Bug 1888994

Summary: Add ~/.mozilla to restorecond directories
Product: [Fedora] Fedora Reporter: Martin Stransky <stransky>
Component: selinux-policyAssignee: Zdenek Pytela <zpytela>
Status: CLOSED EOL QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 34CC: dwalsh, grepl.miroslav, lvrabec, mmalik, omosnace, plautrba, vmojzis, zpytela
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-06-08 06:20:09 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Martin Stransky 2020-10-16 17:32:46 UTC
Description of problem:

See Bug 1731371. Files in ~/.mozilla may have a wrong selinux label and Firefox has to run restorecon on it by itself.

Comment 1 Ben Cotton 2021-02-09 15:20:43 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 34 development cycle.
Changing version to 34.

Comment 2 Petr Lautrbach 2021-08-10 17:25:20 UTC
I somehow missed this bug, sorry.

restorecond is not used since we have file name transition. Most likely this problem could be fixed on selinux policy level.
The original report doesn't contain full avc denial messages.

@stransky do you have a reproducer? Are you able to collect full avc messages? It would help us to understand the problem.

Switching to selinux-policy for now.

Comment 3 Martin Stransky 2021-09-03 07:05:01 UTC
Hello Petr,

sorry for late response.

Reproduction steps:

1) Remove restorecon command from /usr/bin/firefox
2) Create a new profile (run 'firefox -P' on command line)
3) Run Firefox, go to https://bitmovin.com/demos/drm (DRM test page) and try to play the video here
4) See 'DRM crashed' info bar on Firefox, you may also see SELinux error messages.

Comment 4 Ben Cotton 2022-05-12 16:49:15 UTC
This message is a reminder that Fedora Linux 34 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 34 on 2022-06-07.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '34'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, change the 'version' 
to a later Fedora Linux version.

Thank you for reporting this issue and we are sorry that we were not 
able to fix it before Fedora Linux 34 is end of life. If you would still like 
to see this bug fixed and are able to reproduce it against a later version 
of Fedora Linux, you are encouraged to change the 'version' to a later version
prior to this bug being closed.

Comment 5 Ben Cotton 2022-06-08 06:20:09 UTC
Fedora Linux 34 entered end-of-life (EOL) status on 2022-06-07.

Fedora Linux 34 is no longer maintained, which means that it
will not receive any further security or bug fix updates. As a result we
are closing this bug.

If you can reproduce this bug against a currently maintained version of
Fedora please feel free to reopen this bug against that version. If you
are unable to reopen this bug, please file a new report against the
current release.

Thank you for reporting this bug and we are sorry it could not be fixed.