Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: user login SELinux is preventing snapd from 'write' accesses on the Verzeichnis /var/cache/snapd. ***** Plugin catchall_labels (83.8 confidence) suggests ******************* If sie snapd den Zugriff write auf snapd directory erlauben wollen Then sie müssen das Label auf /var/cache/snapd ändern Do # semanage fcontext -a -t FILE_TYPE '/var/cache/snapd' wobei FILE_TYPE einer der folgenen Werte ist: snappy_home_t, snappy_var_lib_t, snappy_var_run_t, snappy_var_t, systemd_unit_file_t, tmp_t, udev_rules_t, user_home_dir_t. Führen Sie danach Folgendes aus: restorecon -v '/var/cache/snapd' ***** Plugin catchall (17.1 confidence) suggests ************************** If sie denken, dass es snapd standardmäßig erlaubt sein sollte, write Zugriff auf snapd directory zu erhalten. Then sie sollten dies als Fehler melden. Um diesen Zugriff zu erlauben, können Sie ein lokales Richtlinien-Modul erstellen. Do allow this access for now by executing: # ausearch -c 'snapd' --raw | audit2allow -M my-snapd # semodule -X 300 -i my-snapd.pp Additional Information: Source Context system_u:system_r:snappy_t:s0 Target Context system_u:object_r:var_t:s0 Target Objects /var/cache/snapd [ dir ] Source snapd Source Path snapd Port <Unbekannt> Host (removed) Source RPM Packages Target RPM Packages snapd-2.29.4-2.fc27.x86_64 Policy RPM selinux-policy-3.13.1-283.17.fc27.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 4.13.15-300.fc27.x86_64 #1 SMP Tue Nov 21 21:10:22 UTC 2017 x86_64 x86_64 Alert Count 1 First Seen 2017-12-02 10:44:43 CET Last Seen 2017-12-02 10:44:43 CET Local ID 7416ef6c-f061-4e74-8116-fd38cf4b3f5d Raw Audit Messages type=AVC msg=audit(1512207883.857:254): avc: denied { write } for pid=3195 comm="snapd" name="snapd" dev="dm-2" ino=262157 scontext=system_u:system_r:snappy_t:s0 tcontext=system_u:object_r:var_t:s0 tclass=dir permissive=1 Hash: snapd,snappy_t,var_t,dir,write Version-Release number of selected component: selinux-policy-3.13.1-283.17.fc27.noarch Additional info: component: selinux-policy reporter: libreport-2.9.3 hashmarkername: setroubleshoot kernel: 4.13.15-300.fc27.x86_64 type: libreport
Description of problem: Installed snapd (sudo dnf install snapd). During the installation process several SELinux denials are raised Version-Release number of selected component: selinux-policy-3.13.1-283.24.fc27.noarch Additional info: reporter: libreport-2.9.3 hashmarkername: setroubleshoot kernel: 4.14.16-300.fc27.x86_64 type: libreport
Description of problem: This error message poped up after installing the snappy core from the official Fedora reps, after rebooting. (Almost all my selinux alerts are from snapd) Version-Release number of selected component: selinux-policy-3.13.1-283.24.fc27.noarch Additional info: reporter: libreport-2.9.3 hashmarkername: setroubleshoot kernel: 4.15.3-300.fc27.x86_64 type: libreport
Description of problem: Snapd starts with the system, upon logging in SELinux begins notifying. No further steps. Version-Release number of selected component: selinux-policy-3.13.1-283.21.fc27.noarch Additional info: reporter: libreport-2.9.3 hashmarkername: setroubleshoot kernel: 4.14.16-300.fc27.x86_64 type: libreport
Description of problem: I followed the guide in https://docs.fedoraproject.org/quick-docs/en-US/installing-spotify.html#Snap to install spotfiy This results in a ton of SElinux alerts, and some of them don't make much sense (e.g., snapd is trying to write to directory snapd). Also, the messages by SELinux doesn't tell where these directories are, so I can't check permissions on them. Version-Release number of selected component: selinux-policy-3.13.1-283.24.fc27.noarch Additional info: reporter: libreport-2.9.3 hashmarkername: setroubleshoot kernel: 4.15.4-300.fc27.x86_64 type: libreport
Description of problem: This AVC Denial occurs when I boot my system and log into gnome. Version-Release number of selected component: selinux-policy-3.13.1-283.26.fc27.noarch Additional info: reporter: libreport-2.9.3 hashmarkername: setroubleshoot kernel: 4.15.6-300.fc27.x86_64 type: libreport
Description of problem: Install snapd. SELinux starts alerting. Version-Release number of selected component: selinux-policy-3.13.1-283.34.fc27.noarch Additional info: reporter: libreport-2.9.3 hashmarkername: setroubleshoot kernel: 4.16.6-202.fc27.x86_64 type: libreport
snapd-glib-1.41-1.fc28 snapd-2.33.1-1.fc28 has been submitted as an update to Fedora 28. https://bodhi.fedoraproject.org/updates/FEDORA-2018-942eec912c
snapd-glib-1.41-1.fc27 snapd-2.33.1-1.fc27 has been submitted as an update to Fedora 27. https://bodhi.fedoraproject.org/updates/FEDORA-2018-1330056acb
snapd-2.33.1-1.fc27, snapd-glib-1.41-1.fc27 has been pushed to the Fedora 27 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2018-1330056acb
snapd-2.33.1-1.fc28, snapd-glib-1.41-1.fc28 has been pushed to the Fedora 28 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2018-942eec912c
snapd-2.33.1-1.fc27, snapd-glib-1.41-1.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.
snapd-2.33.1-1.fc28, snapd-glib-1.41-1.fc28 has been pushed to the Fedora 28 stable repository. If problems still persist, please make note of it in this bug report.