Re: difference between setfiles and restorecon
Henry Zhang <[email protected]> Tue, 13 Jun 2023 08:26:48 -0700
| Newsgroups | gmane.linux.redhat.fedora.selinux |
|---|---|
| Message-ID | <CANTW0yqTWTnq+9kkzvgm8dnr1vw5F0CrW-TeXHue1ObaCQD9gw@mail.gmail.com> |
Vit, I can do it with: setfiles -v /etc/selinux/mcs/contexts/files/file_contexts /home/root/yolo Relabeled /home/root/yolo from root:object_r:unlabeled_t:s0 to root:object_r:user_home_t:s0 when I use "restorecon -R -v /home/root/yolo" Relabeled /sysroot/home/root/yolo from root:object_r:user_home_t:s0 to root:object_r:root_home_t:s0 setfiles relabels yolo back to user_home_t and restorecon relabels yolo back to root_home_t Should setfiles or restorecon be used for me? ---henry On Mon, Jun 12, 2023 at 11:59 PM Vit Mojzis <[email protected]> wrote: > > > On 6/12/23 17:20, Henry Zhang wrote: > > Vit, > > Thanks for the links. > I can use restorecon to recover to default value if file content is > changed by the chcon command. > But setfiles does nothing when the file is changed by chcon. > > May I change something and let setfiles recover it? > > > Sure. But you need to specify the full path (unlike when using restorecon, > which uses "realpath" to get the full path on its own). > > $ touch yolo > $ ls -lZ > total 0 > -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 0 Jun 12 > 13:05 yolo > # chcon -t unlabeled_t yolo > $ ls -lZ > total 0 > -rw-r--r--. 1 root root unconfined_u:object_r:unlabeled_t:s0 0 Jun 12 > 13:05 yolo > # setfiles -v /etc/selinux/targeted/contexts/files/file_contexts > /home/testuser/yolo > Relabeled /home/testuser/yolo from unconfined_u:object_r:unlabeled_t:s0 to > unconfined_u:object_r:user_home_t:s0 > > Vit > > > ---henry > > On Mon, Jun 12, 2023 at 6:15 AM Vit Mojzis <[email protected]> wrote: > >> Hi, >> let me walk you through the steps to find this info on your own. >> >> # dnf provides setfiles >> policycoreutils-3.3-4.fc36.x86_64 : SELinux policy core utilities >> # dnf provides restorecon >> policycoreutils-3.3-4.fc36.x86_64 : SELinux policy core utilities >> >> So both utilities are shipped as part of policycoreutils package. >> The package is build from the following repository: >> https://src.fedoraproject.org/rpms/policycoreutils >> The spec file >> ( >> https://src.fedoraproject.org/rpms/policycoreutils/blob/rawhide/f/policycoreutils.spec#_18) >> >> shows that the source code repository is >> https://github.com/SELinuxProject/selinux >> >> $ git clone https://github.com/SELinuxProject/selinux ; cd selinux >> $ find -name setfiles.c >> ./policycoreutils/setfiles/setfiles.c >> >> This is actually the source file for both tools. Their behavior changes >> based on the executable name >> >> https://github.com/SELinuxProject/selinux/blob/main/policycoreutils/setfiles/setfiles.c#L178 >> >> Hope this helps, >> Vit >> >> On 6/8/23 20:01, Henry Zhang wrote: >> > Hi folks, >> > >> > I want to know the difference between setfiles and restorecon. >> > Where can I get source codes of setfiles and restorecon? >> > >> > ---henry >> > >> > _______________________________________________ >> > selinux mailing list -- [email protected] >> > To unsubscribe send an email to [email protected] >> > Fedora Code of Conduct: >> https://docs.fedoraproject.org/en-US/project/code-of-conduct/ >> > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines >> > List Archives: >> https://lists.fedoraproject.org/archives/list/[email protected] >> > Do not reply to spam, report it: >> https://pagure.io/fedora-infrastructure/new_issue >> _______________________________________________ >> selinux mailing list -- [email protected] >> To unsubscribe send an email to [email protected] >> Fedora Code of Conduct: >> https://docs.fedoraproject.org/en-US/project/code-of-conduct/ >> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines >> List Archives: >> https://lists.fedoraproject.org/archives/list/[email protected] >> Do not reply to spam, report it: >> https://pagure.io/fedora-infrastructure/new_issue >> > > _______________________________________________ selinux mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue