Bug 2054759
Summary: | SELinux is preventing dbus-daemon from read access on the lnk_file /var/lib/flatpak/exports/share/dbus-1/services/org.gnome.Music.Tracker3.Miner.Files.service. | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Marc Pervaz Boocha <mboocha> |
Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> |
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 36 | CC: | amigadave, debarshir, dwalsh, emailtoflorian, grepl.miroslav, klember, lvrabec, mboocha, michael.scheiffler, mmalik, omosnace, pkoncity, vmojzis, zpytela |
Target Milestone: | --- | Keywords: | Triaged |
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | selinux-policy-36.7-1.fc36 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2022-04-26 02:40:06 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Marc Pervaz Boocha
2022-02-15 16:27:03 UTC
(In reply to Marc Pervaz Boocha from comment #0) > Comments: related but maybe a separate issue is during installing or > updating flatpak fails with: > Warning: Failed to get revokefs-fuse socket from system-helper: User flatpak > does not exist in password file entry I think this is bug 2070350 (In reply to Marc Pervaz Boocha from comment #0) > Source Context system_u:system_r:xdm_t:s0-s0:c0.c1023 I am a bit puzzled by the presence of xdm_t there. That doesn't seem like something Flatpak has. Marc, are you using XDM as your display manager by any chance? Or is this is a stock Fedora Workstation/Silverblue? (In reply to Debarshi Ray from comment #2) > (In reply to Marc Pervaz Boocha from comment #0) > > Source Context system_u:system_r:xdm_t:s0-s0:c0.c1023 > > I am a bit puzzled by the presence of xdm_t there. That doesn't seem like > something Flatpak has. These two problems are independent, xdm_t AVC will be addressed in selinux-policy. *** Bug 2070330 has been marked as a duplicate of this bug. *** *** Bug 2070738 has been marked as a duplicate of this bug. *** FEDORA-2022-76963fee71 has been submitted as an update to Fedora 36. https://bodhi.fedoraproject.org/updates/FEDORA-2022-76963fee71 I am using Workstation. GDM is my display manager. FEDORA-2022-76963fee71 has been pushed to the Fedora 36 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2022-76963fee71` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2022-76963fee71 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. Similar problem has been detected: Switched to another account (via System Menu -> Power Off / Log Out -> Switch User...). Shortly after logging in to that account, CPU usage spiked. Logging out of that account & switching back to the first account showed SELinux alerts getting fired once every 3 seconds. This alert is only one of the many that were fired. They are all due to "read" access by /usr/bin/dbus-daemon on what appear to be names of Flatpak apps I have installed. hashmarkername: setroubleshoot kernel: 5.17.3-302.fc36.x86_64 package: selinux-policy-targeted-36.6-1.fc36.noarch reason: SELinux is preventing /usr/bin/dbus-daemon from 'read' accesses on the lnk_file /var/lib/flatpak/exports/share/applications/org.gnome.Photos.desktop. type: libreport FEDORA-2022-76963fee71 has been pushed to the Fedora 36 stable repository. If problem still persists, please make note of it in this bug report. |