Comments

41 Comments
User Icon jkurik commented & provided feedback on pcp-7.0.3-1.fc44 3 days ago
karma

With updated compose to the latest at 2025-11-13 I can not reproduce the AVC anymore. Giving this positive karma as the AVC fluctuation does not seem to be related to this build.

User Icon jkurik commented & provided feedback on pcp-7.0.3-1.fc43 4 days ago
karma

Uppps... the comment above was related to rawhide build (f44), not to the f43 one. This build seems to be OK.

BZ#2397077 pmda-hdb triggers a selinux AVC

I am getting a new AVC with this build. Probably not related to PCP it self, but rather to some changes in selinux-policy ?

# ausearch -m AVC
type=AVC msg=audit(1762936134.961:3109): avc:  denied  { name_bind } for  pid=108196 comm="pmcd" src=44321 scontext=system_u:system_r:pcp_pmcd_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket permissive=0

# audit2allow -a
#============= pcp_pmcd_t ==============
#!!!! This avc can be allowed using the boolean 'nis_enabled'
allow pcp_pmcd_t ephemeral_port_t:tcp_socket name_bind;
User Icon jkurik commented & provided feedback on pcp-7.0.3-1.fc43 4 days ago
karma

I am getting a new AVC with this build. Probably not related to PCP it self, but rather to some changes in selinux-policy ?

# ausearch -m AVC
type=AVC msg=audit(1762936134.961:3109): avc:  denied  { name_bind } for  pid=108196 comm="pmcd" src=44321 scontext=system_u:system_r:pcp_pmcd_t:s0 tcontext=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket permissive=0

# audit2allow -a
#============= pcp_pmcd_t ==============
#!!!! This avc can be allowed using the boolean 'nis_enabled'
allow pcp_pmcd_t ephemeral_port_t:tcp_socket name_bind;
BZ#2397077 pmda-hdb triggers a selinux AVC
karma

Gating tests run manually: Affected by https://bugzilla.redhat.com/show_bug.cgi?id=2400458, otherwise OK.

karma

Gating tests run manually: Affected by https://bugzilla.redhat.com/show_bug.cgi?id=2400458, otherwise OK.

karma

Tested manually - seems to be OK.

karma

LGTM

karma

LGTM

karma

No regression has been observed,

karma

Looks good, no regression and no selinux issue has been observed.

BZ#2363903 SELinux is preventing ps from using the sys_admin capability.
karma

Works for me. The bug 2358326 is fixed (reproducible with the previous build, but not with this new one).

karma

Works for me. The bug 2358326 is fixed (reproducible with the previous build, but not with this new one).

karma

Works for me. The bug 2358326 is fixed (reproducible with the previous build, but not with this new one).

karma

LGTM The failure of "fedora-ci.koji-build.rpminspect.static-analysis" is expected as this is the mechanism how the code change is delivered.

karma

Looks good to me.

karma

Looks good to me.

karma

Looks good to me.

Looks good to me.