can actually be written
through a bind mount, rather than assuming it.
I had listed policycoreutils in the gongfoo build base for exactly this and
then never called setfiles. It is now also in stage2's fallback toolchain, so
the stock-Fedora path works too.
Ship permissive regardless. The labels make enforcing viable, but the failure
mode is unusually punishing — no login prompt, no shell, nothing to repair from
— and on a machine this awkward to reach that is not a default worth choosing.
SELINUX_MODE in config/device.env flips it.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XWRjNJMistCy6ngXH5aJLS
This commit is contained in:
@@ -44,6 +44,15 @@
|
||||
: "${FEDORA_RELEASE:=44}"
|
||||
: "${TARGET_ARCH:=aarch64}"
|
||||
|
||||
# --- selinux ------------------------------------------------------------
|
||||
# The build labels the filesystem offline with setfiles, so enforcing is
|
||||
# viable. It ships permissive anyway: an unlabelled or mislabelled filesystem
|
||||
# takes PID 1 down with "Failed to allocate manager object" before anything can
|
||||
# be logged in and fixed, and on a machine this awkward to debug that trade is
|
||||
# not worth making by default. Switch with `sudo setenforce 1` once it is up,
|
||||
# or set this to enforcing and rebuild.
|
||||
: "${SELINUX_MODE:=permissive}"
|
||||
|
||||
# --- default account ----------------------------------------------------
|
||||
# Password is expired at first login, so it must be changed immediately.
|
||||
: "${DEFAULT_USER:=fedora}"
|
||||
|
||||
Reference in New Issue
Block a user