Bug 1470312 - GDM fails to start when SELinux default user is mapped to the guest_u user
GDM fails to start when SELinux default user is mapped to the guest_u user
Status: NEW
Product: Fedora
Classification: Fedora
Component: gdm (Show other bugs)
x86_64 Linux
unspecified Severity medium
: ---
: ---
Assigned To: Ray Strode [halfline]
Fedora Extras Quality Assurance
Depends On:
  Show dependency treegraph
Reported: 2017-07-12 13:58 EDT by Richard Berg
Modified: 2017-12-18 13:37 EST (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Last Closed:
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
logs (7.85 KB, text/plain)
2017-07-12 13:58 EDT, Richard Berg
no flags Details

  None (edit)
Description Richard Berg 2017-07-12 13:58:39 EDT
Created attachment 1297141 [details]

Description of problem:
GDM fails to start when SELinux default user is mapped to the guest_u user on Fedora 26. The following error message is shown in the console:
  Failed to start User Manager for UID 42 

UID 42 is gdm:
  getent passwd | grep 42

On Fedora 25 GDM starts without any problems when SELinux default user mapped is to guest_u user.

Version-Release number of selected component (if applicable):

Some other component versions:

How reproducible:

Steps to Reproduce:
1. Install Fedora 26 Workstation with default settings.
2. Change mapping of default SELinux user to guest_u with the following command:
  semanage login -m -s guest_u __default__
3. Reboot the computer

Actual results:
Computer boot stops in text mode. The following error message is show:
  Failed to start User Manager for UID 42 

Expected results:
Computer booting to GNOME login screen.

Additional info:
It looks like gdm is started with guest_r role and this role is picked because SELinux default user is mapped to guest_u. SELinux default user should not be used for services.

See attachment for journalctl and AVCs output.
Comment 1 Taras 2017-07-18 11:43:52 EDT
Got this problem while upgrading from 25 with DNF system-upgrade plugin. Is it possible to fix it via specifying SELinux settings for GDM manually?
Comment 2 Benjamin Kreuter 2017-09-12 17:10:48 EDT
This also appears to be a problem when the default user is user_u.
Comment 3 Quintin 2017-12-18 13:37:20 EST
I also have this issue. It seems to be temporarily fixed by first logging in as the xguest user without a desktop environment, then logging in with the desktop environment.

So long as the xguest user is already logged in, selinux seems to allow the user to log in with GDM as well.

Note You need to log in before you can comment on or make changes to this bug.