Bug 2215499
| Summary: | No more audio in SELinux sandbox applications | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Timo Trinks <ttrinks> |
| Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> |
| Status: | CLOSED EOL | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 38 | CC: | dwalsh, lvrabec, mmalik, nknazeko, omosnacek, pkoncity, plautrba, vmojzis, zpytela |
| Target Milestone: | --- | Keywords: | Regression, SELinux |
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2024-05-22 14:07:40 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Timo Trinks
2023-06-16 08:41:15 UTC
Timo, We hardly ever remove existing permissions in selinux-policy. Can you track down on which system the same scenario was working, e.g. F37, and if it was dependent on some other components version? Can you also share AVC denials you get? Does the same scenario work in SELinux permissive mode? Hi Zdenek, It happens on a vanilla, freshly installed F38 desktop with all the latest updates (and recently on F37 as well, with all the latest updates). I have no meaningful AVC denials to share at this point - not sure where to start troubleshooting. In essence what's described here: https://www.reddit.com/r/Fedora/comments/13ftmpk/selinux_sandboxed_firefox_has_no_audio_playback/ https://unix.stackexchange.com/questions/747029/selinux-sandboxed-firefox-has-no-audio Cheers, Timo Timo, We need to see AVC denials from audit logs or journal to move further. Are you sure this is SELinux related? If yes, you can try to disable dontaudit rules: # semodule -DB <reproduce> # semodule -B # ausearch -i -m avc,user_avc,selinux_err,user_selinux_err -ts today Fedora Linux 38 entered end-of-life (EOL) status on 2024-05-21. Fedora Linux 38 is no longer maintained, which means that it will not receive any further security or bug fix updates. As a result we are closing this bug. If you can reproduce this bug against a currently maintained version of Fedora Linux please feel free to reopen this bug against that version. Note that the version field may be hidden. Click the "Show advanced fields" button if you do not see the version field. If you are unable to reopen this bug, please file a new report against an active release. Thank you for reporting this bug and we are sorry it could not be fixed. |