Debian Bug report logs - #922448
policycoreutils: /etc/init.d/selinux-autorelabel should run "sulogin $CONSOLE" if / is read-only

version graph

Package: policycoreutils; Maintainer for policycoreutils is Debian SELinux maintainers <selinux-devel@lists.alioth.debian.org>; Source for policycoreutils is src:policycoreutils (PTS, buildd, popcon).

Reported by: Russell Coker <russell@coker.com.au>

Date: Sat, 16 Feb 2019 08:39:02 UTC

Severity: normal

Tags: upstream

Found in version policycoreutils/2.8-1

Fixed in version policycoreutils/3.1-3

Done: Russell Coker <russell@coker.com.au>

Bug is archived. No further changes may be made.

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian SELinux maintainers <selinux-devel@lists.alioth.debian.org>:
Bug#922448; Package policycoreutils. (Sat, 16 Feb 2019 08:39:05 GMT) (full text, mbox, link).


Acknowledgement sent to Russell Coker <russell@coker.com.au>:
New Bug report received and forwarded. Copy sent to Debian SELinux maintainers <selinux-devel@lists.alioth.debian.org>. (Sat, 16 Feb 2019 08:39:05 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Russell Coker <russell@coker.com.au>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: policycoreutils: /etc/init.d/selinux-autorelabel should run "sulogin $CONSOLE" if / is read-only
Date: Sat, 16 Feb 2019 19:35:25 +1100
Package: policycoreutils
Version: 2.8-1
Severity: normal
Tags: upstream

If /.autorelabel exists and the system can't mount the root filesystem rw then
it will enter a boot loop and never recover.  The only recovery from such a
situation is to boot with selinux=0 on the kernel command line, fix the problem
that made it mount root ro, and then boot normally.

Also there should probably be a noautorelabel kernel command-line option.

-- System Information:
Debian Release: buster/sid
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'testing'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.19.0-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_AU.UTF-8, LC_CTYPE=en_AU.UTF-8 (charmap=UTF-8), LANGUAGE=en_AU:en (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: SELinux: enabled - Mode: Enforcing - Policy name: default

Versions of packages policycoreutils depends on:
ii  libaudit1      1:2.8.4-2
ii  libc6          2.28-6
ii  libselinux1    2.8-1+b1
ii  libsemanage1   2.8-2
ii  libsepol1      2.8-1
ii  lsb-base       10.2018112800
ii  selinux-utils  2.8-1+b1

policycoreutils recommends no packages.

policycoreutils suggests no packages.

-- no debconf information



Reply sent to Russell Coker <russell@coker.com.au>:
You have taken responsibility. (Fri, 05 Mar 2021 10:09:05 GMT) (full text, mbox, link).


Notification sent to Russell Coker <russell@coker.com.au>:
Bug acknowledged by developer. (Fri, 05 Mar 2021 10:09:05 GMT) (full text, mbox, link).


Message #10 received at 922448-close@bugs.debian.org (full text, mbox, reply):

From: Debian FTP Masters <ftpmaster@ftp-master.debian.org>
To: 922448-close@bugs.debian.org
Subject: Bug#922448: fixed in policycoreutils 3.1-3
Date: Fri, 05 Mar 2021 10:06:46 +0000
Source: policycoreutils
Source-Version: 3.1-3
Done: Russell Coker <russell@coker.com.au>

We believe that the bug you reported is fixed in the latest version of
policycoreutils, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 922448@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Russell Coker <russell@coker.com.au> (supplier of updated policycoreutils package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Fri, 05 Mar 2021 20:45:24 +1100
Source: policycoreutils
Architecture: source
Version: 3.1-3
Distribution: unstable
Urgency: medium
Maintainer: Debian SELinux maintainers <selinux-devel@lists.alioth.debian.org>
Changed-By: Russell Coker <russell@coker.com.au>
Closes: 922448 983447 984567
Changes:
 policycoreutils (3.1-3) unstable; urgency=medium
 .
   * Remove needless quotes around $FORCE variable in
     /lib/systemd/selinux-autorelabel to avoid shell error on empty file
     Closes: #983447
   * Add check for noautorelabel command line option to prevent relabeling
     Closes: #922448
   * Make fixfiles avoid trying to relabel tmpfs and other non-permanent
     filesystems
     Closes: #984567
Checksums-Sha1:
 78550592393364c7c7f3dba631f1820f39ec5677 2214 policycoreutils_3.1-3.dsc
 1b5629d891bad8017cccad9e5e6301ae1cf788b7 27480 policycoreutils_3.1-3.debian.tar.xz
 b93dc5e730c3dd66a55b189e3b9112ddd41cce25 7562 policycoreutils_3.1-3_amd64.buildinfo
Checksums-Sha256:
 8d6c15e814a1eef930ba449a83d57371449387014547a70e9faaa2eb1fcdb503 2214 policycoreutils_3.1-3.dsc
 b5651f26654ba889b94fd2bcf01d1ba183fb96e86a31664549641363b1f1cde3 27480 policycoreutils_3.1-3.debian.tar.xz
 285ee8aac0b6dcfce658372fa3f2477d5721e028a80eea78d11c763f35328380 7562 policycoreutils_3.1-3_amd64.buildinfo
Files:
 27a3bde8f38908183f82186daba1d471 2214 utils optional policycoreutils_3.1-3.dsc
 abf0f086ab54a97a46d0a4e254436eb2 27480 utils optional policycoreutils_3.1-3.debian.tar.xz
 87ed19069122e8a4e741994c85340c17 7562 utils optional policycoreutils_3.1-3_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEn31hncwG9XwCqmbH0UHNMPxLj3kFAmBB/jIACgkQ0UHNMPxL
j3mguhAAmE4BKW5b49wbrvrsekupCpSCdxX9Z12BY7ImEmzuTy8YKgrEyF343ai9
Adwy9ss1SdvIVy0Ggx94EzNlxA+cEd1y6Z4xJFjSgzv+3USFtRS4JR3UUPxFqCEl
WYiOdNRH5H/tI05v7Z16r6vWpHaYbjyy2pxUAOMmt7L0dEjONxZPrxM1/enbJXMJ
uCLpZiSjcn6EB/nMEwDGfNporyVnFmb9rp7pz3Qw/ArNaU+lrhj2Lm1/RuUEAkMK
wDAHNzq8r01hPxan1iRaCslYKLKFNzdsBDJTw9lApf+BufYi7L+YAHPoPWxAe0tZ
Uoq5ZmHsPJ3VsKTHnzJi0dFxo3o8L14WzO/UVPi02XRo/jcx9D103Uz397W1ywJt
mGLCZda7A2zYU0MWXbNdQLJMH87lhsmP6xwD+hi3nI3fsnta+iLXIk8alnb2jt8g
J3v2C1P0AEgcxUoulO8VyCmVFZkLEmQlCZjat5c5dogA8+55jAaalK8jMF27YfNT
i+Cni+jHDACmlZDfAWRTN6pYU88lN++dWSUgezXriErj1vPzTQeC1iVN8LWrztNV
rR98lCUa7Yto850gpyYvKxoae3QCPQBEJSzXRvwJDPMJdrJzzPzNlSmUWDq5te/Q
t2ICXhP4DcsV/PsQNktdjLtaSHV7wxoxxcRe+t8MCzlfgzzOHX4=
=/uBL
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 11 Apr 2021 07:26:53 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Sun Jan 25 12:39:48 2026; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU General Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.