Bug 1989070
Summary: | Create separate SELinux context for NetworkManager-dispatcher : avc: denied { execute } for comm="nm-dispatcher" name="04-iscsi" on every boot | |||
---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8 | Reporter: | Thomas Haller <thaller> | |
Component: | selinux-policy | Assignee: | Patrik Koncity <pkoncity> | |
Status: | CLOSED WONTFIX | QA Contact: | Milos Malik <mmalik> | |
Severity: | medium | Docs Contact: | ||
Priority: | medium | |||
Version: | 8.6 | CC: | bgalvani, cedric.bellegarde, dhodovsk, fge, fpokryvk, jhsiao, JONATHAN.SATTELBERGER, leonfauster, lrintel, lvrabec, mmalik, mmarusak, mpitt, pkoncity, pzatko, riehecky, rkhan, ssekidde, sukulkar, till, vbenes, yidliu, zpytela | |
Target Milestone: | beta | Keywords: | Triaged | |
Target Release: | 8.7 | |||
Hardware: | All | |||
OS: | Linux | |||
Whiteboard: | CockpitTest | |||
Fixed In Version: | selinux-policy-3.14.3-91.el8 | Doc Type: | No Doc Update | |
Doc Text: | Story Points: | --- | ||
Clone Of: | ||||
: | 2053641 (view as bug list) | Environment: | ||
Last Closed: | 2022-04-29 16:15:39 UTC | Type: | Bug | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: | ||||
Bug Depends On: | ||||
Bug Blocks: | 2053641 |
Description
Thomas Haller
2021-08-02 10:36:44 UTC
Hello, this el8 package seems to break the NetworkManager-ci tests, there are several "Permission denied" for dispatcher directory or script in journal log for "nm-dispatcher", previous version of selinux-policy works fine (also `setenforce 0` works fine), so it is really selinux-policy issue. I would move this back to ASSIGNED and set FailedQA until there is fixed package. *** Bug 2055199 has been marked as a duplicate of this bug. *** Retitling. I was unable to find this bug with a search, so I filed the duplicate bug 2055199. This should make it searchable. Our Beaker jobs hit the same issue: https://beaker.engineering.redhat.com/jobs/6327666 --- under RHEL-8.6.0-20220220.3 https://beaker.engineering.redhat.com/jobs/6327363 --- under RHEL-8.6.0-20220218.1 Same job under RHEL-8.6.0-20220127.4 passed successfully: https://beaker.engineering.redhat.com/jobs/6277175 NOTE that we're using the fixed version: selinux-policy-targeted-3.14.3-91.el8.noarch *** selinux-policy-3.14.3-91.el8.noarch *** libselinux-2.9-5.el8.x86_64 python3-libselinux-2.9-5.el8.x86_64 libselinux-utils-2.9-5.el8.x86_64 openvswitch-selinux-extra-policy-1.0-28.el8fdp.noarch rpm-plugin-selinux-4.14.3-21.el8.x86_64 Please advise! Thanks! Jean (In reply to Jean-Tsung Hsiao from comment #28) > NOTE that we're using the fixed version: > > selinux-policy-targeted-3.14.3-91.el8.noarch > *** selinux-policy-3.14.3-91.el8.noarch *** In the latest version all related commites were reverted: * Wed Feb 16 2022 Zdenek Pytela <zpytela> - 3.14.3-92 - Allow postfix_domain read dovecot certificates 1/2 Resolves: rhbz#2043599 - Dontaudit dirsrv search filesystem sysctl directories 1/2 Resolves: rhbz#2042568 - Allow chage domtrans to sssd Resolves: rhbz#2054718 - Allow postfix_domain read dovecot certificates 2/2 Resolves: rhbz#2043599 - Allow ctdb create cluster logs Resolves: rhbz#2049481 - Allow alsa bind mixer controls to led triggers Resolves: rhbz#2049730 - Allow alsactl set group Process ID of a process Resolves: rhbz#2049730 - Dontaudit mdadm list dirsrv tmpfs dirs Resolves: rhbz#2011174 - Dontaudit dirsrv search filesystem sysctl directories 2/2 Resolves: rhbz#2042568 - Revert "Label NetworkManager-dispatcher service with separate context" Related: rhbz#1989070 ^^^ - Revert "Allow NetworkManager-dispatcher dbus chat with NetworkManager Related: rhbz#1989070 ^^^ *** Bug 2057147 has been marked as a duplicate of this bug. *** Confining nm-dispatcher plugins will not be included in Red Hat Enterprise Linux 8 as there would be a non-negligible risk of regression. We will now close this issue, but if you believe that the decision needs to be reconsidered, feel free to reopen this bug and attach information regarding severity of the bugzilla. |