libsemanage-3.6-3

- Set new restorecon handle before doing restorecon (RHEL-76472)
Resolves: RHEL-76472
This commit is contained in:
Petr Lautrbach 2025-01-28 13:31:40 +01:00
parent 8a2f230fd0
commit a670a49d65
3 changed files with 108 additions and 2 deletions

View File

@ -0,0 +1,64 @@
From 217f00e1ff962fff7e7babc619d29dfc30cb72f6 Mon Sep 17 00:00:00 2001
From: Vit Mojzis <vmojzis@redhat.com>
Date: Thu, 12 Dec 2024 19:44:25 +0100
Subject: [PATCH] libsemanage: Mute error messages from selinux_restorecon
Content-type: text/plain
Mute error messages produced by selinux_restorecon when rebuilding the
policy store to avoid error messages in containers, image mode, etc.
Fixes:
#podman build --security-opt=label=disable --cap-add=all --device /dev/fuse -t quay.io/jlebon/fedora-bootc:tier-x . --build-arg MANIFEST=fedora-tier-x.yaml --from quay.io/fedora/fedora:rawhide
...
Could not set context for /etc/selinux/targeted/tmp/modules/100/rtas/lang_ext: Operation not supported
Could not set context for /etc/selinux/targeted/tmp/modules/100/rtas: Operation not supported
Could not set context for /etc/selinux/targeted/tmp/modules/100/rtkit/cil: Operation not supported
Could not set context for /etc/selinux/targeted/tmp/modules/100/rtkit/hll: Operation not supported
...
https://bugzilla.redhat.com/show_bug.cgi?id=2326348
Signed-off-by: Vit Mojzis <vmojzis@redhat.com>
Acked-by: James Carter <jwcart2@gmail.com>
---
libsemanage/src/semanage_store.c | 16 +++++++++++++++-
1 file changed, 15 insertions(+), 1 deletion(-)
diff --git a/libsemanage/src/semanage_store.c b/libsemanage/src/semanage_store.c
index c26f5667b3cd..fc77e4817c4d 100644
--- a/libsemanage/src/semanage_store.c
+++ b/libsemanage/src/semanage_store.c
@@ -3026,15 +3026,29 @@ int semanage_nc_sort(semanage_handle_t * sh, const char *buf, size_t buf_len,
return 0;
}
+/* log_callback muting all logs */
+static int __attribute__ ((format(printf, 2, 3)))
+log_callback_mute(__attribute__((unused)) int type, __attribute__((unused)) const char *fmt, ...)
+{
+ return 0;
+}
+
/* Make sure the file context and ownership of files in the policy
* store does not change */
void semanage_setfiles(const char *path){
struct stat sb;
int fd;
+ union selinux_callback cb_orig = selinux_get_callback(SELINUX_CB_LOG);
+ union selinux_callback cb = { .func_log = log_callback_mute };
+
+ /* Mute all logs */
+ selinux_set_callback(SELINUX_CB_LOG, cb);
+
/* Fix the user and role portions of the context, ignore errors
* since this is not a critical operation */
selinux_restorecon(path, SELINUX_RESTORECON_SET_SPECFILE_CTX | SELINUX_RESTORECON_IGNORE_NOENTRY);
-
+ /* restore log_logging */
+ selinux_set_callback(SELINUX_CB_LOG, cb_orig);
/* Make sure "path" is owned by root */
if ((geteuid() != 0 || getegid() != 0) &&
((fd = open(path, O_RDONLY)) != -1)){
--
2.48.1

View File

@ -0,0 +1,37 @@
From d19aee085e00713fd8ed525bf2c041fb2081bc6d Mon Sep 17 00:00:00 2001
From: James Carter <jwcart2@gmail.com>
Date: Wed, 22 Jan 2025 10:58:28 -0500
Subject: [PATCH] libsemanage: Set new restorecon handle before doing
restorecon
Content-type: text/plain
In semanage_setfiles(), need to reset the restorecon handle to make
sure restorecon is not operating on old selabel data.
Signed-off-by: James Carter <jwcart2@gmail.com>
---
libsemanage/src/semanage_store.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/libsemanage/src/semanage_store.c b/libsemanage/src/semanage_store.c
index fc77e4817c4d..aca8274dfa04 100644
--- a/libsemanage/src/semanage_store.c
+++ b/libsemanage/src/semanage_store.c
@@ -3038,9 +3038,14 @@ log_callback_mute(__attribute__((unused)) int type, __attribute__((unused)) cons
void semanage_setfiles(const char *path){
struct stat sb;
int fd;
+ struct selabel_handle *sehandle;
+
union selinux_callback cb_orig = selinux_get_callback(SELINUX_CB_LOG);
union selinux_callback cb = { .func_log = log_callback_mute };
+ sehandle = selinux_restorecon_default_handle();
+ selinux_restorecon_set_sehandle(sehandle);
+
/* Mute all logs */
selinux_set_callback(SELINUX_CB_LOG, cb);
--
2.48.1

View File

@ -1,10 +1,10 @@
%define libsepolver 3.6-1
%define libselinuxver 3.6-1
%define libselinuxver 3.6-3
Summary: SELinux binary policy manipulation library
Name: libsemanage
Version: 3.6
Release: 3%{?dist}
Release: 4%{?dist}
License: LGPLv2+
Source0: https://github.com/SELinuxProject/selinux/releases/download/3.6/libsemanage-3.6.tar.gz
# fedora-selinux/selinux: git checkout c9s; git format-patch -N 3.6 -- libsemanage
@ -14,6 +14,8 @@ Patch0001: 0001-Revert-Do-not-automatically-install-Russian-translat.patch
Patch0002: 0002-Revert-libsemanage-Remove-the-Russian-translations.patch
Patch0003: 0003-libsemanage-Preserve-file-context-and-ownership-in-p.patch
Patch0004: 0004-libsemanage-open-lock_file-with-O_RDWR.patch
Patch0005: 0005-libsemanage-Mute-error-messages-from-selinux_restore.patch
Patch0006: 0006-libsemanage-Set-new-restorecon-handle-before-doing-r.patch
# Patch list end
URL: https://github.com/SELinuxProject/selinux/wiki
Source1: semanage.conf
@ -157,6 +159,9 @@ cp %{SOURCE1} ${RPM_BUILD_ROOT}%{_sysconfdir}/selinux/semanage.conf
%{_libexecdir}/selinux/semanage_migrate_store
%changelog
* Tue Jan 28 2025 Petr Lautrbach <lautrbach@redhat.com> - 3.6-4
- Set new restorecon handle before doing restorecon (RHEL-76472)
* Fri Nov 08 2024 Petr Lautrbach <lautrbach@redhat.com> - 3.6-3
- open lock_file with O_RDWR (RHEL-60503)