[systemd-devel] automount EFI system partition to /efi fails
Chris Murphy
lists at colorremedies.com
Wed Apr 25 00:47:24 UTC 2018
https://www.freedesktop.org/wiki/Specifications/DiscoverablePartitionsSpec/
*The ESP used for the current boot is automatically mounted to /efi (or
/boot as fallback),*
systemd-238-7.fc28.1.x86_64
I've commented out the /boot/efi entry in /etc/fstab and reboot but the ESP
doesn't get mounted to /efi or /boot or /boot/efi.
Full journal with systemd.log_level=debug.
https://drive.google.com/open?id=1b4Lfd0HurX4Z68T1jAHYMC0wy51tQwtk
I get a couple of confusing items:
[ 3.971099] f28h.local systemd-gpt-auto-generator[476]: /efi already
populated, ignoring.
[ 4.102022] f28h.local audit[476]: AVC avc: denied { read } for
pid=476 comm="systemd-gpt-aut" name="efi" dev="nvme0n1p9" ino=3999777
scontext=system_u:system_r:systemd_gpt_generator_t:s0
tcontext=unconfined_u:object_r:default_t:s0 tclass=dir permissive=0
It's definitely empty. But maybe it's due to the avc. chcon fails to set
the type to systemd_gpt_generator_t which itself gives me an avc.
Apr 24 18:42:49 f28h.local audit[4486]: AVC avc: denied { relabelto } for
pid=4486 comm="chcon" name="efi" dev="nvme0n1p9" ino=3999777
scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
tcontext=system_u:object_r:systemd_gpt_generator_t:s0 tclass=dir
permissive=0
Next
[ 6.291607] f28h.local systemd[715]: Followed symlinks /efi → /efi.
[ 6.291643] f28h.local systemd[715]: Applying namespace mount on /efi
[ 6.291671] f28h.local systemd[715]: Successfully mounted /efi to /efi
[ 6.294820] f28h.local systemd[715]: Remounted /efi read-only.
[ 6.314602] f28h.local systemd[715]: Remounted /sys/firmware/efi/efivars
read-only.
[ 6.316442] f28h.local systemd[724]: Followed symlinks /efi → /efi.
[ 6.316472] f28h.local systemd[724]: Applying namespace mount on /efi
[ 6.316505] f28h.local systemd[724]: Successfully mounted /efi to /efi
[ 6.323415] f28h.local systemd[724]: Remounted /efi read-only.
[ 6.354865] f28h.local systemd[753]: Followed symlinks /efi → /efi.
[ 6.354895] f28h.local systemd[753]: Applying namespace mount on /efi
[ 6.354925] f28h.local systemd[753]: Successfully mounted /efi to /efi
[ 6.381654] f28h.local systemd[753]: Remounted /efi read-only.
[ 6.489023] f28h.local systemd[762]: Remounted /sys/firmware/efi/efivars
read-only.
And some additional repetitions but no avcs. So I'm not sure what the
problem is.
--
Chris Murphy
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.freedesktop.org/archives/systemd-devel/attachments/20180424/86c931cc/attachment-0001.html>
More information about the systemd-devel
mailing list