DescriptionAdam Williamson
2023-03-01 22:25:42 UTC
There's an openQA test which tests upgrades - it starts from a clean install of the Workstation edition of the previous release, then upgrades to the release under test. There's a follow-up test which checks that all services started successfully.
Since Fedora-38-20230218.n.0 that test has been failing for F38, because the service `rpmdb-migrate.service` fails. The logs show this:
Mar 01 05:31:11 fedora systemd[1]: Starting rpmdb-migrate.service - RPM database migration to /usr...
Mar 01 05:31:11 fedora systemd[1]: rpmdb-rebuild.service - RPM database rebuild was skipped because of an unmet condition check (ConditionPathExists=/usr/lib/sysimage/rpm/.rebuilddb).
Mar 01 05:31:11 fedora systemd[1]: systemd-pcrphase-sysinit.service - TPM2 PCR Barrier (Initialization) was skipped because of an unmet condition check (ConditionPathExists=/sys/firmware/efi/efivars/StubPcrKernelImage-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f).
Mar 01 05:31:11 fedora audit[600]: AVC avc: denied { map } for pid=600 comm="rpmdb_migrate" path="/usr/bin/bash" dev="vda3" ino=194594 scontext=system_u:system_r:rpmdb_t:s0 tcontext=system_u:object_r:shell_exec_t:s0 tclass=file permissive=0
Mar 01 05:31:11 fedora audit[600]: ANOM_ABEND auid=4294967295 uid=0 gid=0 ses=4294967295 subj=system_u:system_r:rpmdb_t:s0 pid=600 comm="rpmdb_migrate" exe="/usr/bin/bash" sig=11 res=1
Mar 01 05:31:11 fedora audit: BPF prog-id=61 op=LOAD
Mar 01 05:31:11 fedora systemd[1]: Starting dbus-broker.service - D-Bus System Message Bus...
Mar 01 05:31:11 fedora systemd[1]: rpmdb-migrate.service: Main process exited, code=killed, status=11/SEGV
Mar 01 05:31:11 fedora systemd[1]: rpmdb-migrate.service: Failed with result 'signal'.
Mar 01 05:31:11 fedora systemd[1]: Failed to start rpmdb-migrate.service - RPM database migration to /usr.
that is, it seems to fail because the process crashes, which is likely caused by the SELinux denial:
Mar 01 05:31:11 fedora audit[600]: AVC avc: denied { map } for pid=600 comm="rpmdb_migrate" path="/usr/bin/bash" dev="vda3" ino=194594 scontext=system_u:system_r:rpmdb_t:s0 tcontext=system_u:object_r:shell_exec_t:s0 tclass=file permissive=0
Proposing as a Final blocker as a violation of Final criterion "All system services present after installation with one of the release-blocking package sets must start properly, unless they require hardware which is not present" together with Beta requirement "The upgraded system must meet all release criteria" - https://fedoraproject.org/wiki/Fedora_38_Beta_Release_Criteria#Upgrade_requirements and https://fedoraproject.org/wiki/Fedora_38_Final_Release_Criteria#System_services .