Comments

178 Comments
karma
  • System operates without any conspicuous issues.

  • Successfully passed all custom kernel compilations.

Works good

Transaction check error:

file /usr/lib64/gstreamer-1.0/libgsttwolame.so from install of gstreamer1-plugins-ugly-free-1.12.4-2.fc27.x86_64
conflicts with file from package gstreamer1-plugins-ugly-1.12.4-1.fc27.x86_64

Works as far far back as was assembled :)

karma

Works good

karma
  • System operates without any conspicuous issues.

  • Successfully passed all custom kernel compilations.

Working fine for about 3 days

SELinux is preventing abrt-action-gen from read access on the file libvtkFiltersHybrid-pv5.4.so.1

Source Context                system_u:system_r:abrt_t:s0-s0:c0.c1023
Target Context                unconfined_u:object_r:mnt_t:s0
Target Objects                libvtkFiltersHybrid-pv5.4.so.1 [ file ]
Source                            abrt-action-gen
Policy RPM                      selinux-policy-3.13.1-283.17.fc27.noarch
Selinux Enabled              True
Policy Type                     targeted
Enforcing Mode             Enforcing
Alert Count                      1952
First Seen                     2017-12-08 01:59:11 EET
Last Seen                     2017-12-08 01:59:19 EET
Raw Audit Messages
type=AVC msg=audit(1512691159.49:2601): avc:  denied  { read } for  pid=44648 comm="abrt-action-gen" name="libvtkFiltersHybrid-pv5.4.so.1" dev="sda5" ino=4036077 scontext=system_u:system_r:abrt_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:mnt_t:s0 tclass=file permissive=0

SELinux is preventing abrt-action-gen from read access on the file libvtkFiltersHybrid-pv5.4.so.1

Source Context                system_u:system_r:abrt_t:s0-s0:c0.c1023
Target Context                unconfined_u:object_r:mnt_t:s0
Target Objects                libvtkFiltersHybrid-pv5.4.so.1 [ file ]
Source                            abrt-action-gen
Policy RPM                      selinux-policy-3.13.1-283.17.fc27.noarch
Selinux Enabled              True
Policy Type                     targeted
Enforcing Mode             Enforcing
Alert Count                      1952
First Seen                     2017-12-08 01:59:11 EET
Last Seen                     2017-12-08 01:59:19 EET
Raw Audit Messages
type=AVC msg=audit(1512691159.49:2601): avc:  denied  { read } for  pid=44648 comm="abrt-action-gen" name="libvtkFiltersHybrid-pv5.4.so.1" dev="sda5" ino=4036077 scontext=system_u:system_r:abrt_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:mnt_t:s0 tclass=file permissive=0
karma

Fixed the problem with sealert launching.

A huge thanks! :)

SELinux is preventing setroubleshootd from read access on the file /var/lib/rpm/Packages.

Source Context                system_u:system_r:setroubleshootd_t:s0
Target Context                unconfined_u:object_r:var_lib_t:s0
Target Objects                /var/lib/rpm/Packages [ file ]
Source                        setroubleshootd
Source Path                   setroubleshootd
Target RPM Packages           rpm-4.14.0-2.fc27.x86_64
Policy RPM                    selinux-policy-3.13.1-283.17.fc27.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Platform                      Linux  4.14.2 #1 SMP Fri
                              Nov 24 16:50:57 EET 2017 x86_64 x86_64
Alert Count                   12
First Seen                    2017-10-21 20:07:47 EEST
Last Seen                     2017-11-17 08:29:09 EET

SELinux is preventing setroubleshootd from 'read, write' accesses on the file /var/lib/rpm/.dbenv.lock

Source Context                system_u:system_r:setroubleshootd_t:s0
Target Context                unconfined_u:object_r:var_lib_t:s0
Target Objects                /var/lib/rpm/.dbenv.lock [ file ]
Source                        setroubleshootd
Source Path                   setroubleshootd
Policy RPM                    selinux-policy-3.13.1-283.17.fc27.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Platform                      Linux  4.14.2 #1 SMP Fri
                              Nov 24 16:50:57 EET 2017 x86_64 x86_64
Alert Count                   9
First Seen                    2017-11-13 20:30:40 EET
Last Seen                     2017-11-17 08:29:09 EET

