Created attachment 407546 [details] system logs Description of problem: Used preugprade from F12 to F13 Branched. After re-booting NFS statd and HAL fail to start. Xorg fails to start. Fully updated from updates-testing, rebooted. statd and HAL still fail to start, but at least Xorg works now. NetworkManager doesn't want to connect to network. After inspecting logs it seems like SELinux issue. When booted with enforcing=0 kernel option, all services start up fine, everything works. While updating packages with preupgrade there must have been some problem with SELinux and it is now blocking many services and programs. All logs attached. Version-Release number of selected component (if applicable): libselinux-2.0.90-5.fc13.x86_64 libselinux-python-2.0.90-5.fc13.x86_64 libselinux-utils-2.0.90-5.fc13.x86_64 selinux-policy-3.7.15-4.fc13.noarch selinux-policy-targeted-3.7.15-4.fc13.noarch How reproducible: did preugprade from F12 to F13 twice, happened everytime Additional info: This could be the same issue as reported in bug 505772. Also please note that for verifying this issue the fix must be committed to stable F13 repository, not F13 updates-testing. Because preupgrade does not download packages from updates-testing. I have no experience with using SELinux, but I can provide more information if you tell me how.
selinux-policy-3.7.19-2.fc13.noarch is already a candidate and fixes most of the avc's reported. The troublesome ones are the fontconfig.
Will updating to the newer version of selinux automatically fix the problems, or are there some manual steps required afterwards (re-labeling files with correct context and whatnot?).
It should fix most if not all the problems. Relabeling should happen automatically. If you still have problems after update, please open bugs. I would likt to get 19-2 into the iso so we could test the upgrade path though.
selinux-policy-3.7.19-2.fc13.noarch seems to solve all my problems. We would really prefer if this could get into stable f13 repo before preupgrade test day: https://fedoraproject.org/wiki/Test_Day:2010-04-29_Preupgrade
Increase its kama.
Discussed at the blocker review meeting today, we agree this is a blocker and will try to put feedback in Bodhi soon. -- Fedora Bugzappers volunteer triage team https://fedoraproject.org/wiki/BugZappers
selinux-policy-3.7.19-6.fc13 has been submitted as an update for Fedora 13. http://admin.fedoraproject.org/updates/selinux-policy-3.7.19-6.fc13
selinux-policy-3.7.19-6.fc13 has been pushed to the Fedora 13 testing repository. If problems still persist, please make note of it in this bug report. If you want to test the update, you can install it with su -c 'yum --enablerepo=updates-testing update selinux-policy'. You can provide feedback for this update here: http://admin.fedoraproject.org/updates/selinux-policy-3.7.19-6.fc13
I have updated to selinux-policy-3.7.19-6.fc13 and I see this avc denial in /var/log/messages after bootup: Apr 27 05:08:17 localhost kernel: type=1400 audit(1272359290.665:4): avc: denied { mmap_zero } for pid=420 comm="vbetool" scontext=system_u:system_r:vbetool_t:s0-s0:c0.c1023 tcontext=system_u:system_r:vbetool_t:s0-s0:c0.c1023 tclass=memprotect There is not denial in /var/log/audit/audit.log though.
It happens before auditd is started, This bug has been reported against vbetool in the past.
Daniel, I can't find you on any IRC channel. Does this mean that selinux-policy-3.7.19-6.fc13 should get -1 karma from me? Do you have bug number for that vbetool bug?
selinux-policy-3.7.19-6.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in this bug report.