selinux fixfiles context

Thomas Molina tmolina at cablespeed.com
Thu Apr 15 10:47:34 UTC 2004


Does it matter in which context corrective actions for selinux problems 
are performed?  Since starting to experiment with test2 I have seen a number of issues and 
opened several bugs.  Beyond actual "bugs", resolved by package updates, 
most issues seem related to selinux context and file labels/attributes.  

The most offered advice is to do a "fixfiles relabel".  For the issues I 
am looking at on my system this has been largely unsuccessful until last 
night, and I am wondering if there is a connection.  I have been running 
selinux in permissive mode, and Fedora Core has been in runlevel five.  I 
would log in as a regular user, open gnome-terminal, and do a "su -".  id 
-Z would confirm I am running in sysadm role.  relabeling has not resolved 
my issues.

Last night I decided to try something different.  I dropped down into 
single user mode before relabeling.  Since then, the avc denied messages 
have largely disappeared.  

Does system state matter, is single user mode irrelevant, or is there some 
other issue here?





More information about the fedora-test-list mailing list