[DSE-Dev] Bug#1149696: refpolicy: preinst unconditionally aborts on 6.x kernels, breaking autopkgtests (badpkg) and chroots/containers
Viktor Pashaiev
w.paszajew at gmail.com
Fri Oct 2 12:55:11 BST 2026
Package: src:refpolicy
Version: 2:2.20260906-1
Severity: serious
Tags: patch
User: ubuntu-devel at lists.ubuntu.com
Usertags: origin-ubuntu stonking ubuntu-patch
Dear Maintainer,
In refpolicy 2:2.20260906-1, an unconditional abort was added to debian/preinst.policy:
VER=$(uname -r |cut -c1)
if [ "$VER" -eq "6" ]; then
echo "This policy fails to load on Debian 6.x kernels so aborting"
exit 1
fi
This check causes severe regressions across Debian and Ubuntu:
1. It blocks installation and upgrade on any 6.x kernel, including the standard Debian trixie kernel (6.12) and current Ubuntu kernels.
2. Checking uname -r against the running kernel breaks package installation inside containers (LXC, Docker), chroots, debootstrap, disk image builders, and CI testbeds. In these environments, SELinux is inactive and the running host kernel is unrelated to policy usage.
3. In debian/postinst.policy, semodule is already called with -n (noreload) whenever SELinux is not active or not the configured flavour:
if [ "${SELINUXTYPE}" != "${flavour}" ] || ! selinuxenabled; then
noreload='-n'
fi
Therefore, when SELinux is not active, the policy is never loaded into the kernel during package installation.
4. Autopkgtests for refpolicy (validate-default, validate-mls) fail on all 6.x architectures with "badpkg" because the packages cannot even be unpacked. This is currently blocking the migration of refpolicy 2:2.20260906-1 to Debian testing across amd64, arm64, armhf, ppc64el, and i386.
To resolve this without risking kernel panics on systems actively running SELinux on 6.x kernels, the check should only evaluate if SELinux is actually active on the system (selinuxenabled). If SELinux is inactive, chroot/container installations and autopkgtests should proceed cleanly.
This issue is also tracked in Ubuntu at:
https://bugs.launchpad.net/ubuntu/+source/refpolicy/+bug/2169263
The patch below guards the preinst check with a selinuxenabled test:
--- a/debian/preinst.policy
+++ b/debian/preinst.policy
@@ -1,9 +1,11 @@
#!/bin/sh
set -e
-VER=$(uname -r |cut -c1)
-if [ "$VER" -eq "6" ]; then
- echo "This policy fails to load on Debian 6.x kernels so aborting"
- exit 1
+if [ -x /usr/sbin/selinuxenabled ] && selinuxenabled; then
+ VER=$(uname -r | cut -d. -f1)
+ if [ "$VER" = "6" ]; then
+ echo "This policy fails to load on Debian 6.x kernels so aborting"
+ exit 1
+ fi
fi
More information about the SELinux-devel
mailing list