Hide Forgot
Description of problem: sealert does not log selinux alerts anymore even though multiples services (amavisd, bip, denyhosts, ddclient) are failing on boot if the system is not switched to permissive mode I doubt anyone will run rawhide in enforcing mode anymore if there is no easy way to report policy problems Version-Release number of selected component (if applicable): setroubleshoot-server-3.0.47-1.fc17.x86_64
We see this also on F16. The problem is downgraded setroubleshoot does not work too. Btw. What AVC msgs are you getting?
Could you try to downgrade python-slip-dbus?
(In reply to comment #2) > Could you try to downgrade python-slip-dbus? I've tried all python-slip* versions from the latest rawhide one till python-slip-0.2.17-1.fc16.noarch python-slip-gtk-0.2.17-1.fc16.noarch python-slip-dbus-0.2.17-1.fc16.noarch (rebooting after each downgrade) but sealert stays empty
Created attachment 556380 [details] system avcs (In reply to comment #1) > Btw. What AVC msgs are you getting?
(In reply to comment #4) > Created attachment 556380 [details] > system avcs BTW, I made the mistake of forcing an autorelabel after installing selinux-policy-targeted-3.10.0-76.fc17.noarch since its changelog semmed to indicate some of those were fixed selinux blocked itself at the relabel stage (blocked changing of booleans and another file I don't remember) so now I need to boot with selinux=0 Otherwise it will try to relabel, block itself, and make no progress
Fixed in setroubleshoot-3.1.1-1.fc17
(In reply to comment #5) > (In reply to comment #4) > > Created attachment 556380 [details] > > system avcs > > BTW, I made the mistake of forcing an autorelabel after installing > selinux-policy-targeted-3.10.0-76.fc17.noarch since its changelog semmed to > indicate some of those were fixed > > selinux blocked itself at the relabel stage (blocked changing of booleans and > another file I don't remember) > > so now I need to boot with selinux=0 > > Otherwise it will try to relabel, block itself, and make no progress Got the relabel to work by booting with enforcing=0 and single mode. Though it was quite un-obvious