Skip to content

fix(service): don't determine selinux label for socket activation with RootImage= - #433

Open
deepin-ci-robot wants to merge 1 commit into
deepin-community:masterfrom
deepin-ci-robot:backport/fix-service-selinux-label-socket-activation-rootimage
Open

fix(service): don't determine selinux label for socket activation with RootImage=#433
deepin-ci-robot wants to merge 1 commit into
deepin-community:masterfrom
deepin-ci-robot:backport/fix-service-selinux-label-socket-activation-rootimage

Conversation

@deepin-ci-robot

Copy link
Copy Markdown
Contributor

Problem Before the Change

When a service uses RootImage= (or ExtensionImages=/ExtensionDirectories=), socket activation attempted to pre-determine the SELinux label of the service binary by chasing the executable path on the host filesystem. This cannot work because the binary lives inside the image, which is not mounted at that point, leading to failed lookups and ungraceful error handling during socket activation.

What This PR Changes

Backport of upstream commit 8017ed7e0e0ffaafcf9856f963928ca2a21340b6: move the SELinux label determination out of socket.c into a new service_determine_exec_selinux_label() function in service.c. The new function gracefully skips label determination (returning -ENODATA) when RootImage=, ExtensionImages= or ExtensionDirectories= are configured, since paths cannot be chased through images, and adds debug logging.

Problem Solved After the Change

Socket activation of services using RootImage= no longer attempts to determine the SELinux label ahead of time; the missing label is handled cleanly and gracefully.

Changes

  • Add debian/patches/fix-service-selinux-label-socket-activation-rootimage.patch
  • Modify debian/patches/series
  • Modify debian/changelog

Upstream

systemd/systemd@8017ed7

Generated-By: glm-5.3-flash
Co-Authored-By: deepin-ci-robot packages@deepin.org

…h RootImage=

We cannot determine the SELinux label ahead of time if RootImage= is
used, since we'd have to mount the image then, hence don't, and handle
this cleanly, and gracefully.

While we are at it, stop "reaching over" so much from the socket code to
the service code, and instead provide function that most of the hard
work in service.c that socket.c just calls.

While we are at it, add debug logging and stuff.

I noticed the issue when also noticing #30560, but that one is harder to
fix, hence I avoided it for now.

Changes:
  - Add debian/patches/fix-service-selinux-label-socket-activation-rootimage.patch
  - Modify debian/patches/series
  - Modify debian/changelog

Upstream: systemd/systemd@8017ed7

Generated-By: glm-5.3-flash
Co-Authored-By: deepin-ci-robot <packages@deepin.org>
@deepin-ci-robot

Copy link
Copy Markdown
Contributor Author

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign utsweetyfish for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown

TAG Bot

TAG: 255.2-4deepin68
EXISTED: no
DISTRIBUTION: unstable

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant