All of lore.kernel.org
 help / color / mirror / Atom feed
* Unreadable or missing xattr security.selinux on jffs2
@ 2014-04-18 20:06 jkmeinde
  2014-04-21 12:49 ` Stephen Smalley
  0 siblings, 1 reply; 5+ messages in thread
From: jkmeinde @ 2014-04-18 20:06 UTC (permalink / raw)
  To: selinux

[-- Attachment #1: Type: text/plain, Size: 1294 bytes --]

Hello fellow selinux users:
I apologize if this is a duplicate email, the first one I sent was from an 
address that I think is not on the list.

I am currently working on a system that uses embedded linux with a few 
jffs2 file systems on NAND flash.  Each time my device boots, several 
flash partitions are mounted to various mount points throughout my root 
fs.  Some are readonly, a couple are rw.

What I am seeing is that sometimes, when the mount happens on a rw 
partition, the label that shows for the mount point is "file_t".  This is 
not the label that was contained in the xattr on the last boot.  My 
selinux policy is set up to mark file systems which are missing the 
security.selinux attrs as file_t.  In each subsequent boot/mount, the root 
directory of the mounted filesystem remains "file_t" until I manually 
chcon or restorecon (in premissive)

Furthermore, there are no domains in the selinux policy that have 
permissions to relabel directories of the type that I am mounting.  So my 
first question is, does anyone have any idea as to how the label could 
disappear?  Has anyone ever seen behavior like this on JFFS2?

Is this more of a jffs2 question?  Other attrs like date modified, and DAC 
permissions remain intact.

I thank anyone for the consideration.

Judd

[-- Attachment #2: Type: text/html, Size: 1810 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread
* Unreadable or missing xattr security.selinux on jffs2
@ 2014-04-18 19:53 Judd Meinders
  0 siblings, 0 replies; 5+ messages in thread
From: Judd Meinders @ 2014-04-18 19:53 UTC (permalink / raw)
  To: selinux

[-- Attachment #1: Type: text/plain, Size: 1164 bytes --]

Hello fellow selinux users:

I am currently working on a system that uses embedded linux with a few
jffs2 file systems on NAND flash.  Each time my device boots, several flash
partitions are mounted to various mount points throughout my root fs.  Some
are readonly, a couple are rw.

What I am seeing is that sometimes, when the mount happens on a rw
partition, the label that shows for the mount point is "file_t".  This is
not the label that was contained in the xattr on the last boot.  My selinux
policy is set up to mark file systems which are missing the
security.selinux attrs as file_t.  In each subsequent boot/mount, the root
directory of the mounted filesystem remains "file_t" until I manually chcon
or restorecon (in premissive)

Furthermore, there are no domains in the selinux policy that have
permissions to relabel directories of the type that I am mounting.  So my
first question is, does anyone have any idea as to how the label could
disappear?  Has anyone ever seen behavior like this on JFFS2?

Is this more of a jffs2 question?  Other attrs like date modified, and DAC
permissions remain intact.

I thank anyone for the consideration.

Judd

[-- Attachment #2: Type: text/html, Size: 1356 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2014-04-21 14:08 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-04-18 20:06 Unreadable or missing xattr security.selinux on jffs2 jkmeinde
2014-04-21 12:49 ` Stephen Smalley
2014-04-21 14:08   ` jkmeinde
2014-04-21 14:08     ` Stephen Smalley
  -- strict thread matches above, loose matches on Subject: below --
2014-04-18 19:53 Judd Meinders

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.