stable

selinux-policy-41.26-1.fc41

FEDORA-2024-ee068c46d3 created by zpytela 8 months ago for Fedora 41

New F41 selinux-policy build

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2024-ee068c46d3

This update has been submitted for testing by zpytela.

8 months ago

This update's test gating status has been changed to 'waiting'.

8 months ago

This update's test gating status has been changed to 'waiting'.

8 months ago

This update's test gating status has been changed to 'passed'.

8 months ago

This update has been pushed to testing.

8 months ago
User Icon chenxiaolong commented & provided feedback 8 months ago
karma

Confirmed that this fixes #2322522. /dev/nvidia-modeset is now labeled with xserver_misc_device_t.

BZ#2322522 Policy prevents kwin_wayland from accessing /dev/nvidia-modeset
User Icon bojan commented & provided feedback 8 months ago
karma

Works.

This update can be pushed to stable now if the maintainer wishes

8 months ago
User Icon stephent98 commented & provided feedback 8 months ago
karma

Also fixes Bug 2326834.

BZ#2316474 SELinux is preventing pool-libvirt-db from 'connectto' accesses on the unix_stream_socket /run/libvirt/libvirt-sock.
User Icon imabug provided feedback 8 months ago
karma
User Icon py0xc3 commented & provided feedback 8 months ago

With regards to my elaborations in BZ#2316474, I can verify that the denial ... comm=pool-libvirt-db path=/run/libvirt/libvirt-sock ... has disappeared and the issue that occurred on my machine at the very moment of that denial has disappeared as well, although my primary issue (confinement of cockpit-used user accounts is currently not possible) remains. For me, the disappearing of the pool-libvirt-db issue only mitigates the issue of the need to reboot after any confinement.

I assume the issue of the user(s) who created BZ#2316474 is solved, but since I have a different environment (I never had the issue without confinement involved), I avoid to mark the bug as solved here.

Beyond the known issue, the policies seem to work fine.

User Icon gfieni provided feedback 8 months ago
karma

This update has been submitted for stable by bodhi.

8 months ago

This update has been pushed to stable.

8 months ago

Please log in to add feedback.

Metadata
Type
bugfix
Severity
medium
Karma
5
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-2
Stable by Karma
5
Stable by Time
14 days
Dates
submitted
8 months ago
in testing
8 months ago
in stable
8 months ago
approved
8 months ago
BZ#2316474 SELinux is preventing pool-libvirt-db from 'connectto' accesses on the unix_stream_socket /run/libvirt/libvirt-sock.
0
1
BZ#2320395 Missing rules for bootupd 0.2.23+
0
0
BZ#2322522 Policy prevents kwin_wayland from accessing /dev/nvidia-modeset
0
1

Automated Test Results