Bug 2260116 - plymouthd denials when shutting down or rebooting with the 6.8-rc1 kernel
Summary: plymouthd denials when shutting down or rebooting with the 6.8-rc1 kernel
Keywords:
Status: CLOSED DUPLICATE of bug 2259622
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: rawhide
Hardware: Unspecified
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-01-24 14:23 UTC by Matt Fagnani
Modified: 2024-01-30 17:33 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2024-01-30 17:33:31 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
Journal from a shutdown with 6.8-rc1 showing plymouthd denials (281.65 KB, text/plain)
2024-01-24 14:28 UTC, Matt Fagnani
no flags Details

Description Matt Fagnani 2024-01-24 14:23:13 UTC
I installed the 6.8-rc1 kernel in a Fedora Rawhide KDE Plasma installation. When I've shut down or rebooted with the 6.8-rc1 kernel, plymouthd denials were shown in the journal which didn't appear with the 6.7.0 kernel.

Jan 23 07:32:57 audit[27434]: AVC avc:  denied  { read write } for  pid=27434 comm="plymouthd" name="kmsg" dev="devtmpfs" ino=10 scontext=system_u:system_r:plymouthd_t:s0 tcontext=system_u:object_r:kmsg_device_t:s0 tclass=chr_file permissive=0

Jan 23 07:32:57 audit[27434]: AVC avc:  denied  { checkpoint_restore } for  pid=27434 comm="plymouthd" capability=40  scontext=system_u:system_r:plymouthd_t:s0 tcontext=system_u:system_r:plymouthd_t:s0 tclass=capability2 permissive=0

Jan 23 07:32:58 audit[27434]: AVC avc:  denied  { read } for  pid=27434 comm="plymouthd" name="SecureBoot-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=3196 scontext=system_u:system_r:plymouthd_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=0

The denials of checkpoint_restore were sometimes shown several hundred times during shutdown or reboot. The denials were shown 4/5 times. The time the denials weren't shown was during a dnf offline upgrade where I had pressed Escape to see the details of the upgrade so the plymouth screen with the spinner wasn't shown during reboot. selinux-policy-40.9-1.fc40.noarch was used in enforcing mode. I have Secure Boot enabled which might be needed for the last denial. I'll attach the journal from a shutdown with the denials.

Reproducible: Sometimes

Steps to Reproduce:
1. Boot the 6.8.0-0.rc1.12.fc40 kernel in a Fedora Rawhide KDE Plasma installation
2. Log in to Plasma
3. Shut down or reboot
Actual Results:  
plymouthd denials when shutting down or rebooting with the 6.8-rc1 kernel

Expected Results:  
No denials should have been shown.

Comment 1 Matt Fagnani 2024-01-24 14:28:25 UTC
Created attachment 2010205 [details]
Journal from a shutdown with 6.8-rc1 showing plymouthd denials

Comment 2 Zdenek Pytela 2024-01-30 17:33:31 UTC

*** This bug has been marked as a duplicate of bug 2259622 ***


Note You need to log in before you can comment on or make changes to this bug.