stable

selinux-policy-35.7-1.fc35

FEDORA-2021-379f72b2bc created by zpytela 2 years ago for Fedora 35

New F35 selinux-policy build

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2021-379f72b2bc

This update has been submitted for testing by zpytela.

2 years ago

This update's test gating status has been changed to 'waiting'.

2 years ago

This update's test gating status has been changed to 'passed'.

2 years ago

This update has been pushed to testing.

2 years ago
User Icon besser82 commented & provided feedback 2 years ago
karma

Works great! LGTM! =)

User Icon bojan provided feedback 2 years ago
karma

This update can be pushed to stable now if the maintainer wishes

2 years ago
User Icon rocketraman commented & provided feedback 2 years ago
karma

Does not fix 1896648

Bodhi is disabling automatic push to stable due to negative karma. The maintainer may push manually if they determine that the issue is not severe.

2 years ago
BZ#1896648 SELinux is preventing gdb from 'read' accesses on the chr_file renderD128.

no issues

karma
User Icon zpytela commented & provided feedback 2 years ago

@rocketraman please file a new bz and include denials or reproducing steps negative karma is useful to point to a regression which does not seem to be this case

karma
BZ#1896648 SELinux is preventing gdb from 'read' accesses on the chr_file renderD128.
User Icon rocketraman commented & provided feedback 2 years ago
karma

@zpytela thanks, I've reversed my negative karma because you're right -- the policy seems generally functional. However, I've added the denial information to https://bugzilla.redhat.com/show_bug.cgi?id=1896648. Its pretty much exactly the same denial as the OP so I don't think it makes sense to open a new bz issue, at least until 1896648 is closed.

BZ#1896648 SELinux is preventing gdb from 'read' accesses on the chr_file renderD128.
User Icon zpytela commented & provided feedback 2 years ago

@rocketraman, thank you for understanding

I cannot reproduce the problems directly, but it may turn out this boolean needs to be turned on to proceed with further troubleshooting:

abrt_handle_event (off , off) Determine whether ABRT can run in the abrt_handle_event_t domain to handle ABRT event scripts.

setsebool -P abrt_handle_event on

This update has been submitted for stable by zpytela.

2 years ago

This update has been pushed to stable.

2 years ago

Please login to add feedback.

Metadata
Type
bugfix
Severity
medium
Karma
4
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-2
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
2 years ago
in testing
2 years ago
in stable
2 years ago
BZ#1896648 SELinux is preventing gdb from 'read' accesses on the chr_file renderD128.
-1
0
BZ#2025931 smbcontrol fails in SELinux Enforcing mode
0
0

Automated Test Results