Bug 1688883 - the sandbox running with errors
Summary: the sandbox running with errors
Keywords:
Status: CLOSED EOL
Alias: None
Product: Fedora
Classification: Fedora
Component: policycoreutils
Version: 29
Hardware: x86_64
OS: Linux
unspecified
urgent
Target Milestone: ---
Assignee: Petr Lautrbach
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2019-03-14 16:17 UTC by Cătălin George Feștilă
Modified: 2020-02-26 10:50 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2019-11-27 22:19:21 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Cătălin George Feștilă 2019-03-14 16:17:51 UTC
Description of problem:
sandbox tool create multiple errors 

Version-Release number of selected component (if applicable):
Fedora 29 - last update/upgrade:14 march 2019
kernel: 4.20.14-200.fc29.x86 

How reproducible:

I tested with firefox application 

Steps to Reproduce:

1. [root@desk selinux_001]# dnf install selinux-policy-sandbox

2. [mythcat@desk default]$ sandbox -X -t sandbox_web_t firefox
/usr/bin/sandbox: 
/usr/sbin/seunshare is required for the action you want to perform.

3. [root@desk selinux_001]#  yum whatprovides /usr/sbin/seunshare
Last metadata expiration check: 0:25:45 ago on Wed 13 Mar 2019 10:32:19 PM EET.
policycoreutils-sandbox-2.8-17.fc29.x86_64 : SELinux sandbox utilities
Repo        : updates
Matched from:
Filename    : /usr/sbin/seunshare

policycoreutils-sandbox-2.8-8.fc29.x86_64 : SELinux sandbox utilities
Repo        : fedora
Matched from:
Filename    : /usr/sbin/seunshare

4. [root@desk selinux_001]# dnf install policycoreutils-sandbox-2.8-17.fc29.x86_64

5. [mythcat@desk default]$ sandbox -X -t sandbox_web_t firefox

Actual results:

[mythcat@desk default]$ sandbox -X -t sandbox_web_t firefox

dbus[6613]: Unable to set up transient service directory: XDG_RUNTIME_DIR subdirectory "/run/user/1000/dbus-1" not available: Permission denied
dbus-daemon[6613]: [session uid=1000 pid=6613] Activating service name='org.gtk.vfs.Daemon' requested by ':1.0' (uid=1000 pid=6614 comm="/usr/lib64/firefox/firefox " label="unconfined_u:unconfined_r:sandbox_web_client_t:s0:c26,c671")
dbus-daemon[6613]: [session uid=1000 pid=6613] Successfully activated service 'org.gtk.vfs.Daemon'
fuse: bad mount point `/run/user/1000/gvfs': Permission denied
dbus-daemon[6613]: [session uid=1000 pid=6613] Activating service name='org.a11y.Bus' requested by ':1.2' (uid=1000 pid=6614 comm="/usr/lib64/firefox/firefox " label="unconfined_u:unconfined_r:sandbox_web_client_t:s0:c26,c671")
dbus-daemon[6613]: [session uid=1000 pid=6613] Activating service name='org.xfce.Xfconf' requested by ':1.3' (uid=1000 pid=6741 comm="/usr/libexec/at-spi-bus-launcher " label="unconfined_u:unconfined_r:sandbox_web_client_t:s0:c26,c671")
dbus-daemon[6613]: [session uid=1000 pid=6613] Successfully activated service 'org.xfce.Xfconf'

(process:6741): dconf-CRITICAL **: 23:14:05.991: unable to create file '/run/user/1000/dconf/user': Permission denied.  dconf will not work properly.

(process:6741): dconf-WARNING **: 23:14:05.991: unable to open file '/etc/dconf/db/local': Failed to map /etc/dconf/db/local' /etc/dconf/db/local': mmap() failed: Permission denied; expect degraded performance

(process:6741): dconf-WARNING **: 23:14:05.991: unable to open file '/etc/dconf/db/site': Failed to map /etc/dconf/db/site' /etc/dconf/db/site': mmap() failed: Permission denied; expect degraded performance

(process:6741): dconf-WARNING **: 23:14:05.991: unable to open file '/etc/dconf/db/distro': Failed to map /etc/dconf/db/distro' /etc/dconf/db/distro': mmap() failed: Permission denied; expect degraded performance

(process:6741): dconf-CRITICAL **: 23:14:05.991: unable to create file '/run/user/1000/dconf/user': Permission denied.  dconf will not work properly.

(firefox:6614): dconf-CRITICAL **: 23:19:08.721: unable to create file '/run/user/1000/dconf/user': Permission denied.  dconf will not work properly.


... 


XIO:  fatal IO error 11 (Resource temporarily unavailable) on X server ":1"
      after 1059 requests (1054 known processed) with 0 events remaining.
Gdk-Message: 23:19:20.372: /usr/lib64/firefox/firefox: Fatal IO error 11 (Resource temporarily unavailable) on X server :1.

Gdk-Message: 23:19:20.372: /usr/lib64/firefox/firefox: Fatal IO error 11 (Resource temporarily unavailable) on X server :1.

Gdk-Message: 23:19:20.374: /usr/lib64/firefox/firefox: Fatal IO error 11 (Resource temporarily unavailable) on X server :1.

Gdk-Message: 23:19:20.379: firefox: Fatal IO error 11 (Resource temporarily unavailable) on X server :1.

Sandbox: Unexpected EOF, op 2 flags 00 path /etc/localtime
Gdk-Message: 21:19:20.397: /usr/lib64/firefox/firefox: Fatal IO error 11 (Resource temporarily unavailable) on X server :1.


(xfconfd:6745): xfconfd-CRITICAL **: 23:19:21.049: Name org.xfce.Xfconf lost on the message dbus, exiting.
A connection to the bus can't be made

Expected results:

no errors

Additional info:

Comment 1 Ben Cotton 2019-10-31 19:28:30 UTC
This message is a reminder that Fedora 29 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora 29 on 2019-11-26.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
Fedora 'version' of '29'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version.

Thank you for reporting this issue and we are sorry that we were not 
able to fix it before Fedora 29 is end of life. If you would still like 
to see this bug fixed and are able to reproduce it against a later version 
of Fedora, you are encouraged  change the 'version' to a later Fedora 
version prior this bug is closed as described in the policy above.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events. Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

Comment 2 Ben Cotton 2019-11-27 22:19:21 UTC
Fedora 29 changed to end-of-life (EOL) status on 2019-11-26. Fedora 29 is
no longer maintained, which means that it will not receive any further
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of
Fedora please feel free to reopen this bug against that version. If you
are unable to reopen this bug, please file a new report against the
current release. If you experience problems, please add a comment to this
bug.

Thank you for reporting this bug and we are sorry it could not be fixed.

Comment 3 jtougne 2020-02-26 10:50:10 UTC
FYI we had the same problem when dbus-x11 was not installed (it's required by firefox).


Note You need to log in before you can comment on or make changes to this bug.