Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1035857

Bug#906729: Please fix SELinux labels of /vmlinuz symlink after kernel update

From bauen1 <j2468h@googlemail.com>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#906729: Please fix SELinux labels of /vmlinuz symlink after kernel update
Date 2020-12-05 13:50 +0100
Message-ID <BiFaF-3TC-1@gated-at.bofh.it> (permalink)
References <zsyFk-5Wz-15@gated-at.bofh.it> <zsyFk-5Wz-13@gated-at.bofh.it> <zsyFk-5Wz-13@gated-at.bofh.it> <woOPg-4vN-11@gated-at.bofh.it> <zsyFk-5Wz-13@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


On Sat, 25 Jan 2020 19:42:53 +0100 =?UTF-8?Q?Christian_G=C3=B6ttsche?= <cgzones@googlemail.com> wrote:
> It is not needed for anything to work correctly; it is just that
> objects should have the context defined by the SELinux policy. The
> root_t context should only be used by the root path directory,
> anything else is suspicious and should be avoided. Also if one sets up
> an alert for incorrect labeled objects (e.g. via repeatedly running
> restorecon -v -R -n /) this mislabeling would trigger.

Even better would be if the linux-update-symlinks perl script fixed the symlinks label before replacing it in an atomic operation in https://salsa.debian.org/kernel-team/linux-base/-/blob/master/bin/linux-update-symlinks#L49-76

-- 

bauen1
https://dn42.bauen1.xyz/

Back to linux.debian.bugs.dist | Previous | Next | Find similar | Unroll thread


Thread

Bug#906729: Please fix SELinux labels of /vmlinuz symlink after kernel update bauen1 <j2468h@googlemail.com> - 2020-12-05 13:50 +0100

csiph-web