stable

selinux-policy-3.14.2-34.fc29

FEDORA-2018-db240a1726 created by lvrabec 6 years ago for Fedora 29

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2018-db240a1726

This update has been submitted for testing by lvrabec.

6 years ago
User Icon adamwill commented & provided feedback 6 years ago
karma

Fixes all Workstation boot slowness for me.

BZ#1625218 Fedora Workstation 29 takes a long time to boot in enforcing mode.
User Icon adamwill commented & provided feedback 6 years ago
karma

Solves all boot slowness for me.

BZ#1625218 Fedora Workstation 29 takes a long time to boot in enforcing mode.
User Icon kalev commented & provided feedback 6 years ago
karma

No regressions noted here and seems to fix boot slowness

BZ#1625218 Fedora Workstation 29 takes a long time to boot in enforcing mode.
User Icon mohanboddu commented & provided feedback 6 years ago
karma

No regressions after the reboot.

User Icon mohanboddu commented & provided feedback 6 years ago
karma

No regressions after the reboot.

User Icon mohanboddu commented & provided feedback 6 years ago
karma

No issues after the update.

User Icon pwhalen commented & provided feedback 6 years ago
karma

No issues.

User Icon pwhalen commented & provided feedback 6 years ago
karma

No issues.

User Icon pwhalen commented & provided feedback 6 years ago
karma

no issues.

User Icon sgallagh commented & provided feedback 6 years ago
karma

No regressions noted and I'm seeing fewer AVCs at login than previously.

User Icon sgallagh commented & provided feedback 6 years ago
karma

No regressions noted and I'm seeing fewer AVCs at login than previously.

User Icon sgallagh commented & provided feedback 6 years ago
karma

No regressions noted and I'm seeing fewer AVCs at login than previously.

This update has been submitted for stable by adamwill.

6 years ago
karma
BZ#1593816 SELinux is preventing (upowerd) from 'mounton' accesses on the directory /var/lib/upower.
BZ#1596929 SELinux is preventing (uetoothd) from 'mounton' accesses on the fichier /run/systemd/unit-root/proc/kallsyms.
BZ#1605200 SELinux is preventing (fprintd) from 'mounton' accesses on the fichier /run/systemd/unit-root/proc/kallsyms.
BZ#1607807 AVC avc: denied { setpcap } for pid=1213 comm="sedispatch" capability=8
BZ#1608028 SELinux is preventing ebtables from using the 'net_raw' capabilities.
BZ#1608029 SELinux is preventing ebtables from 'getopt' accesses on the rawip_socket Unknown.
BZ#1608030 SELinux is preventing ebtables from 'create' accesses on the rawip_socket Unknown.
BZ#1625218 Fedora Workstation 29 takes a long time to boot in enforcing mode.
User Icon nonamedotc commented & provided feedback 6 years ago
karma

Fix the sluggish boot on F29 xfce. No regressions noticed.

User Icon nonamedotc commented & provided feedback 6 years ago
karma

Fixes sluggish boot in Fedora 29 Xfce.

User Icon nonamedotc commented & provided feedback 6 years ago
karma

Fixes sluggish boot in Fedora 29 Xfce.

This update has been pushed to stable.

6 years ago

Please login to add feedback.

