Note: This is a public test instance of Red Hat Bugzilla. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback at bugzilla.redhat.com.
Bug 583659
Summary: | SELinux context wrong after using preugprade | ||||||
---|---|---|---|---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Kamil Páral <kparal> | ||||
Component: | selinux-policy | Assignee: | Daniel Walsh <dwalsh> | ||||
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||
Severity: | medium | Docs Contact: | |||||
Priority: | low | ||||||
Version: | 13 | CC: | awilliam, dwalsh, mgrepl | ||||
Target Milestone: | --- | ||||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | selinux-policy-3.7.19-6.fc13 | Doc Type: | Bug Fix | ||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2010-04-28 03:07:39 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | |||||||
Bug Blocks: | 507681 | ||||||
Attachments: |
|
Description
Kamil Páral
2010-04-19 10:51:26 UTC
selinux-policy-3.7.19-2.fc13.noarch is already a candidate and fixes most of the avc's reported. The troublesome ones are the fontconfig. Will updating to the newer version of selinux automatically fix the problems, or are there some manual steps required afterwards (re-labeling files with correct context and whatnot?). It should fix most if not all the problems. Relabeling should happen automatically. If you still have problems after update, please open bugs. I would likt to get 19-2 into the iso so we could test the upgrade path though. selinux-policy-3.7.19-2.fc13.noarch seems to solve all my problems. We would really prefer if this could get into stable f13 repo before preupgrade test day: https://fedoraproject.org/wiki/Test_Day:2010-04-29_Preupgrade Increase its kama. Discussed at the blocker review meeting today, we agree this is a blocker and will try to put feedback in Bodhi soon. -- Fedora Bugzappers volunteer triage team https://fedoraproject.org/wiki/BugZappers selinux-policy-3.7.19-6.fc13 has been submitted as an update for Fedora 13. http://admin.fedoraproject.org/updates/selinux-policy-3.7.19-6.fc13 selinux-policy-3.7.19-6.fc13 has been pushed to the Fedora 13 testing repository. If problems still persist, please make note of it in this bug report. If you want to test the update, you can install it with su -c 'yum --enablerepo=updates-testing update selinux-policy'. You can provide feedback for this update here: http://admin.fedoraproject.org/updates/selinux-policy-3.7.19-6.fc13 I have updated to selinux-policy-3.7.19-6.fc13 and I see this avc denial in /var/log/messages after bootup: Apr 27 05:08:17 localhost kernel: type=1400 audit(1272359290.665:4): avc: denied { mmap_zero } for pid=420 comm="vbetool" scontext=system_u:system_r:vbetool_t:s0-s0:c0.c1023 tcontext=system_u:system_r:vbetool_t:s0-s0:c0.c1023 tclass=memprotect There is not denial in /var/log/audit/audit.log though. It happens before auditd is started, This bug has been reported against vbetool in the past. Daniel, I can't find you on any IRC channel. Does this mean that selinux-policy-3.7.19-6.fc13 should get -1 karma from me? Do you have bug number for that vbetool bug? selinux-policy-3.7.19-6.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in this bug report. |