Bug 1130596
Summary: | SELinux is preventing gnome-session-c from read, write access on the chr_file nvidiactl. | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Stefan Ringel <mail> |
Component: | selinux-policy | Assignee: | Miroslav Grepl <mgrepl> |
Status: | CLOSED EOL | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | unspecified | Docs Contact: | |
Priority: | unspecified | ||
Version: | 22 | CC: | dominick.grift, dwalsh, igeorgex, lvrabec, mgrepl, moez.roy, p.malishev |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | x86_64 | ||
OS: | Unspecified | ||
Whiteboard: | abrt_hash:7095cb86daa476d5032c402a1fd9401d81368e96c834bf1ed17ac95dde23f2ff | ||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2016-07-19 12:01:26 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Stefan Ringel
2014-08-15 15:45:49 UTC
ls -lZ /dev/nvidiactl What every created this device, it created it with the wrong label. type_transition puppetagent_t device_t : chr_file xserver_misc_device_t "nvidiactl"; type_transition udev_t device_t : chr_file xserver_misc_device_t "nvidiactl"; type_transition kernel_t device_t : chr_file xserver_misc_device_t "nvidiactl"; type_transition authconfig_t device_t : chr_file xserver_misc_device_t "nvidiactl"; type_transition init_t device_t : chr_file xserver_misc_device_t "nvidiactl"; type_transition unconfined_t device_t : chr_file xserver_misc_device_t "nvidiactl"; type_transition sysadm_t device_t : chr_file xserver_misc_device_t "nvidiactl"; type_transition xserver_t device_t : chr_file xserver_misc_device_t "nvidiactl"; type_transition rpm_script_t device_t : chr_file xserver_misc_device_t "nvidiactl"; type_transition pegasus_t device_t : chr_file xserver_misc_device_t "nvidiactl"; type_transition neutron_t device_t : chr_file xserver_misc_device_t "nvidiactl"; Looks like we have lots of domains setup to create this device with the correct label. *** Bug 1130595 has been marked as a duplicate of this bug. *** *** Bug 1130519 has been marked as a duplicate of this bug. *** *** Bug 1130522 has been marked as a duplicate of this bug. *** This bug appears to have been reported against 'rawhide' during the Fedora 22 development cycle. Changing version to '22'. More information and reason for this action is here: https://fedoraproject.org/wiki/Fedora_Program_Management/HouseKeeping/Fedora22 Just faced the issue with Fedora 22 $ LANG=C ls -lZ /dev/nvidiactl crw-rw-rw-. 1 root root system_u:object_r:device_t:s0 195, 255 Jul 1 18:01 /dev/nvidiactl Workaround, just for reference: $ sudo restorecon -r -vv /dev/nvidiactl $ sudo restorecon -r -vv /dev/nvidia0 Expected labels: $ LANG=C ls -lZ /dev/nvidia* crw-rw-rw-. 1 root root system_u:object_r:xserver_misc_device_t:s0 195, 0 Jul 1 18:01 /dev/nvidia0 crw-rw-rw-. 1 root root system_u:object_r:xserver_misc_device_t:s0 195, 255 Jul 1 18:01 /dev/nvidiactl Fedora 22 changed to end-of-life (EOL) status on 2016-07-19. Fedora 22 is no longer maintained, which means that it will not receive any further security or bug fix updates. As a result we are closing this bug. If you can reproduce this bug against a currently maintained version of Fedora please feel free to reopen this bug against that version. If you are unable to reopen this bug, please file a new report against the current release. If you experience problems, please add a comment to this bug. Thank you for reporting this bug and we are sorry it could not be fixed. |