Bug 2380156
| Summary: | Chromium %post script breaks SELinux policy | ||||||
|---|---|---|---|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Marek Marczykowski <marmarek> | ||||
| Component: | chromium | Assignee: | Than Ngo <than> | ||||
| Status: | CLOSED WORKSFORME | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||
| Severity: | high | Docs Contact: | |||||
| Priority: | unspecified | ||||||
| Version: | 42 | CC: | pigpigman8686, spotrh, suraj.ghimire7, than, yaneti | ||||
| Target Milestone: | --- | Keywords: | SELinux | ||||
| Target Release: | --- | Flags: | than:
needinfo?
(marmarek) |
||||
| Hardware: | x86_64 | ||||||
| OS: | Linux | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | Doc Type: | --- | |||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2025-12-10 11:23:49 UTC | Type: | --- | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Attachments: |
|
||||||
|
Description
Marek Marczykowski
2025-07-15 14:24:43 UTC
I tried to reproduce your problem by installing updates to the new selinux-policy(-targeted) packages created for testing purposes, as well as Chromium, and could not find any problem. It just works for me Maybe it's a bug in QubesOS? It's about transient state during update, services affected by it will have all operations denied (due to the policy being loaded without modules). I've made a reproducer, let me attach it here. Usage: 1. Get a system with updates for selinux-policy and chromium pending (Fedora live image is okay). 2. Build selinux-repro.spec. When installing build deps, be careful to not update selinux-policy just yet (I simply use --disablerepo=updates on live image) 3. Install selinux-repro and selinux-repro-selinux 4. Start selinux-repro service 5. Now update selinux-policy and chromium in a single transaction. 6. Observe that selinux-repro service crashed, see audit log for selinux denials Created attachment 2102313 [details]
Reproducer
Could you please try new chromium-142.0.7444.59 ? It's submitted as update in https://bodhi.fedoraproject.org/updates/FEDORA-2025-7c0b3fa81f sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-7c0b3fa81f Thank you! CLosing it as i cannot reproduce it here. |