Bug 1761765
| Summary: | Cannot lock down cockpit.service: avc: denied { mounton } / { nnp_transition } | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Martin Pitt <mpitt> |
| Component: | selinux-policy | Assignee: | Patrik Koncity <pkoncity> |
| Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 31 | CC: | dwalsh, lvrabec, mgrepl, plautrba, zpytela |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| URL: | https://github.com/fedora-selinux/selinux-policy-contrib/commit/793708559184e44e7b7c93f47eb5860fcb1017fd | ||
| Whiteboard: | |||
| Fixed In Version: | selinux-policy-3.14.4-39.fc31 | Doc Type: | If docs needed, set a value |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2019-10-29 01:27:42 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Martin Pitt
2019-10-15 10:24:01 UTC
commit 793708559184e44e7b7c93f47eb5860fcb1017fd (HEAD -> rawhide, origin/rawhide, origin/HEAD)
Author: Patrik Koncity <pkoncity>
Date: Tue Oct 22 17:24:10 2019 +0200
Update cockpit policy
Allow to systemd to use dir with file context cockpit_var_run_t as mount point
Allow SELinux Domain trasition from sytemd into confined domain with NoNewPrivileges
Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1761765
Awesome, thank you Lukas! Kudos to Patrik. :) Fix will be part of next selinux-policy update. If you need some scratch builds we could provide them. FEDORA-2019-7d65c50fd6 has been submitted as an update to Fedora 31. https://bodhi.fedoraproject.org/updates/FEDORA-2019-7d65c50fd6 selinux-policy-3.14.4-39.fc31 has been pushed to the Fedora 31 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2019-7d65c50fd6 The update works great, thank you! OOI, is this fix also aimed at Fedora 30? selinux-policy-3.14.4-39.fc31 has been pushed to the Fedora 31 stable repository. If problems still persist, please make note of it in this bug report. |