SELinux is preventing mandb from search access on the directory /var/lib/sss

Source Context                system_u:system_r:mandb_t:s0
Target Context                system_u:object_r:sssd_var_lib_t:s0
Target Objects                /var/lib/sss [ dir ]
Source Path                   mandb
Target RPM Packages           sssd-common-1.16.0-4.fc27.x86_64
Policy RPM                    selinux-policy-3.13.1-283.17.fc27.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Platform                      Linux  4.14.2 #1 SMP Fri
                              Nov 24 16:50:57 EET 2017 x86_64 x86_64
Alert Count                   66
First Seen                    2017-11-17 03:13:37 EET
Last Seen                     2017-11-22 07:41:30 EET

@plautrba

O.K. I'll try to do it, as soon as I figure how to get more debug info from sealert -b launching than I've just 'filed' here.

setroubleshoot start problems:

setroubleshoot: org.freedesktop.DBus.Error.AccessDenied: Request to own name refused by policy

/usr/bin/sealert: could not start dbus: org.freedesktop.DBus.Error.NoReply: Did not receive a reply.

Nov 23 12:16:46  dbus-broker-launch[1116]: Activation request for 'org.fedoraproject.Setroubleshootd'
Nov 23 12:16:46  systemd[1082]: Created slice dbus\x2dorg.fedoraproject.Setroubleshootd.slice.
Nov 23 12:16:46  systemd[1082]: Started dbus-org.fedoraproject.Setroubleshootd@0.service.
Nov 23 12:16:46  systemd[1]: systemd-journald.service: Got notification message from PID 416 (FDSTORE=1)
Nov 23 12:16:46  systemd[1]: systemd-journald.service: Added fd 18 (n/a) to fd store.
Nov 23 12:16:48  dbus-broker-launch[678]: Activation request for 'org.fedoraproject.Setroubleshootd'
Nov 23 12:16:48  audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=dbus-org.fedoraproject.Setroubleshootd@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
 Nov 23 12:16:48  systemd[1]: SELinux access check scon=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 tcon=system_u:system_r:init_t:s0 tclass=system perm=start path=(null) cmdline=/usr/bin/dbus-broker-launch -v --scope system --listen inherit: 0
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Failed to load configuration: No such file or directory
Nov 23 12:16:48  systemd[1]: SELinux access check scon=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 tcon=system_u:object_r:init_var_run_t:s0 tclass=service perm=start path=/run/systemd/transient/dbus-org.fedoraproject.Setroubleshootd@0.service cmdline=/usr/bin/dbus-broker-launch -v --scope system --listen inherit: 0
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Trying to enqueue job dbus-org.fedoraproject.Setroubleshootd@0.service/start/fail
Nov 23 12:16:48  systemd[1]: system-dbus\x2dorg.fedoraproject.Setroubleshootd.slice: Installed new job system-dbus\x2dorg.fedoraproject.Setroubleshootd.slice/start as 7328
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Installed new job dbus-org.fedoraproject.Setroubleshootd@0.service/start as 7192
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Enqueued job dbus-org.fedoraproject.Setroubleshootd@0.service/start as 7192
Nov 23 12:16:48  systemd[1]: system-dbus\x2dorg.fedoraproject.Setroubleshootd.slice changed dead -> active
Nov 23 12:16:48  systemd[1]: system-dbus\x2dorg.fedoraproject.Setroubleshootd.slice: Job system-dbus\x2dorg.fedoraproject.Setroubleshootd.slice/start finished, result=done
Nov 23 12:16:48  systemd[1]: Created slice system-dbus\x2dorg.fedoraproject.Setroubleshootd.slice.
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Passing 0 fds to service
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: About to execute: /usr/sbin/setroubleshootd -f
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Forked /usr/sbin/setroubleshootd as 63988
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Changed dead -> running
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Job dbus-org.fedoraproject.Setroubleshootd@0.service/start finished, result=done
Nov 23 12:16:48  systemd[1]: Started dbus-org.fedoraproject.Setroubleshootd@0.service.
Nov 23 12:16:48  systemd[63988]: dbus-org.fedoraproject.Setroubleshootd@0.service: Executing: /usr/sbin/setroubleshootd -f
Nov 23 12:16:48  systemd[1]: systemd-journald.service: Got notification message from PID 416 (FDSTORE=1)
Nov 23 12:16:48  systemd[1]: systemd-journald.service: Added fd 19 (n/a) to fd store.
Nov 23 12:16:49  setroubleshootd[63988]: org.freedesktop.DBus.Error.AccessDenied: Request to own name refused by policy
Nov 23 12:16:49  systemd[1]: systemd-journald.service: Received EPOLLHUP on stored fd 19 (stored), closing.
Nov 23 12:16:49  audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=dbus-org.fedoraproject.Setroubleshootd@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Nov 23 12:16:49  systemd[1]: Received SIGCHLD from PID 63988 (setroubleshootd).
Nov 23 12:16:49  systemd[1]: Child 63988 (setroubleshootd) died (code=exited, status=1/FAILURE)
Nov 23 12:16:49  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Child 63988 belongs to dbus-org.fedoraproject.Setroubleshootd@0.service
Nov 23 12:16:49  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Main process exited, code=exited, status=1/FAILURE
Nov 23 12:16:49  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Changed running -> dead
Nov 23 12:16:49  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Collecting.
Nov 23 12:17:13  sealert[63984]: Exception ignored in: <bound method="" SETroubleshootdDBus.__del__="" of="" <__main__.SETroubleshootdDBus="" object="" at="" 0x7f30dd152318="" (__main__+SETroubleshootdDBus="" at="" 0x564e9b0c02a0)="">>
Nov 23 12:17:13  sealert[63984]: Traceback (most recent call last):
Nov 23 12:17:13  sealert[63984]:   File "/usr/bin/sealert", line 266, in __del__
Nov 23 12:17:13  sealert[63984]:     s = self.iface.finish()
Nov 23 12:17:13  sealert[63984]: AttributeError: 'SETroubleshootdDBus' object has no attribute 'iface'

