Skip to content
This repository has been archived by the owner on Dec 9, 2022. It is now read-only.

possible improvement - plugin restorecon suggests no-op command (99.5 confidence) #48

Open
bachradsusi opened this issue Feb 27, 2017 · 0 comments

Comments

@bachradsusi
Copy link
Member

I used semanage fcontext + restorecon, and then (still) suffered an AVC denial executing the file.

This is not my complaint, I clearly don't understand selinux enough to implement any workaround more subtle than disabling selinux,

The problem detected is that setroubleshootd suggests the most likely fix is to run restorecon -v on the file. That was part of how I caused the problem, and of course re-running it does nothing to help.

The plugin actually knows what label "should" be re-applied. So it could easily see that something more is wrong. (Just run the equivalent of restorecon -nv).

For more information see https://bugzilla.redhat.com/show_bug.cgi?id=1427142

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant