| Summary: | setroubleshoot not finding AVC denials | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Tom <thomasbelvin> |
| Component: | setroubleshoot | Assignee: | Daniel Walsh <dwalsh> |
| Status: | CLOSED CANTFIX | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | medium | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | rawhide | CC: | dwalsh, germano.massullo, mgrepl, notting, rdieter |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2011-11-23 16:52:43 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Tom
2011-08-01 17:19:15 UTC
This is happening to me in Fedora 16. Programs well known to have problems with SELinux auto close or have malfunctions, but SELinux troubleshooter does not notify in taskbar. I have KDE 4.7.3. Tom could you change version to Fedora 16? I think it could be better The problem is on update auditd is not running. systemctl enable auditd systemctl start auditd Then the auditd will start sending avc's to setroubleshoot. [root@computer ]# systemctl enable auditd Failed to issue method call: Invalid argument systemctl enable auditd.service systemctl start auditd.service should work. Oops always forget the .service part. Why did you close as not a bug? The system did not show SELinux errors until we do systemctl enable auditd.service systemctl start auditd.service That's not normal Well I guess I should have closed it as cantfix, since updates from F15 to F16 did not maintain the state of running services. I am not sure why this decision was made, but that is what caused the problem. Nothing audit, setroubleshoot or selinux can do about it. I don't understand well these technical things, but we must let know developer leaders that SELinux troubleshooter is no longer working, and this is not admissable. Yes I understand. On fresh installs it will work, but on updates no system services that were working before work afterwards. Then someone should put systemctl enable auditd.service systemctl start auditd.service under upgrade FAQs from Fedora 15 to Fedora 16 Bill who should I ping to do this? It's on the wiki - https://fedoraproject.org/wiki/Common_F16_bugs Maybe we should call this out on setroubleshoot directly. |