Bug 1471401
Summary: | SELinux is preventing systemd from read, write access on the chr_file /dev/input/event9. | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Mikhail <mikhail.v.gavrilov> |
Component: | selinux-policy | Assignee: | Lukas Vrabec <lvrabec> |
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | unspecified | Docs Contact: | |
Priority: | unspecified | ||
Version: | 27 | CC: | alciregi, awilliam, dominick.grift, dwalsh, flast, jfrieben, lvrabec, mgrepl, plautrba, pmoore, ssekidde |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | x86_64 | ||
OS: | Unspecified | ||
Whiteboard: | abrt_hash:127c2610c127dded662a90285b78b1d30d95976d4c77720edb1ec8f81d3db9dd;VARIANT_ID=workstation; AcceptedFreezeException | ||
Fixed In Version: | selinux-policy-3.13.1-283.14.fc27 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2017-10-31 15:37:46 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 1396705 |
Description
Mikhail
2017-07-15 16:32:19 UTC
Description of problem: Just load Rawhide from USB stick Version-Release number of selected component: selinux-policy-3.13.1-263.fc27.noarch Additional info: reporter: libreport-2.9.1 hashmarkername: setroubleshoot kernel: 4.13.0-0.rc0.git6.1.fc27.x86_64 type: libreport Description of problem: Just after logging in. Version-Release number of selected component: selinux-policy-3.13.1-263.fc27.noarch Additional info: reporter: libreport-2.9.1 hashmarkername: setroubleshoot kernel: 4.13.0-0.rc0.git6.1.fc27.x86_64 type: libreport Description of problem: Happened in normal system use, not sure what was the precise trigger. Version-Release number of selected component: selinux-policy-3.13.1-270.fc27.noarch Additional info: reporter: libreport-2.9.1 hashmarkername: setroubleshoot kernel: 4.13.0-0.rc4.git4.1.fc27.x86_64 type: libreport This bug appears to have been reported against 'rawhide' during the Fedora 27 development cycle. Changing version to '27'. selinux-policy-3.13.1-283.13.fc27 has been submitted as an update to Fedora 27. https://bodhi.fedoraproject.org/updates/FEDORA-2017-b5e9ce60d2 Proposing this for a Final freeze exception, as a proxy for the large amount of added permissions in this update: https://koji.fedoraproject.org/koji/buildinfo?buildID=988969 everything in -11, -12 and -13 is new in this update. All those permissions will prevent quite a lot of AVCs, at least some of which could potentially occur during use of live images (and hence can't be fixed with a post-release update). Discussed at 2017-10-26 Fedora 27 Final go/no-go meeting, acting as a freeze exception review meeting: https://meetbot-raw.fedoraproject.org/fedora-meeting-1/2017-10-26/f27-final-and-server-beta-go-no-go-meeting.2017-10-26-17.00.html . Accepted as a freeze exception, we would like to have this and the other policy loosenings in the final compose to avoid AVCs during install and live use. selinux-policy-3.13.1-283.14.fc27 has been pushed to the Fedora 27 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-b5e9ce60d2 selinux-policy-3.13.1-283.14.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report. |