Files
c630/config/device.env
rob thijssen 482c5d9c9a
All checks were successful
build image / build (push) Successful in 25m5s
Label the filesystem for SELinux at build time
The image booted. Kernel came up, the device tree loaded — UFS, display,
WiFi and IPA all probed as platform devices — framebuffer console came up, root
mounted off USB and systemd started. Then:

    systemd[1]: Unable to fix SELinux security context of /dev/tty..: Permission denied
    (x hundreds)
    systemd[1]: Too many messages being logged to kmsg, ignoring
    [!!!!!!] Failed to allocate manager object.

The filesystem had no SELinux labels. mke2fs -d carries security.* xattrs
across faithfully, but nothing had ever set them: the tree came from dnf, not
from a running SELinux system. I had relied on /.autorelabel, which cannot
work here — PID 1 dies long before anything acts on the flag.

Label the tree with setfiles instead, after the bind mounts are torn down (or
it would walk the builder's /proc) and before /boot is split out, so /boot's
files are labelled along with everything else. Verified in a privileged
container beforehand that security.selinux xattrs can actually be written
through a bind mount, rather than assuming it.

I had listed policycoreutils in the gongfoo build base for exactly this and
then never called setfiles. It is now also in stage2's fallback toolchain, so
the stock-Fedora path works too.

Ship permissive regardless. The labels make enforcing viable, but the failure
mode is unusually punishing — no login prompt, no shell, nothing to repair from
— and on a machine this awkward to reach that is not a default worth choosing.
SELINUX_MODE in config/device.env flips it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XWRjNJMistCy6ngXH5aJLS
2026-07-27 18:05:28 +03:00

60 lines
2.7 KiB
Bash

# Device parameters for the Lenovo Yoga C630 13Q50 (81JL) — Qualcomm SDM850.
#
# Sourced by build/stage2.sh. Everything here is overridable from the
# environment, so CI can tweak a value without editing this file.
# --- identity -----------------------------------------------------------
: "${DEVICE_NAME:=lenovo-yoga-c630}"
: "${DEVICE_DESC:=Lenovo Yoga C630 13Q50}"
# Device tree shipped by Fedora's kernel-core, relative to /boot/dtb-$KVER/.
: "${DEVICE_DTB:=qcom/sdm850-lenovo-yoga-c630.dtb}"
# --- kernel command line ------------------------------------------------
#
# clk_ignore_unused / pd_ignore_unused
# The SDM850 clock and power-domain trees are only partially described in
# the device tree. Without these the kernel gates clocks and power domains
# that nothing has claimed but that the machine still needs, and the boot
# dies somewhere between the pivot and the display coming up.
#
# efi=noruntime
# The C630's EFI runtime services are not usable from Linux. Since 6.7 the
# qcom_uefisecapp driver provides efivars through SCM instead, so turning
# runtime services off costs nothing and avoids the hangs.
#
# arm64.nopauth
# Harmless on Cortex-A75/A55 (no pointer auth), kept for parity with the
# rest of the Snapdragon WoA laptop fleet.
: "${DEVICE_CMDLINE:=clk_ignore_unused pd_ignore_unused efi=noruntime arm64.nopauth}"
# Uncomment if USB dies during boot before the Windows DSP firmware has been
# extracted — the ADSP reset puts the USB-C PHY into high-Z briefly.
# DEVICE_CMDLINE="$DEVICE_CMDLINE modprobe.blacklist=qcom_q6v5_pas"
# --- image geometry (MiB) -----------------------------------------------
: "${ESP_SIZE_MIB:=512}"
: "${BOOT_SIZE_MIB:=1024}"
# Total image size. The root partition takes whatever is left, and grows to
# fill the target medium on first boot.
: "${IMAGE_SIZE_MIB:=8192}"
# --- distro -------------------------------------------------------------
: "${FEDORA_RELEASE:=44}"
: "${TARGET_ARCH:=aarch64}"
# --- selinux ------------------------------------------------------------
# The build labels the filesystem offline with setfiles, so enforcing is
# viable. It ships permissive anyway: an unlabelled or mislabelled filesystem
# takes PID 1 down with "Failed to allocate manager object" before anything can
# be logged in and fixed, and on a machine this awkward to debug that trade is
# not worth making by default. Switch with `sudo setenforce 1` once it is up,
# or set this to enforcing and rebuild.
: "${SELINUX_MODE:=permissive}"
# --- default account ----------------------------------------------------
# Password is expired at first login, so it must be changed immediately.
: "${DEFAULT_USER:=fedora}"
: "${DEFAULT_PASSWORD:=fedora}"