Note: This is a public test instance of Red Hat Bugzilla. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback at

Bug 1823812

Summary: Fedora Silverblue should follow the same firewall rules as Fedora Workstation.
Product: [Fedora] Fedora Reporter: Tomas Popela <tpopela>
Component: firewalldAssignee: Eric Garver <egarver>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 32CC: awilliam, bcotton, egarver, psutter, sgallagh, tpopela
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: AcceptedFreezeException
Fixed In Version: firewalld-0.8.2-2.fc32 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-04-16 01:41:38 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On:    
Bug Blocks: 1705306    

Description Tomas Popela 2020-04-14 14:41:41 UTC
Reported in The user was not able to access his public files on another machine on his network using Nautilus. To get it work he had to switch to Workstation zone with `firewall-cmd --set-default-zone=FedoraWorkstation`. This is a regression in Fedora 32, when we moved from using fedora-release-workstation to fedora-release-silverblue.

The fix is already committed and awaits a koji build -

Comment 1 Fedora Blocker Bugs Application 2020-04-14 14:44:17 UTC
Proposed as a Freeze Exception for 32-final by Fedora user tpopela using the blocker tracking app because:

 This is a regression after we moved from using fedora-release-workstation to fedora-release-silverblue. Breaks at least file sharing in Nautilus and possible others as the Workstation's zone is more opened than the one that is used currently (as a fallback). The fix is committed and awaits a build.

Comment 2 Adam Williamson 2020-04-14 14:47:00 UTC
+1 FE, I guess. But can you please do a build/update soon? We are already trying to build the Final RC at this point.

Comment 3 Stephen Gallagher 2020-04-14 16:16:59 UTC
Yeah, +1 FE. Setting the default firewall isn't really fixable in an update.

Comment 4 Fedora Update System 2020-04-14 16:50:31 UTC
FEDORA-2020-485316ccc7 has been submitted as an update to Fedora 32.

Comment 5 Ben Cotton 2020-04-14 16:58:58 UTC
+1 FE

Comment 6 Adam Williamson 2020-04-14 17:09:31 UTC
That's +3 FE, accepting.

Comment 7 Tomas Popela 2020-04-15 11:51:09 UTC
Tested the Silverblue Fedora-32-20200414.1 compose:

[tpopela@ibm-p8-kvm-03-guest-02 ~]$ firewall-cmd --list-all
FedoraWorkstation (active)
  target: default
  icmp-block-inversion: no
  interfaces: ens3
  services: dhcpv6-client samba-client ssh
  ports: 1025-65535/udp 1025-65535/tcp
  masquerade: no
  rich rules:

Comment 8 Fedora Update System 2020-04-16 01:41:38 UTC
FEDORA-2020-485316ccc7 has been pushed to the Fedora 32 stable repository.
If problem still persists, please make note of it in this bug report.