chcon in %post

Jason L Tibbitts III tibbs at math.uh.edu
Tue Jun 17 21:22:19 UTC 2008


I just came across a package that does this:

%post
/usr/bin/chcon -t unconfined_execmem_exec_t %{_libexecdir}/haddock.bin >/dev/null 2>&1 || :

rpmlint complains bitterly about it, and honestly I'm really not sure
what's supposed to happen here.  This is a ghc-compiled binary.  (ghc
is a Haskell compiler.)

So, if you have a binary in a package that really needs this context,
is running chcon in %post the right way to do it?

 - J<




More information about the fedora-selinux-list mailing list