selinux fixfiles context
Thomas Molina
tmolina at cablespeed.com
Thu Apr 15 10:47:34 UTC 2004
Does it matter in which context corrective actions for selinux problems
are performed? Since starting to experiment with test2 I have seen a number of issues and
opened several bugs. Beyond actual "bugs", resolved by package updates,
most issues seem related to selinux context and file labels/attributes.
The most offered advice is to do a "fixfiles relabel". For the issues I
am looking at on my system this has been largely unsuccessful until last
night, and I am wondering if there is a connection. I have been running
selinux in permissive mode, and Fedora Core has been in runlevel five. I
would log in as a regular user, open gnome-terminal, and do a "su -". id
-Z would confirm I am running in sysadm role. relabeling has not resolved
my issues.
Last night I decided to try something different. I dropped down into
single user mode before relabeling. Since then, the avc denied messages
have largely disappeared.
Does system state matter, is single user mode irrelevant, or is there some
other issue here?
More information about the fedora-test-list
mailing list