aboutgitcodebugslistschat
path: root/contrib/fedora
diff options
context:
space:
mode:
authorStefano Brivio <sbrivio@redhat.com>2023-08-15 18:22:02 +0200
committerStefano Brivio <sbrivio@redhat.com>2023-08-18 13:18:34 +0200
commit479a9e1b4d9b4e426754b44fb767d252ca144e0f (patch)
treee77ae25dec9c36ebbb582a75161e3d07325378ad /contrib/fedora
parent5f1fcfffe45f943fdb2dfd530f15185e9f1e416f (diff)
downloadpasst-479a9e1b4d9b4e426754b44fb767d252ca144e0f.tar
passt-479a9e1b4d9b4e426754b44fb767d252ca144e0f.tar.gz
passt-479a9e1b4d9b4e426754b44fb767d252ca144e0f.tar.bz2
passt-479a9e1b4d9b4e426754b44fb767d252ca144e0f.tar.lz
passt-479a9e1b4d9b4e426754b44fb767d252ca144e0f.tar.xz
passt-479a9e1b4d9b4e426754b44fb767d252ca144e0f.tar.zst
passt-479a9e1b4d9b4e426754b44fb767d252ca144e0f.zip
fedora: Install pasta as hard link to ensure SELinux file context match
The Makefile installs symbolic links by default, which actually worked at some point (not by design) with SELinux, but at least on recent kernel versions it doesn't anymore: override pasta (and pasta.avx2) with hard links. Otherwise, even if the links are labeled as pasta_exec_t, SELinux will "resolve" them to passt_exec_t, and we'll have pasta running as passt_t instead of pasta_t. Signed-off-by: Stefano Brivio <sbrivio@redhat.com> Acked-by: Richard W.M. Jones <rjones@redhat.com>
Diffstat (limited to 'contrib/fedora')
-rw-r--r--contrib/fedora/passt.spec7
1 files changed, 7 insertions, 0 deletions
diff --git a/contrib/fedora/passt.spec b/contrib/fedora/passt.spec
index 8d28ef6..d0c6895 100644
--- a/contrib/fedora/passt.spec
+++ b/contrib/fedora/passt.spec
@@ -54,10 +54,17 @@ This package adds SELinux enforcement to passt(1) and pasta(1).
%make_build VERSION="%{version}-%{release}.%{_arch}"
%install
+
%make_install DESTDIR=%{buildroot} prefix=%{_prefix} bindir=%{_bindir} mandir=%{_mandir} docdir=%{_docdir}/%{name}
+# The Makefile creates symbolic links for pasta, but we need hard links for
+# SELinux file contexts to work as intended. Same with pasta.avx2 if present.
+ln -f %{buildroot}%{_bindir}/passt %{buildroot}%{_bindir}/pasta
%ifarch x86_64
+ln -f %{buildroot}%{_bindir}/passt.avx2 %{buildroot}%{_bindir}/pasta.avx2
+
ln -sr %{buildroot}%{_mandir}/man1/passt.1 %{buildroot}%{_mandir}/man1/passt.avx2.1
ln -sr %{buildroot}%{_mandir}/man1/pasta.1 %{buildroot}%{_mandir}/man1/pasta.avx2.1
+install -p -m 755 %{buildroot}%{_bindir}/passt.avx2 %{buildroot}%{_bindir}/pasta.avx2
%endif
pushd contrib/selinux