[From nobody Sat Oct  3 07:35:10 2026
Received: (at submit) by bugs.debian.org; 2 Oct 2026 11:55:16 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-15.2 required=4.0 tests=BAYES_00,
 BODY_INCLUDES_PACKAGE,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,
 DKIM_VALID_EF,FREEMAIL_FROM,HAS_PACKAGE,RCVD_IN_DNSWL_NONE,
 SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 50; hammy, 150; neutral, 86; spammy,
 0. spammytokens: hammytokens:0.000-+--trixie, 0.000-+--armhf,
 0.000-+--autopkgtests, 0.000-+--chroots, 0.000-+--Maintainer
Return-path: &lt;w.paszajew@gmail.com&gt;
Received: from mail-wr2-x0f.google.com ([2a00:1450:4864:30::f]:37359)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_128_GCM:128)
 (Exim 4.96) (envelope-from &lt;w.paszajew@gmail.com&gt;)
 id 1xCbr8-003EUA-26 for submit@bugs.debian.org;
 Fri, 02 Oct 2026 11:55:16 +0000
Received: by mail-wr2-x0f.google.com with SMTP id
 ffacd0b85a97d-48b0f4efe31so1000525f8f.2
 for &lt;submit@bugs.debian.org&gt;; Fri, 02 Oct 2026 04:55:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=gmail.com; s=20251104; t=1790942112; x=1791546912; darn=bugs.debian.org;
 h=mime-version:content-transfer-encoding:content-type:message-id:date
 :subject:to:from:from:to:cc:subject:date:message-id:reply-to
 :content-type; bh=Xgo4GyUXyG7zK0aeXmR36Fs87ArjVjJbicU1gQRki7w=;
 b=l10FYD1zxKYTZPhGrAdHHkjD82RtduR9bNX3sQKkPiLGXWsCtqMwBZrEdDGQnNXDW4
 9uwJl0c1l7uaRm1HYovAUTuhVZ+0H/9zebgArZnKhJKpRkZ9teBbaYrW3EInPoUQ3Aix
 90NwZ+p/B8tOKiBk/jKiJIPP0P16o+XHF0fds51AYCeEr9YQdItxp/Yvz8vpWssQcqNa
 Ay5EdWYj29FKjT7eCJ1uXRy6FqAoTXVVKr51DRAnPgl2FU+sAebkvDw0A5YTU0K03yVt
 HWaMMFAjDuCBN6lol57XCCeZoFF1fwhm3iNo6rDYNIYptLFaEZmxqZfDgla9yEoKJk3F
 DudA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20260707; t=1790942112; x=1791546912;
 h=mime-version:content-transfer-encoding:content-type:message-id:date
 :subject:to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date
 :message-id:reply-to:content-type;
 bh=Xgo4GyUXyG7zK0aeXmR36Fs87ArjVjJbicU1gQRki7w=;
 b=mKUC3UpSp3cuLXTLSkea78IcdWqytUeLAUt+lKD82EM3dBb3Z6jyXtSrabHBVly1Ze
 emDuHr+9eQyYSZ1PxodMSOgWxEKCQKWtqCXeeGn4XQ/glMBpzjpM9D+cYCpLMr9H05AF
 QGgqxTwOKr/JG/dIARqBd2opu0RE7EPbIulx3j1KKy3w72K5Kpm7dCjR7FwOIoukle8Q
 M1pEt/NiiPeGpqNHJrZsWezJv53iSX2h+7DBg+qrG/YIy9966POhUs9/LxQj447TsvoH
 FB/4XMUjBqJqiK+qfz1IsRPZdgt5dnbfk2I46DYXHOZUEwMbT5xF9Edl2ci+yO6poim3
 rO/w==
X-Gm-Message-State: AFq9FYKM2xJujGaP7uysZDmfvrCw1QYvxGzn0M3o6ol65X1Zy2TcyvXB
 g8UKbvAt5Yrx3yK4gcaqcM4ca4rMCif9rUTFbdeGicSD6vp7w45HU2Ef7zkegA==
X-Gm-Gg: AYBFou1RDpNZljJZS7e0lkB60l5l58pOvlLcbiMauMb1PkkKhTS4/8BdaSNc0glnuR7
 4ingLl9wKl+7wYWT0SwP/EnTtTnsjxAEuRW65wy3IvyU1iIIGx62scOIcMarEAJ1WP9as/h8gHu
 4B+/UUhsIi6fctmdyIoCH8q2HXTfwdKj/rriwmF8NtmEAMu8oKjcvr9Llh5peDSJv1g6X7crSvE
 kBO5f4C78a4vcXgAr8G/NiP775IgKqYUnJSeSkHMRwr6lI/bpAw9CdvooPG0r+mePHIDfELgnYE
 cflFOgu4csAgN8pn3Mblgo4yEyKm2CQ9b957tk0cR8UTH2nEj2YCPzsfl9taJb6A8bdZHHOuUtH
 Z+lJtpKOuixZJMg2avjhw69CbsB2Aj8st6PpubgQ8xiFxg7L9AMasoGMtXKLJWawOhLWDoGJ3BU
 FgcCj792jbCEXYJ26aVvM+UVEY9s3K/NNIqGZFNM5Mt9S7vx/sJPpqFO03C23oGbQfyrXaY4FYV
 gr1+z7J1V4TSMCQAKKq/3jsBkttUoIHWMJf86R+DIXzHEmqH5xQ+0u+kN6rq1Q=
X-Received: by 2002:a05:6000:98d:b0:48b:7e:eebe with SMTP id
 ffacd0b85a97d-48b12716e1amr5027912f8f.24.1790942112229; 
 Fri, 02 Oct 2026 04:55:12 -0700 (PDT)
Received: from DESKTOP-IH7LN89.home (83.22.35.167.ipv4.supernova.orange.pl.
 [83.22.35.167]) by smtp.gmail.com with ESMTPSA id
 ffacd0b85a97d-48b382f98ffsm5360248f8f.38.2026.10.02.04.55.11
 for &lt;submit@bugs.debian.org&gt;
 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
 Fri, 02 Oct 2026 04:55:11 -0700 (PDT)
From: Viktor Pashaiev &lt;w.paszajew@gmail.com&gt;
To: submit@bugs.debian.org
Subject: refpolicy: preinst unconditionally aborts on 6.x kernels, breaking
 autopkgtests (badpkg) and chroots/containers
Date: Fri, 02 Oct 2026 13:55:11 +0200
Message-ID: &lt;179094211123.24060.11624123572480188950@gmail.com&gt;
Content-Type: text/plain; charset=&quot;utf-8&quot;
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Delivered-To: submit@bugs.debian.org