Metadata
Type
bugfix
Severity
high
Karma
7
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-2
Stable by Karma
4
Stable by Time
disabled
Dates
submitted
6 years ago
in stable
6 years ago
BZ#1471533 SElinux is preventing esmtp from writing .esmtp_queue/<hash>/mail on ecryptfs
0
0
BZ#1496274 SELinux policy provides no way for 'tor' to run its pluggable transports
0
0
BZ#1551578 SELinux is preventing systemd-network from 'create' accesses on the netlink_generic_socket Unknown.
0
0
BZ#1554001 SELinux is preventing logrotate from using the 'dac_override' capabilities.
0
0
BZ#1557219 SELinux is preventing (fprintd) from 'remount' accesses on the système de fichiers .
0
0
BZ#1557891 SELinux is preventing (ostnamed) from 'remount' accesses on the système de fichiers .
0
0
BZ#1558441 SELinux is preventing ssh from 'append' accesses on the file known_hosts.
0
0
BZ#1559795 avc: denied { map } for pid=15641 comm="smbcontrol" path="/var/lib/samba/lock/names.tdb" dev="vda1" ino=2492866 scontext=unconfined_u:unconfined_r:smbcontrol_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:samba_var_t:s0 tclass=file permissive=0
0
0
BZ#1567366 selinux denied systemd map_create for bpf class
0
0
BZ#1570587 avc: denied { map_create } for pid=706 comm="systemd" scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tclass=bpf permissive=0
0
0
BZ#1572712 SELinux is preventing systemd from 'map_create' accesses on the bpf Unknown.
0
0
BZ#1574658 [daemon rename] pacemaker-remote package: /usr/sbin/pacemaker_remoted -> /usr/sbin/pacemaker-remoted
0
0
BZ#1575213 SELinux is preventing (geoclue) from 'execute_no_trans' accesses on the file /usr/libexec/geoclue.
0
0
BZ#1575749 Multiple AVC for geoclue (geoclue),init_t,geoclue_exec_t,file,execute_no_trans
0
0
BZ#1579760 Tighten policy in Fedora by removing some execstack permissions
0
0
BZ#1586003 BRLTTY needs additional allow rules in the Selinux policy to function properly.
0
0
BZ#1589663 SELinux is preventing abrt-action-gen from map access on the file 2F686F6D652F6D696B6861696C2F2E6C6F63616C2F73686172652F537465616D2F737465616D617070732F636F6D6D6F6E2F496E7465727374656C6C6172204D6172696E65732F496E7465727374656C6C61724D6172696E65732E783634.
0
0
BZ#1591440 bpftool returns EPERM on all actions
0
0
BZ#1593816 SELinux is preventing (upowerd) from 'mounton' accesses on the directory /var/lib/upower.
0
1
BZ#1593817 SELinux is preventing (upowerd) from using the 'nnp_transition' accesses on a process.
0
0
BZ#1593819 SELinux is preventing gdbus from 'write' accesses on the fifo_file /run/systemd/inhibit/4.ref.
0
0
BZ#1593820 SELinux is preventing upowerd from 'read' accesses on the file /var/lib/upower/history-time-empty-Sony_Interactive_Entertainment_Wireless_Controller-f4:93:9f:56:03:cb.dat.
0
0
BZ#1593821 SELinux is preventing upowerd from 'write' accesses on the directory /var/lib/upower.
0
0
BZ#1595187 SELinux is preventing /usr/libexec/upowerd from 'open' accesses on the chr_file /dev/input/event0.
0
0
BZ#1595189 SELinux is preventing /usr/lib/systemd/systemd-user-runtime-dir from 'unlink' accesses on the file user.
0
0
BZ#1595226 SELinux is preventing /usr/libexec/upowerd from using the 'nnp_transition' accesses on a process.
0
0
BZ#1596499 /usr/sbin/rhn_check* should have same context as /usr/sbin/rhn_check
0
0
BZ#1596928 SELinux is preventing (uetoothd) from 'getattr' accesses on the fichier /run/systemd/unit-root/proc/kcore.
0
0
BZ#1596929 SELinux is preventing (uetoothd) from 'mounton' accesses on the fichier /run/systemd/unit-root/proc/kallsyms.
0
1
BZ#1596930 SELinux is preventing (uetoothd) from 'mounton' accesses on the fichier /run/systemd/unit-root/proc/kcore.
0
0
BZ#1597462 SELinux is preventing (fprintd) from 'mounton' accesses on the file /run/systemd/unit-root/proc/kcore.
0
0
BZ#1597864 SELinux is preventing (coredump) from 'getattr' accesses on the file /run/systemd/unit-root/proc/kcore.
0
0
BZ#1597865 SELinux is preventing (coredump) from 'mounton' accesses on the file /run/systemd/unit-root/proc/kcore.
0
0
BZ#1598400 SELinux is preventing (ostnamed) from 'mounton' accesses on the file /run/systemd/unit-root/proc/kcore.
0
0
BZ#1598401 SELinux is preventing (ostnamed) from 'getattr' accesses on the file /run/systemd/unit-root/proc/kcore.
0
0
BZ#1599230 Mongodb 4.0 avc denied - snmp and netstat
0
0
BZ#1600276 SELinux is preventing upowerd from 'connectto' accesses on the unix_stream_socket /run/usbmuxd.
0
0
BZ#1600713 SELinux is preventing iptables from 'create' accesses on the rawip_socket Unknown.
0
0
BZ#1600718 SELinux is preventing upowerd from read, write, open access on the file /var/lib/upower/history-rate-Sony_Interactive_Entertainment_Wireless_Controller-f4:93:9f:56:03:cb.dat.I1KBMZ.
0
0
BZ#1601148 SELinux is preventing iptables from 'read' accesses on the file modprobe.
0
0
BZ#1601149 SELinux is preventing iptables from 'getattr' accesses on the filesystem /proc.
0
0
BZ#1601367 SELinux is preventing /usr/sbin/xtables-legacy-multi from 'read' accesses on the file xtables.lock.
0
0
BZ#1601493 SELinux is preventing ModemManager from 'read' accesses on the file /var/lib/sss/mc/passwd.
0
0
BZ#1602153 Set fcontext for /var/log/mysql directory
0
0
BZ#1605200 SELinux is preventing (fprintd) from 'mounton' accesses on the fichier /run/systemd/unit-root/proc/kallsyms.
0
1
BZ#1607806 SELinux is preventing /usr/lib/systemd/systemd from 'mounton' accesses on the file /run/systemd/unit-root/proc/kallsyms.
0
0
BZ#1607807 AVC avc: denied { setpcap } for pid=1213 comm="sedispatch" capability=8
0
1
BZ#1608028 SELinux is preventing ebtables from using the 'net_raw' capabilities.
0
1
BZ#1608029 SELinux is preventing ebtables from 'getopt' accesses on the rawip_socket Unknown.
0
1
BZ#1608030 SELinux is preventing ebtables from 'create' accesses on the rawip_socket Unknown.
0
1
BZ#1608031 SELinux is preventing ebtables from 'open' accesses on the file /proc/sys/kernel/modprobe.
0
0
BZ#1608032 SELinux is preventing ebtables from 'read' accesses on the file modprobe.
0
0
BZ#1612967 allow pdns webserver on port 8081
0
0
BZ#1615492 nsd daemon needs access to remove/add socket file /run/nsd/nsd.ctl
0
0
BZ#1619008 SELinux is preventing fcoemon from write access on the directory ctlr_7. For complete SELinux messages run: sealert -l 955f5499-15a9-442d-8b5f-396041aa9571
0
0
BZ#1622509 chronyc cannot write to pipe (socket when executed from ksh)
0
0
BZ#1625218 Fedora Workstation 29 takes a long time to boot in enforcing mode.
-1
2

Automated Test Results