Description of problem: SELinux is preventing udisksd from 'wake_alarm' accesses on the capability2 Unknown. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that udisksd should be allowed wake_alarm access on the Unknown capability2 by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'udisksd' --raw | audit2allow -M my-udisksd # semodule -X 300 -i my-udisksd.pp Additional Information: Source Context system_u:system_r:udisks2_t:s0 Target Context system_u:system_r:udisks2_t:s0 Target Objects Unknown [ capability2 ] Source udisksd Source Path udisksd Port <Unknown> Host (removed) Source RPM Packages Target RPM Packages Policy RPM selinux-policy-3.13.1-211.fc25.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 4.8.0-0.rc2.git3.1.fc25.x86_64 #1 SMP Fri Aug 19 14:24:04 UTC 2016 x86_64 x86_64 Alert Count 2 First Seen 2016-08-25 22:26:03 CEST Last Seen 2016-08-25 22:26:31 CEST Local ID f8bdc9e4-c5ab-4ef2-a065-605828431f53 Raw Audit Messages type=AVC msg=audit(1472156791.247:245): avc: denied { wake_alarm } for pid=1857 comm="udisksd" capability=35 scontext=system_u:system_r:udisks2_t:s0 tcontext=system_u:system_r:udisks2_t:s0 tclass=capability2 permissive=0 Hash: udisksd,udisks2_t,udisks2_t,capability2,wake_alarm Version-Release number of selected component: selinux-policy-3.13.1-211.fc25.noarch Additional info: reporter: libreport-2.7.2 hashmarkername: setroubleshoot kernel: 4.8.0-0.rc2.git3.1.fc25.x86_64 type: libreport
Description of problem: I think it was related to a dnf upgrade where one of the updrades was related to SELinux Version-Release number of selected component: selinux-policy-3.13.1-208.fc25.noarch selinux-policy-3.13.1-211.fc25.noarch Additional info: reporter: libreport-2.7.2 hashmarkername: setroubleshoot kernel: 4.8.0-0.rc2.git3.1.fc25.x86_64 type: libreport
Description of problem: Boot into f25 Version-Release number of selected component: selinux-policy-3.13.1-211.fc25.noarch Additional info: reporter: libreport-2.7.2 hashmarkername: setroubleshoot kernel: 4.8.0-0.rc2.git3.1.fc25.x86_64 type: libreport
udisks2_t domain is part of devicekit_t policy.
Description of problem: Seems to occur on boot. Version-Release number of selected component: selinux-policy-3.13.1-211.fc25.noarch Additional info: reporter: libreport-2.7.2 hashmarkername: setroubleshoot kernel: 4.8.0-0.rc4.git0.1.fc25.x86_64 type: libreport
Description of problem: I've found this right after loggin' in to a Xfce session (Fedora Workstation x86_64, as qemu-guest). Version-Release number of selected component: selinux-policy-3.13.1-211.fc25.noarch Additional info: reporter: libreport-2.7.2 hashmarkername: setroubleshoot kernel: 4.8.0-0.rc4.git0.1.fc25.x86_64 type: libreport
I hit this issue too after upgrading a mostly new F24 install to F25.
selinux-policy-3.13.1-214.fc25 has been submitted as an update to Fedora 25. https://bodhi.fedoraproject.org/updates/FEDORA-2016-5f88bebc7c
selinux-policy-3.13.1-214.fc25 has been pushed to the Fedora 25 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-5f88bebc7c
selinux-policy-3.13.1-214.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.