Bug 1165713
Summary: | Disabling the 'unconfined' module broke setroubleshootd | |||
---|---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Miroslav Grepl <mgrepl> | |
Component: | selinux-policy | Assignee: | Petr Lautrbach <plautrba> | |
Status: | CLOSED NEXTRELEASE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | |
Severity: | unspecified | Docs Contact: | ||
Priority: | unspecified | |||
Version: | 22 | CC: | alphsteiner, benl, dominick.grift, dwalsh, lvrabec, mgrepl, plautrba | |
Target Milestone: | --- | |||
Target Release: | --- | |||
Hardware: | Unspecified | |||
OS: | Unspecified | |||
Whiteboard: | ||||
Fixed In Version: | 3.13.1-128.12.fc22 | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | ||
Clone Of: | 1162811 | |||
: | 1165734 (view as bug list) | Environment: | ||
Last Closed: | 2015-08-27 18:25:01 UTC | Type: | Bug | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: | ||||
Bug Depends On: | 1162811 | |||
Bug Blocks: | 1165734 |
Description
Miroslav Grepl
2014-11-19 14:24:26 UTC
The point is we want to have system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 8823 ? 00:00:00 unconfined_dbus_service for unconfined dbus service if unconfined.pp is disabled and have system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 10605 ? 00:00:00 unconfined_dbus_service if unconfined.pp is enabled. commit c0c6b7d012b4dc271aee472632367e386644976a Author: Miroslav Grepl <mgrepl> Date: Wed Nov 19 15:47:53 2014 +0100 Allow systemd_dbus_t to execute bin_t in the caller domain if unconfined.pp is disabled to have unconfined dbus service running as system_dbusd_t. This bug appears to have been reported against 'rawhide' during the Fedora 22 development cycle. Changing version to '22'. More information and reason for this action is here: https://fedoraproject.org/wiki/Fedora_Program_Management/HouseKeeping/Fedora22 selinux-policy-3.13.1-128.12.fc22 has been submitted as an update to Fedora 22. https://bugzilla.redhat.com/show_bug.cgi?id=1165713 selinux-policy-3.13.1-128.12.fc22 has been pushed to the Fedora 22 testing repository. If problems still persist, please make note of it in this bug report.\nIf you want to test the update, you can install it with \n su -c 'yum --enablerepo=updates-testing update selinux-policy'. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2015-14076 selinux-policy-3.13.1-128.12.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report. |