stable

selinux-policy-3.13.1-154.fc23

FEDORA-2015-6b85d80ba8 created by mgrepl 9 years ago for Fedora 23

selinux-policy-3.13.1-154.fc23

  • The ABRT coredump handler has code to emulate default core file creation The handler runs in a separate process with abrt_dump_oops_t SELinux process type. abrt-hook-ccpp also saves the core dump file in the very same way as kernel does and a user can specify CWD location for a coredump. abrt-hook-ccpp has been made as a SELinux aware apps to create this coredumps with correct labeling and with this commit the policy rules have been updated to allow access all non security files on a system.
  • Since /dev/log is a symlink, we need to allow relabelto also symlink. This commit update logging_relabel_devlog_dev() interface to allow it.
  • systemd-user has pam_selinux support and needs to able to compute user security context if init_t is not unconfined domain.

More info: http://koji.fedoraproject.org/koji/buildinfo?buildID=694542

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2015-6b85d80ba8

This update has been submitted for testing by mgrepl.

9 years ago

This update has obsoleted selinux-policy-3.13.1-153.fc23, and has inherited its bugs and notes.

9 years ago

This update has been pushed to testing.

9 years ago
User Icon cserpentis commented & provided feedback 9 years ago
karma

works fine

User Icon lslebodn commented & provided feedback 9 years ago
karma

problem with abrt is solved +1

BZ#1276305 SELinux is preventing abrt-hook-ccpp from using the 'sigchld' accesses on a process.
User Icon jpopelka commented & provided feedback 9 years ago
karma

no problems spotted

User Icon mhayden commented & provided feedback 9 years ago
karma

Works for me.

User Icon jfilak commented & provided feedback 9 years ago

User coredumps are still not working.

Reproducer

$ sudo setenforce 0 $ ulimit -c unlimited $ will_segfault

BZ#1276305 SELinux is preventing abrt-hook-ccpp from using the 'sigchld' accesses on a process.

This update has been submitted for stable by bodhi.

9 years ago
User Icon renault commented & provided feedback 9 years ago
karma

No trouble for me

This update has been pushed to stable.

9 years ago

Please log in to add feedback.

Metadata
Type
bugfix
Severity
high
Karma
5
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
5
Stable by Time
disabled
Dates
submitted
9 years ago
in testing
9 years ago
in stable
9 years ago
BZ#1273733 SELinux issues with latest chrony (F23)
0
0
BZ#1276305 SELinux is preventing abrt-hook-ccpp from using the 'sigchld' accesses on a process.
-1
1

Automated Test Results