Package: src:refpolicy
Version: 2:2.20260906-1
Severity: serious
Tags: patch
User: ubuntu-devel@lists.ubuntu.com
Usertags: origin-ubuntu stonking ubuntu-patch

Dear Maintainer,

In refpolicy 2:2.20260906-1, an unconditional abort was added to debian/prein=
st.policy:

  VER=3D$(uname -r |cut -c1)
  if [ &quot;$VER&quot; -eq &quot;6&quot; ]; then
    echo &quot;This policy fails to load on Debian 6.x kernels so aborting&quot;
    exit 1
  fi

This check causes severe regressions across Debian and Ubuntu:

1. It blocks installation and upgrade on any 6.x kernel, including the standa=
rd Debian trixie kernel (6.12) and current Ubuntu kernels.
2. Checking uname -r against the running kernel breaks package installation i=
nside containers (LXC, Docker), chroots, debootstrap, disk image builders, an=
d CI testbeds. In these environments, SELinux is inactive and the running hos=
t kernel is unrelated to policy usage.
3. In debian/postinst.policy, semodule is already called with -n (noreload) w=
henever SELinux is not active or not the configured flavour:
     if [ &quot;${SELINUXTYPE}&quot; !=3D &quot;${flavour}&quot; ] || ! selinuxenabled; then
         noreload=3D'-n'
     fi
   Therefore, when SELinux is not active, the policy is never loaded into the=
 kernel during package installation.
4. Autopkgtests for refpolicy (validate-default, validate-mls) fail on all 6.=
x architectures with &quot;badpkg&quot; because the packages cannot even be unpacked. T=
his is currently blocking the migration of refpolicy 2:2.20260906-1 to Debian=
 testing across amd64, arm64, armhf, ppc64el, and i386.

To resolve this without risking kernel panics on systems actively running SEL=
inux on 6.x kernels, the check should only evaluate if SELinux is actually ac=
tive on the system (selinuxenabled). If SELinux is inactive, chroot/container=
 installations and autopkgtests should proceed cleanly.

This issue is also tracked in Ubuntu at:
https://bugs.launchpad.net/ubuntu/+source/refpolicy/+bug/2169263

The patch below guards the preinst check with a selinuxenabled test:

--- a/debian/preinst.policy
+++ b/debian/preinst.policy
@@ -1,9 +1,11 @@
 #!/bin/sh
 set -e
=20
-VER=3D$(uname -r |cut -c1)
-if [ &quot;$VER&quot; -eq &quot;6&quot; ]; then
-  echo &quot;This policy fails to load on Debian 6.x kernels so aborting&quot;
-  exit 1
+if [ -x /usr/sbin/selinuxenabled ] &amp;&amp; selinuxenabled; then
+  VER=3D$(uname -r | cut -d. -f1)
+  if [ &quot;$VER&quot; =3D &quot;6&quot; ]; then
+    echo &quot;This policy fails to load on Debian 6.x kernels so aborting&quot;
+    exit 1
+  fi
 fi
=20
]