restoring SELinux context using STAR fails



Hello,

I am unable to use star to restore SELinux file
contexts on FC5 (from an offline booted generic
selinux-turned-off miniboot disk; much like rescue mode).

I use star with -acl, -H=exustar etc. etc. from the FAQ.

The problem is; most of the contexts *do* get restored
- except for the symbolic links. Most notably,
files in /lib get selinux context system_u:object_u:lib_t
but the symlinks (and there are a few in /lib since
well you know) get system_u:object_u:file_t
Now linux breaks. If I run a fixfiles ('relabel')
I can see the symlinks are meant to have lib_t too
(and things work again).

The command line I use for extraction is
star -x -p -acl -xattr -H=exustar -z -C=/lib -f root.tgz

When I restore the very same archive on a running Linux
(selinux=permissive), restoring (to /tmp/lib) *does* give
me all the right contexts (that is; also for the symlinks).

So well this does look a lot like
http://www.redhat.com/archives/rhl-list/2006-April/msg06611.html

but that one is about not getting *any* context restored;
I am only asking for the symbolic link contexts...

Regards,
Klaas










--
redhat-list mailing list
unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe
https://www.redhat.com/mailman/listinfo/redhat-list



Relevant Pages

  • Re: Odd ACL question
    ... TK>Joerg Schilling's "star" archives ACLs as follows: ... If you, for example, restore on a system that usually gets its passwd from ... As far as I know there are options to star that let you select the exact ...
    (freebsd-hackers)
  • Re: Non-Pessimistic Modern SF
    ... Much as I hate to bring it up, I'd wager most recent _Star Trek_ ... I suppose that is what happens when you restore the old republic without ... 1: Let's see: First Republic, First Empire, Monarchy, ... Monarchy, Second Republic, Second Empire, Third Republic, ...
    (rec.arts.sf.written)