Bug 1989641
Summary: | SELinux is blocking firewalld from dropping linux capabilities | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 9 | Reporter: | Tomas Dolezal <todoleza> |
Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | Milos Malik <mmalik> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 9.0 | CC: | dwalsh, egarver, extras-qa, grepl.miroslav, jjaburek, jstodola, lvrabec, mikhail.v.gavrilov, mmalik, omosnace, snemec, ssekidde, vmojzis, zpytela |
Target Milestone: | beta | Keywords: | AutoVerified, Triaged |
Target Release: | 9.0 Beta | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | selinux-policy-34.1.14-1.el9 | Doc Type: | No Doc Update |
Doc Text: | Story Points: | --- | |
Clone Of: | 1985494 | Environment: | |
Last Closed: | 2021-12-07 21:35:16 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1985494 | ||
Bug Blocks: | 1914945, 1942219 |
Description
Tomas Dolezal
2021-08-03 16:11:06 UTC
I've submitted a Fedora PR to address the issue: https://github.com/fedora-selinux/selinux-policy/pull/826 (In reply to Zdenek Pytela from comment #2) > I've submitted a Fedora PR to address the issue: > https://github.com/fedora-selinux/selinux-policy/pull/826 firewalld also needs CAP_SYS_MODULE as per 1990271 comment 14. However, it looks like firewalld never had that listed in the selinux-policy. Do you know if it also needs to be added? (In reply to Eric Garver from comment #3) > (In reply to Zdenek Pytela from comment #2) > > I've submitted a Fedora PR to address the issue: > > https://github.com/fedora-selinux/selinux-policy/pull/826 > > firewalld also needs CAP_SYS_MODULE as per 1990271 comment 14. However, it > looks like firewalld never had that listed in the selinux-policy. > > Do you know if it also needs to be added? I suppose it is. Is there a Fedora build available already? (In reply to Zdenek Pytela from comment #4) > (In reply to Eric Garver from comment #3) > > (In reply to Zdenek Pytela from comment #2) > > > I've submitted a Fedora PR to address the issue: > > > https://github.com/fedora-selinux/selinux-policy/pull/826 > > > > firewalld also needs CAP_SYS_MODULE as per 1990271 comment 14. However, it > > looks like firewalld never had that listed in the selinux-policy. > > > > Do you know if it also needs to be added? > > I suppose it is. Is there a Fedora build available already? Here is a Fedora 35 build: https://koji.fedoraproject.org/koji/taskinfo?taskID=73738461 |