diff --git a/0005-libsemanage-Mute-error-messages-from-selinux_restore.patch b/0005-libsemanage-Mute-error-messages-from-selinux_restore.patch new file mode 100644 index 0000000..5bc047a --- /dev/null +++ b/0005-libsemanage-Mute-error-messages-from-selinux_restore.patch @@ -0,0 +1,64 @@ +From 217f00e1ff962fff7e7babc619d29dfc30cb72f6 Mon Sep 17 00:00:00 2001 +From: Vit Mojzis +Date: Thu, 12 Dec 2024 19:44:25 +0100 +Subject: [PATCH] libsemanage: Mute error messages from selinux_restorecon +Content-type: text/plain + +Mute error messages produced by selinux_restorecon when rebuilding the +policy store to avoid error messages in containers, image mode, etc. + +Fixes: + #podman build --security-opt=label=disable --cap-add=all --device /dev/fuse -t quay.io/jlebon/fedora-bootc:tier-x . --build-arg MANIFEST=fedora-tier-x.yaml --from quay.io/fedora/fedora:rawhide +... +Could not set context for /etc/selinux/targeted/tmp/modules/100/rtas/lang_ext: Operation not supported +Could not set context for /etc/selinux/targeted/tmp/modules/100/rtas: Operation not supported +Could not set context for /etc/selinux/targeted/tmp/modules/100/rtkit/cil: Operation not supported +Could not set context for /etc/selinux/targeted/tmp/modules/100/rtkit/hll: Operation not supported +... + +https://bugzilla.redhat.com/show_bug.cgi?id=2326348 + +Signed-off-by: Vit Mojzis +Acked-by: James Carter +--- + libsemanage/src/semanage_store.c | 16 +++++++++++++++- + 1 file changed, 15 insertions(+), 1 deletion(-) + +diff --git a/libsemanage/src/semanage_store.c b/libsemanage/src/semanage_store.c +index c26f5667b3cd..fc77e4817c4d 100644 +--- a/libsemanage/src/semanage_store.c ++++ b/libsemanage/src/semanage_store.c +@@ -3026,15 +3026,29 @@ int semanage_nc_sort(semanage_handle_t * sh, const char *buf, size_t buf_len, + return 0; + } + ++/* log_callback muting all logs */ ++static int __attribute__ ((format(printf, 2, 3))) ++log_callback_mute(__attribute__((unused)) int type, __attribute__((unused)) const char *fmt, ...) ++{ ++ return 0; ++} ++ + /* Make sure the file context and ownership of files in the policy + * store does not change */ + void semanage_setfiles(const char *path){ + struct stat sb; + int fd; ++ union selinux_callback cb_orig = selinux_get_callback(SELINUX_CB_LOG); ++ union selinux_callback cb = { .func_log = log_callback_mute }; ++ ++ /* Mute all logs */ ++ selinux_set_callback(SELINUX_CB_LOG, cb); ++ + /* Fix the user and role portions of the context, ignore errors + * since this is not a critical operation */ + selinux_restorecon(path, SELINUX_RESTORECON_SET_SPECFILE_CTX | SELINUX_RESTORECON_IGNORE_NOENTRY); +- ++ /* restore log_logging */ ++ selinux_set_callback(SELINUX_CB_LOG, cb_orig); + /* Make sure "path" is owned by root */ + if ((geteuid() != 0 || getegid() != 0) && + ((fd = open(path, O_RDONLY)) != -1)){ +-- +2.48.1 + diff --git a/0006-libsemanage-Set-new-restorecon-handle-before-doing-r.patch b/0006-libsemanage-Set-new-restorecon-handle-before-doing-r.patch new file mode 100644 index 0000000..58908c9 --- /dev/null +++ b/0006-libsemanage-Set-new-restorecon-handle-before-doing-r.patch @@ -0,0 +1,37 @@ +From d19aee085e00713fd8ed525bf2c041fb2081bc6d Mon Sep 17 00:00:00 2001 +From: James Carter +Date: Wed, 22 Jan 2025 10:58:28 -0500 +Subject: [PATCH] libsemanage: Set new restorecon handle before doing + restorecon +Content-type: text/plain + +In semanage_setfiles(), need to reset the restorecon handle to make +sure restorecon is not operating on old selabel data. + +Signed-off-by: James Carter +--- + libsemanage/src/semanage_store.c | 5 +++++ + 1 file changed, 5 insertions(+) + +diff --git a/libsemanage/src/semanage_store.c b/libsemanage/src/semanage_store.c +index fc77e4817c4d..aca8274dfa04 100644 +--- a/libsemanage/src/semanage_store.c ++++ b/libsemanage/src/semanage_store.c +@@ -3038,9 +3038,14 @@ log_callback_mute(__attribute__((unused)) int type, __attribute__((unused)) cons + void semanage_setfiles(const char *path){ + struct stat sb; + int fd; ++ struct selabel_handle *sehandle; ++ + union selinux_callback cb_orig = selinux_get_callback(SELINUX_CB_LOG); + union selinux_callback cb = { .func_log = log_callback_mute }; + ++ sehandle = selinux_restorecon_default_handle(); ++ selinux_restorecon_set_sehandle(sehandle); ++ + /* Mute all logs */ + selinux_set_callback(SELINUX_CB_LOG, cb); + +-- +2.48.1 + diff --git a/libsemanage.spec b/libsemanage.spec index 523b3b6..55087ca 100644 --- a/libsemanage.spec +++ b/libsemanage.spec @@ -1,10 +1,10 @@ %define libsepolver 3.6-1 -%define libselinuxver 3.6-1 +%define libselinuxver 3.6-3 Summary: SELinux binary policy manipulation library Name: libsemanage Version: 3.6 -Release: 3%{?dist} +Release: 4%{?dist} License: LGPLv2+ Source0: https://github.com/SELinuxProject/selinux/releases/download/3.6/libsemanage-3.6.tar.gz # fedora-selinux/selinux: git checkout c9s; git format-patch -N 3.6 -- libsemanage @@ -14,6 +14,8 @@ Patch0001: 0001-Revert-Do-not-automatically-install-Russian-translat.patch Patch0002: 0002-Revert-libsemanage-Remove-the-Russian-translations.patch Patch0003: 0003-libsemanage-Preserve-file-context-and-ownership-in-p.patch Patch0004: 0004-libsemanage-open-lock_file-with-O_RDWR.patch +Patch0005: 0005-libsemanage-Mute-error-messages-from-selinux_restore.patch +Patch0006: 0006-libsemanage-Set-new-restorecon-handle-before-doing-r.patch # Patch list end URL: https://github.com/SELinuxProject/selinux/wiki Source1: semanage.conf @@ -157,6 +159,9 @@ cp %{SOURCE1} ${RPM_BUILD_ROOT}%{_sysconfdir}/selinux/semanage.conf %{_libexecdir}/selinux/semanage_migrate_store %changelog +* Tue Jan 28 2025 Petr Lautrbach - 3.6-4 +- Set new restorecon handle before doing restorecon (RHEL-76472) + * Fri Nov 08 2024 Petr Lautrbach - 3.6-3 - open lock_file with O_RDWR (RHEL-60503)