Bug 1355861
Summary: | 20160712 Workstation Rawhide nightly fails to boot in enforcing mode, boots in permissive | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Adam Williamson <awilliam> |
Component: | selinux-policy | Assignee: | Lukas Vrabec <lvrabec> |
Status: | CLOSED RAWHIDE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | urgent | Docs Contact: | |
Priority: | urgent | ||
Version: | rawhide | CC: | dominick.grift, dwalsh, lvrabec, mgrepl, plautrba, renault, robatino |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | x86_64 | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2016-07-15 22:58:09 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 1277284 | ||
Attachments: |
Description
Adam Williamson
2016-07-12 18:27:48 UTC
Created attachment 1178971 [details]
sealert -a /var/log/audit/audit.log output on 20160711
Created attachment 1178972 [details]
sealert -a /var/log/audit/audit.log output on 20160712
Created attachment 1178973 [details]
journalctl -b | grep -i avc | grep den output on 20160711
Created attachment 1178974 [details]
journalctl -b | grep -i avc | grep den output on 20160712
I probably see the issue here. I will fix this ASAP. I built selinux-policy-3.13.1-202.fc25 selinux policy package. This should fix the issue. Thanks. We didn't get a nightly today because of https://fedorahosted.org/rel-eng/ticket/6442 , I'll be able to confirm the fix (or not) when that's resolved. The update doesn't fix the issue for me. Many services couldn't be started and the boot failed. With selinux=0 in the command line to boot, no problem. It does fix nightly live image boots, though. The last couple of days of Workstation nightly lives have booted OK. It's fixed for me after manual relabelling. Thanks. |