Does not mend a problem with setroubleshhoot service failures in starting:

Nov 23 12:16:46  dbus-broker-launch[1116]: Activation request for 'org.fedoraproject.Setroubleshootd'
Nov 23 12:16:46  systemd[1082]: Created slice dbus\x2dorg.fedoraproject.Setroubleshootd.slice.
Nov 23 12:16:46  systemd[1082]: Started dbus-org.fedoraproject.Setroubleshootd@0.service.
Nov 23 12:16:46  systemd[1]: systemd-journald.service: Got notification message from PID 416 (FDSTORE=1)
Nov 23 12:16:46  systemd[1]: systemd-journald.service: Added fd 18 (n/a) to fd store.
Nov 23 12:16:48  dbus-broker-launch[678]: Activation request for 'org.fedoraproject.Setroubleshootd'
Nov 23 12:16:48  audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=dbus-org.fedoraproject.Setroubleshootd@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Nov 23 12:16:48  systemd[1]: SELinux access check scon=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 tcon=system_u:system_r:init_t:s0 tclass=system perm=start path=(null) cmdline=/usr/bin/dbus-broker-launch -v --scope system --listen inherit: 0
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Failed to load configuration: No such file or directory
Nov 23 12:16:48  systemd[1]: SELinux access check scon=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 tcon=system_u:object_r:init_var_run_t:s0 tclass=service perm=start path=/run/systemd/transient/dbus-org.fedoraproject.Setroubleshootd@0.service cmdline=/usr/bin/dbus-broker-launch -v --scope system --listen inherit: 0
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Trying to enqueue job dbus-org.fedoraproject.Setroubleshootd@0.service/start/fail
Nov 23 12:16:48  systemd[1]: system-dbus\x2dorg.fedoraproject.Setroubleshootd.slice: Installed new job system-dbus\x2dorg.fedoraproject.Setroubleshootd.slice/start as 7328
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Installed new job dbus-org.fedoraproject.Setroubleshootd@0.service/start as 7192
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Enqueued job dbus-org.fedoraproject.Setroubleshootd@0.service/start as 7192
Nov 23 12:16:48  systemd[1]: system-dbus\x2dorg.fedoraproject.Setroubleshootd.slice changed dead -> active
Nov 23 12:16:48  systemd[1]: system-dbus\x2dorg.fedoraproject.Setroubleshootd.slice: Job system-dbus\x2dorg.fedoraproject.Setroubleshootd.slice/start finished, result=done
Nov 23 12:16:48  systemd[1]: Created slice system-dbus\x2dorg.fedoraproject.Setroubleshootd.slice.
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Passing 0 fds to service
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: About to execute: /usr/sbin/setroubleshootd -f
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Forked /usr/sbin/setroubleshootd as 63988
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Changed dead -> running
Nov 23 12:16:48  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Job dbus-org.fedoraproject.Setroubleshootd@0.service/start finished, result=done
Nov 23 12:16:48  systemd[1]: Started dbus-org.fedoraproject.Setroubleshootd@0.service.
Nov 23 12:16:48  systemd[63988]: dbus-org.fedoraproject.Setroubleshootd@0.service: Executing: /usr/sbin/setroubleshootd -f
Nov 23 12:16:48  systemd[1]: systemd-journald.service: Got notification message from PID 416 (FDSTORE=1)
Nov 23 12:16:48  systemd[1]: systemd-journald.service: Added fd 19 (n/a) to fd store.
Nov 23 12:16:49  setroubleshootd[63988]: org.freedesktop.DBus.Error.AccessDenied: Request to own name refused by policy
Nov 23 12:16:49  systemd[1]: systemd-journald.service: Received EPOLLHUP on stored fd 19 (stored), closing.
Nov 23 12:16:49  audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=dbus-org.fedoraproject.Setroubleshootd@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Nov 23 12:16:49  systemd[1]: Received SIGCHLD from PID 63988 (setroubleshootd).
Nov 23 12:16:49  systemd[1]: Child 63988 (setroubleshootd) died (code=exited, status=1/FAILURE)
Nov 23 12:16:49  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Child 63988 belongs to dbus-org.fedoraproject.Setroubleshootd@0.service
Nov 23 12:16:49  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Main process exited, code=exited, status=1/FAILURE
Nov 23 12:16:49  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Changed running -> dead
Nov 23 12:16:49  systemd[1]: dbus-org.fedoraproject.Setroubleshootd@0.service: Collecting.
Nov 23 12:17:13  sealert[63984]: Exception ignored in: <bound method SETroubleshootdDBus.__del__ of <__main__.SETroubleshootdDBus object at 0x7f30dd152318 (__main__+SETroubleshootdDBus at 0x564e9b0c02a0)>>
Nov 23 12:17:13  sealert[63984]: Traceback (most recent call last):
Nov 23 12:17:13  sealert[63984]:   File "/usr/bin/sealert", line 266, in __del__
Nov 23 12:17:13  sealert[63984]:     s = self.iface.finish()
Nov 23 12:17:13  sealert[63984]: AttributeError: 'SETroubleshootdDBus' object has no attribute 'iface'

