Wind River Support Network

HomeDefectsCGP8-235
Not to be fixed

CGP8-235 : The levels for /etc/selinux/wr-mls/{policy/policy.29, seusers} changed by semanage

Created: Mar 2, 2016    Updated: Apr 28, 2018
Resolved Date: Apr 17, 2018
Found In Version: 8.0
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

root@SDP_Wildcat_Pass-3-C1:~# ls -Z /etc/selinux/wr-mls/policy/policy.29
root:object_r:policy_config_t:s0 /etc/selinux/wr-mls/policy/policy.29
root@SDP_Wildcat_Pass-3-C1:~# ls -Z /etc/selinux/wr-mls/seusers
root:object_r:selinux_config_t:s0 /etc/selinux/wr-mls/seusers

root@SDP_Wildcat_Pass-3-C1:~# matchpathcon /etc/selinux/wr-mls/policy/policy.29
/etc/selinux/wr-mls/policy/policy.29 system_u:object_r:policy_config_t:s15:c0.c1023
root@SDP_Wildcat_Pass-3-C1:~# matchpathcon /etc/selinux/wr-mls/seusers
/etc/selinux/wr-mls/seusers system_u:object_r:selinux_config_t:s15:c0.c1023

Steps to Reproduce

$ configure --enable-board=intel-x86-64 --enable-kernel=cgl --enable-rootfs=glibc-cgl
$ make fs

# boot up target
root@SDP_Wildcat_Pass-3-C1:~# useradd t1
root@SDP_Wildcat_Pass-3-C1:~# passwd t1
root@SDP_Wildcat_Pass-3-C1:~# newrole -r secadm_r
root@SDP_Wildcat_Pass-3-C1:~# semanage login -a -s staff_u -r s0-s15:c0.c1023 t1
root@SDP_Wildcat_Pass-3-C1:~# ls -Z /etc/selinux/wr-mls/policy/policy.29
root@SDP_Wildcat_Pass-3-C1:~# ls -Z /etc/selinux/wr-mls/seusers
root@SDP_Wildcat_Pass-3-C1:~# matchpathcon /etc/selinux/wr-mls/policy/policy.29
root@SDP_Wildcat_Pass-3-C1:~# matchpathcon /etc/selinux/wr-mls/seusers
Live chat
Online