restorecon isn't restoring what matchpathcon shows

Stephen Smalley sds at tycho.nsa.gov
Fri Nov 21 14:20:57 UTC 2008


On Fri, 2008-11-21 at 09:11 -0500, Chuck Anderson wrote:
> There are a bunch of files and directories in my F10 home dirs that 
> have type unconfined_u:object_r:user_home_t, but matchpathcon says 
> they are supposed to be system_u:object_r:user_home_t.  I tried to run 
> restorecon but it isn't changing the type:
> 
> [root at l 9:06:49 /home/install]#matchpathcon /home/install/Templates
> /home/install/Templates	system_u:object_r:user_home_t:s0
> [root at l 9:06:51 /home/install]#ls -lZd Templates
> drwxr-xr-x  install install unconfined_u:object_r:user_home_t:s0 
> Templates/
> [root at l 9:06:56 /home/install]#restorecon -R Templates
> [root at l 9:07:07 /home/install]#ls -lZd Templates
> drwxr-xr-x  install install unconfined_u:object_r:user_home_t:s0 
> Templates/
> 
> [root at l 9:07:10 /home/install]#su - install
> [install at l ~]$ restorecon -R .
> [install at l ~]$ restorecon -R Templates/
> [install at l ~]$ logout
> [root at l 9:08:23 /home/install]#ls -lZd Templates
> drwxr-xr-x  install install unconfined_u:object_r:user_home_t:s0 
> Templates/
> 
> Why does this happen?

The type is correct; only the user is wrong.  restorecon ignores
differences in the user by default.  restorecon -F if you truly care.

-- 
Stephen Smalley
National Security Agency




More information about the fedora-selinux-list mailing list