Bug 1557219
| Summary: | SELinux is preventing (fprintd) from 'remount' accesses on the système de fichiers . | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Nicolas Mailhot <nicolas.mailhot> |
| Component: | selinux-policy | Assignee: | Lukas Vrabec <lvrabec> |
| Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 29 | CC: | dwalsh, lvrabec, mgrepl, plautrba, pmoore |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Unspecified | ||
| Whiteboard: | abrt_hash:a6335903412fe03db25a74bb4027bde929d39f3b5f565b6414fd7ac2924683c1;VARIANT_ID=workstation; | ||
| Fixed In Version: | selinux-policy-3.14.2-15.fc29 selinux-policy-3.14.2-34.fc29 | Doc Type: | If docs needed, set a value |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2018-09-12 02:59:49 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
This bug appears to have been reported against 'rawhide' during the Fedora 29 development cycle. Changing version to '29'. selinux-policy-3.14.2-34.fc29 has been submitted as an update to Fedora 29. https://bodhi.fedoraproject.org/updates/FEDORA-2018-db240a1726 selinux-policy-3.14.2-34.fc29 has been pushed to the Fedora 29 stable repository. If problems still persist, please make note of it in this bug report. |
Description of problem: SELinux is preventing (fprintd) from 'remount' accesses on the système de fichiers . ***** Plugin catchall (100. confidence) suggests ************************** Si vous pensez que (fprintd) devrait être autorisé à accéder remount sur filesystem par défaut. Then vous devriez rapporter ceci en tant qu'anomalie. Vous pouvez générer un module de stratégie local pour autoriser cet accès. Do autoriser cet accès pour le moment en exécutant : # ausearch -c "(fprintd)" --raw | audit2allow -M my-fprintd # semodule -X 300 -i my-fprintd.pp Additional Information: Source Context system_u:system_r:init_t:s0 Target Context system_u:object_r:unlabeled_t:s0 Target Objects [ filesystem ] Source (fprintd) Source Path (fprintd) Port <Inconnu> Host (removed) Source RPM Packages Target RPM Packages Policy RPM selinux-policy-3.14.2-6.fc29.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Permissive Host Name (removed) Platform Linux (removed) 4.16.0-0.rc5.git1.2.fc29.x86_64 #1 SMP Thu Mar 15 00:16:00 UTC 2018 x86_64 x86_64 Alert Count 72 First Seen 2018-03-11 11:09:38 CET Last Seen 2018-03-16 09:32:57 CET Local ID 3008d0e3-9db4-4fd7-8dd1-6290fa6f309c Raw Audit Messages type=AVC msg=audit(1521189177.472:469): avc: denied { remount } for pid=17825 comm="(fprintd)" scontext=system_u:system_r:init_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=filesystem permissive=1 Hash: (fprintd),init_t,unlabeled_t,filesystem,remount Version-Release number of selected component: selinux-policy-3.14.2-6.fc29.noarch Additional info: component: selinux-policy reporter: libreport-2.9.3 hashmarkername: setroubleshoot kernel: 4.16.0-0.rc5.git1.2.fc29.x86_64 type: libreport Potential duplicate: bug 1554462