Hide Forgot
Description of problem: After an update to kernel-4.8.8-100.fc23.x86_64 on November 24th the following started to show quite regularly: SELinux is preventing fprintd from using the wake_alarm capability. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that fprintd should have the wake_alarm capability by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'fprintd' --raw | audit2allow -M my-fprintd # semodule -X 300 -i my-fprintd.pp Additional Information: Source Context system_u:system_r:fprintd_t:s0 Target Context system_u:system_r:fprintd_t:s0 Target Objects Unknown [ capability2 ] Source fprintd Source Path fprintd Port <Unknown> Host aaa.bbb.cc Source RPM Packages Target RPM Packages Policy RPM selinux-policy-3.13.1-158.24.fc23.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Permissive Host Name aaa.bbb.cc Platform Linux aaa.bbb.cc 4.8.8-100.fc23.x86_64 #1 SMP Tue Nov 15 18:51:53 UTC 2016 x86_64 x86_64 Alert Count 9 First Seen 2016-11-24 18:44:37 CET Last Seen 2016-11-25 11:16:39 CET Local ID 9289498f-64e6-4947-9693-350bc2ed0eee Raw Audit Messages type=AVC msg=audit(1480068999.967:308): avc: denied { wake_alarm } for pid=9816 comm="fprintd" capability=35 scontext=system_u:system_r:fprintd_t:s0 tcontext=system_u:system_r:fprintd_t:s0 tclass=capability2 permissive=1 Hash: fprintd,fprintd_t,fprintd_t,capability2,wake_alarm Version-Release number of selected component (if applicable): selinux-policy-3.13.1-158.24 How reproducible: the number of incidents seems to be growing Additional info: The same update included also perl with a bunch of modules, hwdata, ghostscript, bind99 and other ods-and-ends so that this is linked to a kernel version is only a guess.
This seems to happen when waking up a machine from suspend, but I cannot tell for sure if only in such circumstances (and I got the next one).
Fedora 23 changed to end-of-life (EOL) status on 2016-12-20. Fedora 23 is no longer maintained, which means that it will not receive any further security or bug fix updates. As a result we are closing this bug. If you can reproduce this bug against a currently maintained version of Fedora please feel free to reopen this bug against that version. If you are unable to reopen this bug, please file a new report against the current release. If you experience problems, please add a comment to this bug. Thank you for reporting this bug and we are sorry it could not be fixed.