Skip to content

Leaked selinux policy store files to the image root directory #596

@pothos

Description

@pothos

Description

These files/directories got added to the images compared to the 3066 Alpha:

+/final
+/mcs
+/mcs/active
+/mcs/active/modules
+/mcs/semanage.read.LOCK
+/mcs/semanage.trans.LOCK
+/mls
+/mls/active
+/mls/active/modules
+/mls/semanage.read.LOCK
+/mls/semanage.trans.LOCK
+/targeted
+/targeted/active
+/targeted/active/modules
+/targeted/semanage.read.LOCK
+/targeted/semanage.trans.LOCK

Impact

Possibly people are confused/concerned

Environment and steps to reproduce

FILE=flatcar_production_image_contents.txt FILESONLY=1 CUTKERNEL=1 CHANNEL_A=alpha CHANNEL_B=alpha ./package-diff 3066.0.0 3115.0.0

Expected behavior

These files should not leak to the rootfs

Additional information

Probably related to the recent selinux policy store fix

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions