New upstream release with optimized earching and reporting.
Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:
sudo dnf upgrade --refresh --advisory=FEDORA-2025-1a9b66e130
Please log in to add feedback.
| 0 | 0 | Test Case audit |
This update has been submitted for testing by sgrubb.
This update's test gating status has been changed to 'waiting'.
This update's test gating status has been changed to 'waiting'.
sgrubb edited this update.
This update's test gating status has been changed to 'failed'.
This update has been pushed to testing.
SELinux issues:
I think maybe we fixed this in Rawhide but not F43?
Bodhi is disabling automatic push to stable due to negative karma. The maintainer may push manually if they determine that the issue is not severe.
yeah, F43 is on selinux-policy-42.8-1 . F42 is on 42.9-1, Rawhide is on 42.10-1.
@zpytela @lvrabec PTAL
specifically, 42.9 included "- Allow auditd manage its private run dirs" which is what we need here.
if someone does a 42.10-1 build for f43 we can edit it into this update.
I guess this update is not critical so it can wait to GA but I will create a new selinux-policy build addressing one blocker and fix for this will be included
If this is waiting for GA, I prefer to unpush this update now, and reintroduce it once selinux-policy is ready. We don't want users running with updates-testing enabled to have broken system parts for long. Unless auditd.service is not that important and useful (haha, I have no idea what it is used for - I still see audit messages in journal even without this service running). Thoughts?
This was part of the python mini rebuild. If we wait until GA, there might be problems with the python bindings.
I created the policy build in the meantime https://koji.fedoraproject.org/koji/taskinfo?taskID=137405431, not an update, so you can try to add it here @adamwill
There will be another build+update later this week
@kparal updates-testing are enabled by default and I think it is not a good idea at this phase when updates are frozen
adamwill edited this update.
New build(s):
Karma has been reset.
This update has been submitted for testing by adamwill.
we're not in a freeze currently.
This update's test gating status has been changed to 'waiting'.
This update's test gating status has been changed to 'passed'.
with the new selinux -policy I finally get no more sealerts from my VMs
with the new selinux -policy auditd starts again
thanks
This update has been pushed to testing.
This update can be pushed to stable now if the maintainer wishes
Works
When shutting down a VM the following SELinux warning (directory number varies) appears :
SELinux is preventing systemd-machine from search access on the directory 15069.
Additional Information:
Source Context system_u:system_r:systemd_machined_t:s0
Target Context system_u:system_r:svirt_t:s0:c715,c889
Target Objects 15069 [ dir ]
Source systemd-machine
Source Path systemd-machine
Source RPM Packages
Target RPM Packages
SELinux Policy RPM selinux-policy-targeted-42.9-1.fc43.noarch
Local Policy RPM selinux-policy-targeted-42.9-1.fc43.noarch
Selinux Enabled True
Policy Type targeted
Enforcing Mode Enforcing
Host Name XXXXXXXX
Platform Linux XXXXXXXX 6.17.0-0.rc7.56.fc43.x86_64 #1 SMP
PREEMPT_DYNAMIC Fri Sep 26 10:30:30 UTC 2025 x86_64
When connecting to a remote F43 system via RDP, this warning appears on the remote host :
SELinux is preventing RDP socket thre from read access on the directory /var/lib/sss/pubconf/krb5.include.d.
Additional Information:
Source Context system_u:system_r:gnome_remote_desktop_t:s0
Target Context system_u:object_r:sssd_public_t:s0
Target Objects /var/lib/sss/pubconf/krb5.include.d [ dir ]
Source RDP socket thre
Source Path RDP socket thre
Source RPM Packages
Target RPM Packages sssd-krb5-common-2.11.1-3.fc43.x86_64
SELinux Policy RPM selinux-policy-targeted-42.9-1.fc43.noarch
Local Policy RPM selinux-policy-targeted-42.9-1.fc43.noarch
Selinux Enabled True
Policy Type targeted
Enforcing Mode Enforcing
Host Name XXXXXXXX
Platform Linux XXXXXXXX 6.17.0-0.rc7.56.fc43.x86_64 #1 SMP
PREEMPT_DYNAMIC Mon Sep 22 14:29:30 UTC 2025 x86_64
Works great! LGTM! =)
Works.
adamwill edited this update.
Removed build(s):
Karma has been reset.
This update has been submitted for testing by adamwill.
edited to remove the selinux-policy build as there is a newer one in stable now, at request of @dustymabe . we'll see if that resolves the test failures.
passes coreos tests
This update has been pushed to testing.
%post scriptlet: failed ; https://bugzilla.redhat.com/show_bug.cgi?id=2412472
This update can be pushed to stable now if the maintainer wishes
This update has been submitted for stable by sgrubb.
This update has been pushed to stable.