Description of problem: Gnome-bluetooth manager will not run under Enforcing SELinux settings. Version-Release number of selected component (if applicable): gnome-bluetooth-0.7.0-2 How reproducible: every time Steps to Reproduce: 1. Try to start Gnome-bluetooth manager from Gnome menu or CLI Actual results: Nothing appears to happen Expected results: Bluetooth manager to start up Additional info: If you change to permissive SELinux settings it appears to work fine. This was on a freshly installed system with updates applied. No customisations made yet.
Created attachment 126540 [details] grep of "blue" against /var/messages/log
SELinux bugs should be assigned to SELinux components regardless of the actual package since the policy is managed centrally. Reassigning.
Essentially a "me too" running FC5 with all released updates (not testing on this box) with selinux enforcing Same errors as reported above from hcid/bluez-pin/sdpd/rfcomm
Fixed in selinux-policy-2.2.29-2.fc5
Using bluetooth with selinux-policy-2.2.29-3.fc5 does not work with selinux set to enforce. The following message is shown in /var/log/messages: Apr 22 10:33:41 f10197 hcid[2069]: Can't get system message bus name: Connection ":1.0" is not allowed to own the service "org.bluez" due to SELinux policy Apr 22 10:33:41 f10197 sdpd[2072]: Bluetooth SDP daemon Apr 22 10:33:41 f10197 hcid[2069]: Unable to get on D-BUS Using setenforce to change se-linux to permisseve allows bluetooth to work. Is this bug perhaps connected to bug # 182094?
Are you seeing any AVC MEssages?
I've scanned /var/log/messages for some messages. Near the messages mentioned above no SELinux messages are present. There is however a message, which might be of interest?? Apr 23 17:13:06 i243061 kernel: audit(1145805186.643:30): user pid=2062 uid=81 auid=4294967295 msg='avc: denied { acquire_svc } for service=org.bluez spid=3726 scontext=system_u:system_r:bluetooth_t tcontext=system_u:system_r:system_dbusd_t tclass=dbus
Try selinux-policy-2.2.34-3.fc5
Closing as these have been marked as modified, for a while. Feel free to reopen if not fixed