All checks were successful
build image / build (push) Successful in 25m5s
The image booted. Kernel came up, the device tree loaded — UFS, display,
WiFi and IPA all probed as platform devices — framebuffer console came up, root
mounted off USB and systemd started. Then:
systemd[1]: Unable to fix SELinux security context of /dev/tty..: Permission denied
(x hundreds)
systemd[1]: Too many messages being logged to kmsg, ignoring
[!!!!!!] Failed to allocate manager object.
The filesystem had no SELinux labels. mke2fs -d carries security.* xattrs
across faithfully, but nothing had ever set them: the tree came from dnf, not
from a running SELinux system. I had relied on /.autorelabel, which cannot
work here — PID 1 dies long before anything acts on the flag.
Label the tree with setfiles instead, after the bind mounts are torn down (or
it would walk the builder's /proc) and before /boot is split out, so /boot's
files are labelled along with everything else. Verified in a privileged
container beforehand that security.selinux xattrs can actually be written
through a bind mount, rather than assuming it.
I had listed policycoreutils in the gongfoo build base for exactly this and
then never called setfiles. It is now also in stage2's fallback toolchain, so
the stock-Fedora path works too.
Ship permissive regardless. The labels make enforcing viable, but the failure
mode is unusually punishing — no login prompt, no shell, nothing to repair from
— and on a machine this awkward to reach that is not a default worth choosing.
SELINUX_MODE in config/device.env flips it.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XWRjNJMistCy6ngXH5aJLS
60 lines
2.7 KiB
Bash
60 lines
2.7 KiB
Bash
# Device parameters for the Lenovo Yoga C630 13Q50 (81JL) — Qualcomm SDM850.
|
|
#
|
|
# Sourced by build/stage2.sh. Everything here is overridable from the
|
|
# environment, so CI can tweak a value without editing this file.
|
|
|
|
# --- identity -----------------------------------------------------------
|
|
: "${DEVICE_NAME:=lenovo-yoga-c630}"
|
|
: "${DEVICE_DESC:=Lenovo Yoga C630 13Q50}"
|
|
|
|
# Device tree shipped by Fedora's kernel-core, relative to /boot/dtb-$KVER/.
|
|
: "${DEVICE_DTB:=qcom/sdm850-lenovo-yoga-c630.dtb}"
|
|
|
|
# --- kernel command line ------------------------------------------------
|
|
#
|
|
# clk_ignore_unused / pd_ignore_unused
|
|
# The SDM850 clock and power-domain trees are only partially described in
|
|
# the device tree. Without these the kernel gates clocks and power domains
|
|
# that nothing has claimed but that the machine still needs, and the boot
|
|
# dies somewhere between the pivot and the display coming up.
|
|
#
|
|
# efi=noruntime
|
|
# The C630's EFI runtime services are not usable from Linux. Since 6.7 the
|
|
# qcom_uefisecapp driver provides efivars through SCM instead, so turning
|
|
# runtime services off costs nothing and avoids the hangs.
|
|
#
|
|
# arm64.nopauth
|
|
# Harmless on Cortex-A75/A55 (no pointer auth), kept for parity with the
|
|
# rest of the Snapdragon WoA laptop fleet.
|
|
: "${DEVICE_CMDLINE:=clk_ignore_unused pd_ignore_unused efi=noruntime arm64.nopauth}"
|
|
|
|
# Uncomment if USB dies during boot before the Windows DSP firmware has been
|
|
# extracted — the ADSP reset puts the USB-C PHY into high-Z briefly.
|
|
# DEVICE_CMDLINE="$DEVICE_CMDLINE modprobe.blacklist=qcom_q6v5_pas"
|
|
|
|
# --- image geometry (MiB) -----------------------------------------------
|
|
: "${ESP_SIZE_MIB:=512}"
|
|
: "${BOOT_SIZE_MIB:=1024}"
|
|
|
|
# Total image size. The root partition takes whatever is left, and grows to
|
|
# fill the target medium on first boot.
|
|
: "${IMAGE_SIZE_MIB:=8192}"
|
|
|
|
# --- distro -------------------------------------------------------------
|
|
: "${FEDORA_RELEASE:=44}"
|
|
: "${TARGET_ARCH:=aarch64}"
|
|
|
|
# --- selinux ------------------------------------------------------------
|
|
# The build labels the filesystem offline with setfiles, so enforcing is
|
|
# viable. It ships permissive anyway: an unlabelled or mislabelled filesystem
|
|
# takes PID 1 down with "Failed to allocate manager object" before anything can
|
|
# be logged in and fixed, and on a machine this awkward to debug that trade is
|
|
# not worth making by default. Switch with `sudo setenforce 1` once it is up,
|
|
# or set this to enforcing and rebuild.
|
|
: "${SELINUX_MODE:=permissive}"
|
|
|
|
# --- default account ----------------------------------------------------
|
|
# Password is expired at first login, so it must be changed immediately.
|
|
: "${DEFAULT_USER:=fedora}"
|
|
: "${DEFAULT_PASSWORD:=fedora}"
|