Bug 1377113
Summary: | [selinux-policy] media inserted into by optical drive do not get auto-mounted | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Joachim Frieben <jfrieben> | ||||||
Component: | selinux-policy | Assignee: | Lukas Vrabec <lvrabec> | ||||||
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||||
Severity: | unspecified | Docs Contact: | |||||||
Priority: | unspecified | ||||||||
Version: | 25 | CC: | awilliam, bugzilla, cpanceac, dominick.grift, dwalsh, kevin, kparal, lvrabec, mgrepl, phatina, plautrba, pschindl, renault, rh, robatino, satellitgo, stefw, thunderbirdtr, tsmetana | ||||||
Target Milestone: | --- | ||||||||
Target Release: | --- | ||||||||
Hardware: | x86_64 | ||||||||
OS: | Linux | ||||||||
Whiteboard: | AcceptedBlocker | ||||||||
Fixed In Version: | selinux-policy-3.13.1-216.fc25 | Doc Type: | If docs needed, set a value | ||||||
Doc Text: | Story Points: | --- | |||||||
Clone Of: | Environment: | ||||||||
Last Closed: | 2016-10-07 03:35:09 UTC | Type: | Bug | ||||||
Regression: | --- | Mount Type: | --- | ||||||
Documentation: | --- | CRM: | |||||||
Verified Versions: | Category: | --- | |||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||
Embargoed: | |||||||||
Bug Depends On: | |||||||||
Bug Blocks: | 1277287, 1277289 | ||||||||
Attachments: |
|
Description
Joachim Frieben
2016-09-18 15:41:34 UTC
Blocks bug 1277287: automatic mounting of removable media on insertion must work in release-blocking desktops. I'll try to reproduce this: the usual suspect is SELinux though... Issue is absent after booting system in permissive mode. I'm +1 to the issue being a blocker, but didn't we already have a bug filed on the actual SELinux denial that caused this? (In reply to Adam Williamson from comment #4) > I'm +1 to the issue being a blocker, but didn't we already have a bug filed > on the actual SELinux denial that caused this? Yes, bug #1375156 which was fixed by selinux-policy-3.13.1-214.fc25. I'm unable to boot the F25 alpha at all (no idea why yet, freezes quite early in the boot process), so Joachim or whoever has F25 running, please make sure you have the updated selinux-policy package installed. (In reply to Tomas Smetana from comment #5) 1. Issue is still present for selinux-policy-3.13.1-215.fc25. 2. The latest live image of type "Workstation" includes package selinux-policy-3.13.1-214.fc25 and is available at https://dl.fedoraproject.org/pub/fedora/linux/development/25/Workstation/x86_64/iso/Fedora-Workstation-Live-x86_64-25-20160928.n.0.iso. However, when booting from the latter in "Boxes" (gnome-boxes), it does of course never appear as a user-mounted media. It is necessary to add an optical image to an -installed- virtual Fedora 25 guest via "Boxes"' menu item "Properties > Devices". Created attachment 1205878 [details]
AVCs from the audit.log
I have the problem reproduced finally. Attached are the AVCs I grepped from the audit.log. Looks like this time storaged was not involved.
Forgot to mention: reproduced with selinux-policy-3.13.1-215.fc25.noarch. Created attachment 1205880 [details]
Some more AVCs
...from permissive mode.
*** Bug 1380190 has been marked as a duplicate of this bug. *** Tomas, Thanks for AVCs. Fixed in our policy repo. Builds will be available ASAP. So, +1 beta blocker from me. -216 does appear to fix this, also. *** Bug 1379053 has been marked as a duplicate of this bug. *** +1 beta blocker +1 beta blocker Discussed at 2016-10-03 blocker review meeting: [1]. This bug was accepted as Beta blocker: This bug violates Beta criterion "Automatic mounting of removable media on insertion must work in release-blocking desktops." [1] https://meetbot-raw.fedoraproject.org/fedora-blocker-review/2016-10-03/ I sent https://bodhi.fedoraproject.org/updates/FEDORA-2016-b596fd5579 , I don't know why it didn't edit this update, but this should now be MODIFIED. *** Bug 1380149 has been marked as a duplicate of this bug. *** *** Bug 1381232 has been marked as a duplicate of this bug. *** selinux-policy-3.13.1-216.fc25 has been pushed to the Fedora 25 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-b596fd5579 This worked for me with Beta 1.1. Verified with Beta-1.1. selinux-policy-3.13.1-216.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report. |