After an successfully upgrade to f36 I observed some strange selinux error messages. So I tried to solve this with restorecon
and touch /.autorelabel ; reboot
Bad idea
Problem After a correct attempt to login (Gui), the the system asks immediately again for the login. With a wrong pw, the system asks for the correct pw.
Trying to boot the rescue system, the boot process fails. It can’t perform a ‘sulogin’
First diagnostics With some support in an other thread I was able to detect that my problem is related to selinux.
Ugly workaround Starting the system with the kernel parameter selinux=0
it is possible to login and useing the system like normal. But this is no solution, or?
Question
Since a cleanup with dnf reinstall systemd
, dnf reinstall selinux-policy.noarch
and touch /.autorelabel; reboot
didn’t helped, I’m looking for new ideas/hints.
Logs Inspecting (journalctl -p 3 -x --boot=-1
) the last boot (activated selinux) I found:
Mai 25 11:15:41 localhost.localdomain gdm-password][1859]: gkr-pam: unable to locate daemon control file
Mai 25 11:15:41 localhost.localdomain systemd[1869]: user@1000.service: Failed to execute /usr/lib/systemd/systemd: Permission denied
Mai 25 11:15:41 localhost.localdomain systemd[1869]: user@1000.service: Failed at step EXEC spawning /usr/lib/systemd/systemd: Permission denied
░░ Subject: Process /usr/lib/systemd/systemd could not be executed
░░ Defined-By: systemd
░░ Support: …
░░
░░ The process /usr/lib/systemd/systemd could not be executed and failed.
░░
░░ The error number returned by this process is ERRNO.
Mai 25 11:15:41 localhost.localdomain systemd[1]: Failed to start user@1000.service - User Manager for UID 1000.
░░ Subject: A start job for unit user@1000.service has failed
░░ Defined-By: systemd
░░ Support: …
░░
░░ A start job for unit user@1000.service has finished with a failure.
░░
░░ The job identifier is 3037 and the job result is failed.
Mai 25 11:15:41 localhost.localdomain gdm-password][1872]: gkr-pam: couldn’t run gnome-keyring-daemon: Keine Berechtigung
Mai 25 11:15:41 localhost.localdomain gdm-password][1859]: gkr-pam: gnome-keyring-daemon didn’t start properly
Also I found (journalctl | grep autorelabel
)some comments to autorelable:
Mai 25 11:14:39 localhost.localdomain selinux-autorelabel[1208]: Failed to resolve allow statement at /var/lib/selinux/targeted/tmp/modules/200/snappy/cil:302
Mai 25 11:14:39 localhost.localdomain selinux-autorelabel[1208]: Failed to resolve AST
Mai 25 11:14:39 localhost.localdomain selinux-autorelabel[1208]: genhomedircon: Failed!
Mai 25 11:14:39 localhost.localdomain selinux-autorelabel[827]: Relabeling / /boot /dev /dev/hugepages /dev/mqueue /dev/pts /dev/shm /home /run /store /sys /sys/fs/cgroup /sys/fs/pstore /sys/kernel/debug /sys/kernel/tracing /tmp
Mai 25 11:14:39 localhost.localdomain selinux-autorelabel[1211]: /sbin/setfiles: /etc/selinux/targeted/contexts/files/file_contexts.bin: context system_u:object_r:container_runtime_exec_t:s0 is invalid
Mai 25 11:14:39 localhost.localdomain selinux-autorelabel[1211]: /sbin/setfiles: /etc/selinux/targeted/contexts/files/file_contexts.homedirs.bin: context unconfined_u:object_r:snappy_home_t:s0 is invalid
Mai 25 11:14:50 localhost.localdomain selinux-autorelabel[1211]: /sbin/setfiles: conflicting specifications for /usr/bin/uic-qt5 and /usr/lib64/qt5/bin/uic, using system_u:object_r:lib_t:s0.
Mai 25 11:14:50 localhost.localdomain selinux-autorelabel[1211]: /sbin/setfiles: conflicting specifications for /usr/bin/qlalr and /usr/lib64/qt5/bin/qlalr, using system_u:object_r:lib_t:s0.
…
Mai 25 11:15:10 localhost.localdomain selinux-autorelabel[827]: Cleaning up labels on /tmp
Mai 25 11:15:10 localhost.localdomain selinux-autorelabel[1235]: ERROR: src/skipcpio/skipcpio.c:91:main(): Cannot open file ‘/boot/1767bcd731864042b60a97dfd5130265/5.17.9-300.fc36.x86_64/initrd’
Mai 25 11:15:10 localhost.localdomain selinux-autorelabel[1236]: cpio: Vorzeitiges Ende des Archivs
Mai 25 11:15:10 localhost.localdomain selinux-autorelabel[1237]: ERROR: src/skipcpio/skipcpio.c:91:main(): Cannot open file ‘/boot/1767bcd731864042b60a97dfd5130265/5.17.9-300.fc36.x86_64/initrd’
…
Any help apreciated
Uwe