Problem:

package gns3-server-2.1.0-1.fc27.noarch requires python3-aiohttp < 2.3.0,
but none of the providers can be installed
  - cannot install both python3-aiohttp-2.3.0-1.fc27.x86_64 and python3-aiohttp-2.2.5-1.fc27.x86_64
  - cannot install both python3-aiohttp-2.2.5-1.fc27.x86_64 and python3-aiohttp-2.3.0-1.fc27.x86_64
  - cannot install the best update candidate for package python3-aiohttp-2.2.5-1.fc27.x86_64
  - cannot install the best update candidate for package gns3-server-2.1.0-1.fc27.noarch

Works good!

Feels better than 5.10

No regressions noticed

Still has no default label for /dev/mqueue

Nov 17 07:25:39  sealert[4032]: Exception ignored in: <bound method SETroubleshootdDBus.__del__ of <__main__.SETroubleshootdDBus object at 0x7f645f440990 (__main__+SETroubleshootdDBus at 0x5628e90562a0)>>
Nov 17 07:25:39  sealert[4032]: Traceback (most recent call last):
Nov 17 07:25:39  sealert[4032]:   File "/usr/bin/sealert", line 266, in __del__
Nov 17 07:25:39  sealert[4032]:     s = self.iface.finish()
Nov 17 07:25:39  sealert[4032]: AttributeError: 'SETroubleshootdDBus' object has no attribute 'iface'

setroubleshoot does not work when dbus-broker enabled in the system:

Nov 17 07:25:15  setroubleshoot: failed to get filesystem list from rpm
Nov 17 07:25:15  setroubleshoot: org.freedesktop.DBus.Error.AccessDenied: Request to own name refused by policy
Nov 17 07:25:18  sedispatch: AVC Message for setroubleshoot, dropping message
Nov 17 07:25:18  sedispatch: AVC Message for setroubleshoot, dropping message
Nov 17 07:25:39  /usr/bin/sealert: could not start dbus: org.freedesktop.DBus.Error.NoReply:
    Did not receive a reply. Possible causes include: the remote application did not send a reply,
    the message bus security policy blocked the reply, the reply timeout expired,
    or the network connection was broken.