Note: This is a public test instance of Red Hat Bugzilla. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback at bugzilla.redhat.com.
Bug 1811099
Summary: | SELinux is preventing ModemManager from using the setsched access on a process | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Paul Whalen <pwhalen> |
Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> |
Status: | CLOSED DUPLICATE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 32 | CC: | dwalsh, grepl.miroslav, lvrabec, plautrba, vmojzis, zpytela |
Target Milestone: | --- | Keywords: | Triaged |
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2020-03-06 16:22:54 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Paul Whalen
2020-03-06 15:36:44 UTC
Paul, Thank you for reporting the issue. This AVC will be dontaudited in the next version of the selinux-policy package. Apart from the denial reported, do you also see any functionality issue? Thanks, no functionality issues so far. I saw a few more right after install, if you would like I can open separate bugs. Listed below: time->Fri Mar 6 10:22:17 2020 type=AVC msg=audit(1583508137.943:147): avc: denied { sys_nice } for pid=1189 comm="pcscd" capability=23 scontext=system_u:system_r:pcscd_t:s0 tcontext=system_u:system_r:pcscd_t:s0 tclass=capability permissive=0 ---- time->Fri Mar 6 10:22:17 2020 type=AVC msg=audit(1583508137.943:148): avc: denied { setsched } for pid=1189 comm="pcscd" scontext=system_u:system_r:pcscd_t:s0 tcontext=system_u:system_r:pcscd_t:s0 tclass=process permissive=0 ---- time->Fri Mar 6 10:25:41 2020 type=AVC msg=audit(1583508341.455:221): avc: denied { setsched } for pid=1412 comm="cockpit-ws" scontext=system_u:system_r:cockpit_ws_t:s0 tcontext=system_u:system_r:cockpit_ws_t:s0 tclass=process permissive=0 (In reply to Zdenek Pytela from comment #1) Paul, No need to create bugzillas for the setsched permission unless you see an issue with the software. With the update the denials will no longer be audited. Closing this bz as duplicate of bz#1795524, you can find additional information there if interested. *** This bug has been marked as a duplicate of bug 1795524 *** |