errors with labels after running for a while

Bill Nottingham notting at redhat.com
Thu Mar 11 15:10:56 UTC 2004


Russell Coker (russell at coker.com.au) said: 
> > /usr/sbin/setfiles:  relabeling /etc/modules.conf from
> > system_u:object_r:etc_t to system_u:object_r:modules_conf_t
> 
> This is a problem.  Do you know what might have created that file?

Bad %post from nfs-utils. It will be fixed in a future build.

> > /usr/sbin/setfiles:  relabeling /etc/auto.master from root:object_r:etc_t
> > to system_u:object_r:etc_t /usr/sbin/setfiles:  relabeling
> 
> When you re-create a file the identity will match the identity of the creating 
> process.  Presumably you edited the file as root:sysadm_r:sysadm_t.  When you 
> relabel /etc after running for some time you see all the files you modified 
> as root.

scp'd it, actually. Although, it does point out that we probably
need to patch more editors.

> > /etc/ptal/ptal-printd-like from system_u:object_r:etc_runtime_t to
> > system_u:object_r:etc_t /usr/sbin/setfiles:  relabeling
> 
> How is this file created?  Maybe we should put in a file_contexts entry for 
> it?  What package(s) use it?

Tim - this is something to do with hpoj and foomatic?

> > /usr/sbin/setfiles:  relabeling /etc/rndc.key from system_u:object_r:etc_t
> > to system_u:object_r:rndc_conf_t make: *** [checklabels] Error 1
> 
> This is a serious problem.  How was the rndc.key file created?

%post of bind.

Bill




More information about the selinux mailing list