FEDORA-2021-3a592334ef created by zpytela 8 months ago for Fedora 34
stable

New F34 selinux-policy build

How to install

sudo dnf upgrade --advisory=FEDORA-2021-3a592334ef

This update has been submitted for testing by zpytela.

8 months ago

This update's test gating status has been changed to 'failed'.

8 months ago

This update's test gating status has been changed to 'waiting'.

8 months ago

This update's test gating status has been changed to 'failed'.

8 months ago
User Icon imabug provided feedback 8 months ago
karma

This update's test gating status has been changed to 'passed'.

8 months ago

This update has been pushed to testing.

8 months ago
User Icon bojan provided feedback 8 months ago
karma

This update can be pushed to stable now if the maintainer wishes

8 months ago
karma

This update has been submitted for stable by bodhi.

8 months ago
User Icon ersen provided feedback 8 months ago
karma
User Icon andilinux commented & provided feedback 8 months ago
karma

no issues

User Icon andilinux commented & provided feedback 8 months ago
karma

works

User Icon clnetbox commented & provided feedback 8 months ago
karma

After applying selinux-policy-34.9-1.fc34, I always receive this sealert when running the command sudo updatedb :

setroubleshoot[7078]: SELinux is preventing updatedb from search access on the directory dma_heap.
If you believe that updatedb should be allowed search access on the dma_heap directory by default.
# ausearch -c 'updatedb' --raw | audit2allow -M my-updatedb
# semodule -X 300 -i my-updatedb.pp

By the way, I'm receiving this sealert message after every system boot since I have installed fedora 34 workstation :

setroubleshoot[2132]: SELinux is preventing gnome-session-c from write access on the sock_file dbus-AG0rCzsVkf.
If you believe that gnome-session-c should be allowed write access on the dbus-AG0rCzsVkf sock_file by default.
# ausearch -c 'gnome-session-c' --raw | audit2allow -M my-gnomesessionc
# semodule -X 300 -i my-gnomesessionc.pp

This update has been pushed to stable.

8 months ago
User Icon zpytela commented & provided feedback 8 months ago

@clnetbox, the first one is because the new type needs directory handling, will be addressed soon https://bugzilla.redhat.com/show_bug.cgi?id=1965743

the second one is probably https://bugzilla.redhat.com/show_bug.cgi?id=1949712 where the fix is not available yet

User Icon clnetbox commented & provided feedback 8 months ago

@zpytela : Thank you for the information, Zdenek !


Please login to add feedback.

Metadata
Type
bugfix
Severity
medium
Karma
6
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
8 months ago
in testing
8 months ago
in stable
8 months ago
BZ#1878348 Selinux prevents saslauthd from verifying kerberos passwords
0
0
BZ#1953060 SELinux is preventing systemd-hostnam from write access on the directory systemd
0
0

Automated Test Results