I have come across two different SELinux types which are unconfined_t and unlabeled_t
Can anyone tell me what is difference between them?
I have come across two different SELinux types which are unconfined_t and unlabeled_t
Can anyone tell me what is difference between them?
unlabeled_t is a special type (isid type). Initial security identifiers (isid) are a special way to label entities. It is used to label entities in scenarios that could not otherwise be addressed. For example the scenario of fail-over, initialization and fixed objects.
The unlabeled_t type is associated with both the "unlabeled" as well as the "file" isid. The unlabeled isid is used to automatically associate the type (in this case unlabeled_t) with entities that have an invalid context, and the file isid is used to automatically associate the type associated with it (in this case unlabeled_t) with entities that have no label at all.
These two common (fail over) scenario's can happen for various reasons:
SELinux is mutable at runtime in GNU/Linux, this means that one can add and remove contexts at runtime, and therefore validate and invalidate contexts. So if there is an entity in your system with a given context, and you decide to remove that context at runtime, then it gets invalidated and the unlabeled isid will automatically associate unlabeled_t with it.
When you format a new partition, or when you share a partition with a system that does not use SELinux, then that filesystem has no labels by default. The file initial sid kicks in and associates unlabeled_t with objects that have no label.
The isid contexts are associated in memory. SELinux enforces integrity by default. So everything always needs a valid label. Initial security identifiers are used to address labeling challenges that can't otherwise be addressed.
If you see unlabeled_t, then the entity either has an invalid label or no label at all. You would want to address that by associating a valid label with the entity.
unconfined_t is a "normal" type that just has a very broad set of permissions associated with it. Entities associated with the unconfined_t type are virtually unconfined by SELinux.
Because your selinux is enable. You can check it getenforce. I think better if you switch your selinux in Permissive. You need to use setenforce 0 or disable