Description of problem: SELinux is preventing firewalld from using the 'sys_nice' capabilities. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that firewalld should have the sys_nice capability by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'firewalld' --raw | audit2allow -M my-firewalld # semodule -X 300 -i my-firewalld.pp Additional Information: Source Context system_u:system_r:firewalld_t:s0 Target Context system_u:system_r:firewalld_t:s0 Target Objects Unknown [ capability ] Source firewalld Source Path firewalld Port <Unknown> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-3.14.6-6.fc33.noarch Local Policy RPM selinux-policy-targeted-3.14.6-6.fc33.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Permissive Host Name (removed) Platform Linux (removed) 5.6.0-0.rc4.git0.1.fc33.x86_64 #1 SMP Mon Mar 2 17:20:57 UTC 2020 x86_64 x86_64 Alert Count 2 First Seen 2020-02-27 01:43:12 +05 Last Seen 2020-03-05 15:32:32 +05 Local ID fd1733d8-2658-41c0-9f77-5c9f35e6bb63 Raw Audit Messages type=AVC msg=audit(1583404352.303:1523): avc: denied { sys_nice } for pid=1134 comm="firewalld" capability=23 scontext=system_u:system_r:firewalld_t:s0 tcontext=system_u:system_r:firewalld_t:s0 tclass=capability permissive=1 Hash: firewalld,firewalld_t,firewalld_t,capability,sys_nice Version-Release number of selected component: selinux-policy-3.14.6-6.fc33.noarch Additional info: component: selinux-policy reporter: libreport-2.12.0 hashmarkername: setroubleshoot kernel: 5.6.0-0.rc5.git0.1.fc33.x86_64 type: libreport Potential duplicate: bug 863686
Michail, Thank you for reporting the issue. This bug seems to reproduce only if accountsservice is installed and running. Are you aware of any functionality issues in firewalld service?
*** Bug 1816869 has been marked as a duplicate of this bug. ***
Similar problem has been detected: This has repeatedly popped up since upgrading to the Fedora 32 branch hashmarkername: setroubleshoot kernel: 5.6.0-0.rc5.git0.2.fc32.x86_64 package: selinux-policy-3.14.5-31.fc32.noarch reason: SELinux is preventing firewalld from using the 'sys_nice' capabilities. type: libreport
Similar problem has been detected: Not sure. Just updated on Fedora 32 Beta, after sometime popup about Selinux problem is showed up hashmarkername: setroubleshoot kernel: 5.6.0-0.rc7.git0.2.fc32.x86_64 package: selinux-policy-3.14.5-31.fc32.noarch reason: SELinux is preventing firewalld from using the 'sys_nice' capabilities. type: libreport
*** This bug has been marked as a duplicate of bug 1811407 ***
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 1000 days