Bug 682416
Summary: | SELinux is preventing /usr/bin/spice-vdagent "write" access on spice-vdagent-sock | |||
---|---|---|---|---|
Product: | Red Hat Enterprise Linux 6 | Reporter: | Hans de Goede <hdegoede> | |
Component: | selinux-policy | Assignee: | Miroslav Grepl <mgrepl> | |
Status: | CLOSED ERRATA | QA Contact: | Desktop QE <desktop-qa-list> | |
Severity: | medium | Docs Contact: | ||
Priority: | low | |||
Version: | 6.0 | CC: | dwalsh, mgrepl, mhasko, mkrcmari | |
Target Milestone: | rc | |||
Target Release: | --- | |||
Hardware: | Unspecified | |||
OS: | Unspecified | |||
Whiteboard: | ||||
Fixed In Version: | selinux-policy-3.7.19-79.el6 | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | ||
Clone Of: | 648553 | |||
: | 737790 (view as bug list) | Environment: | ||
Last Closed: | 2011-05-19 12:12:39 UTC | Type: | --- | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: | ||||
Bug Depends On: | 648553 | |||
Bug Blocks: | 737790 |
Description
Hans de Goede
2011-03-05 10:25:03 UTC
Yes, I need to backport vdagent policy from F14/F15. (In reply to comment #1) > Yes, I need to backport vdagent policy from F14/F15. Great, could this be done in time for 6.1 (IOW can you devel ack this) ? Thanks, Hans I am pretty sure Dan will get me devel ack today and I will do it either today or tomorrow. Could you test it then? I will let you know as soon as a new build is done. (In reply to comment #3) > Could you test it then? I will let you know as soon as a new build is done. I'll test. Just drop a comment or ping me when you are done. Thank you. Fixed in selinux-policy-3.7.19-76.el6 Need to add some other changes. Fixed in selinux-policy-3.7.19-77.el6 Marian, how is labelled spice-vdagentd daemon library? (In reply to comment #10) > Marian, > how is labelled spice-vdagentd daemon library? I meant binary. Miro, Here what I get $ ls -Z /usr/sbin/spice-vdagentd -rwxr-xr-x. root root system_u:object_r:vdagent_exec_t:s0 /usr/sbin/spice-vdagentd when running in gnome session: $ ps -eZ | grep vdag system_u:system_r:initrc_t:s0 1547 ? 00:00:00 spice-vdagentd unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 2011 ? 00:00:00 spice-vdagent $ ls -Z /var/run/spice-vdagentd/spice-vdagent-sock srw-rw-rw-. root root system_u:object_r:vdagent_var_run_t:s0 /var/run/spice-vdagentd/spice-vdagent-sock Ok, I probably know where the problem is. I am creating a test build for testing this issue. (In reply to comment #13) > Ok, I probably know where the problem is. I am creating a test build for > testing this issue. Marian, thanks for testing. *** Bug 685156 has been marked as a duplicate of this bug. *** Fixed in selinux-policy-3.7.19-79.el6 Working on selinux-policy-3.7.19-79.el6. Thanks. An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on therefore solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHBA-2011-0526.html |