[DSE-Dev] Bug#1149696: refpolicy: preinst unconditionally aborts on 6.x kernels, breaking autopkgtests (badpkg) and chroots/containers

Viktor Pashaiev w.paszajew at gmail.com
Fri Oct 2 12:55:11 BST 2026


Package: src:refpolicy
Version: 2:2.20260906-1
Severity: serious
Tags: patch
User: ubuntu-devel at lists.ubuntu.com
Usertags: origin-ubuntu stonking ubuntu-patch

Dear Maintainer,

In refpolicy 2:2.20260906-1, an unconditional abort was added to debian/preinst.policy:

  VER=$(uname -r |cut -c1)
  if [ "$VER" -eq "6" ]; then
    echo "This policy fails to load on Debian 6.x kernels so aborting"
    exit 1
  fi

This check causes severe regressions across Debian and Ubuntu:

1. It blocks installation and upgrade on any 6.x kernel, including the standard Debian trixie kernel (6.12) and current Ubuntu kernels.
2. Checking uname -r against the running kernel breaks package installation inside containers (LXC, Docker), chroots, debootstrap, disk image builders, and CI testbeds. In these environments, SELinux is inactive and the running host kernel is unrelated to policy usage.
3. In debian/postinst.policy, semodule is already called with -n (noreload) whenever SELinux is not active or not the configured flavour:
     if [ "${SELINUXTYPE}" != "${flavour}" ] || ! selinuxenabled; then
         noreload='-n'
     fi
   Therefore, when SELinux is not active, the policy is never loaded into the kernel during package installation.
4. Autopkgtests for refpolicy (validate-default, validate-mls) fail on all 6.x architectures with "badpkg" because the packages cannot even be unpacked. This is currently blocking the migration of refpolicy 2:2.20260906-1 to Debian testing across amd64, arm64, armhf, ppc64el, and i386.

To resolve this without risking kernel panics on systems actively running SELinux on 6.x kernels, the check should only evaluate if SELinux is actually active on the system (selinuxenabled). If SELinux is inactive, chroot/container installations and autopkgtests should proceed cleanly.

This issue is also tracked in Ubuntu at:
https://bugs.launchpad.net/ubuntu/+source/refpolicy/+bug/2169263

The patch below guards the preinst check with a selinuxenabled test:

--- a/debian/preinst.policy
+++ b/debian/preinst.policy
@@ -1,9 +1,11 @@
 #!/bin/sh
 set -e
 
-VER=$(uname -r |cut -c1)
-if [ "$VER" -eq "6" ]; then
-  echo "This policy fails to load on Debian 6.x kernels so aborting"
-  exit 1
+if [ -x /usr/sbin/selinuxenabled ] && selinuxenabled; then
+  VER=$(uname -r | cut -d. -f1)
+  if [ "$VER" = "6" ]; then
+    echo "This policy fails to load on Debian 6.x kernels so aborting"
+    exit 1
+  fi
 fi
 



More information about the SELinux-devel mailing list