stable

selinux-policy-35.7-1.fc35

FEDORA-2021-379f72b2bc created by zpytela a year ago for Fedora 35

New F35 selinux-policy build

How to install

sudo dnf upgrade --refresh --advisory=FEDORA-2021-379f72b2bc

This update has been submitted for testing by zpytela.

a year ago

This update's test gating status has been changed to 'waiting'.

a year ago

This update's test gating status has been changed to 'passed'.

a year ago

This update has been pushed to testing.

a year ago
User Icon besser82 commented & provided feedback a year ago
karma

Works great! LGTM! =)

User Icon bojan provided feedback a year ago
karma

This update can be pushed to stable now if the maintainer wishes

a year ago
User Icon rocketraman commented & provided feedback a year ago
karma

Does not fix 1896648

Bodhi is disabling automatic push to stable due to negative karma. The maintainer may push manually if they determine that the issue is not severe.

a year ago
User Icon rocketraman provided feedback a year ago
BZ#1896648 SELinux is preventing gdb from 'read' accesses on the chr_file renderD128.

no issues

karma
User Icon zpytela commented & provided feedback a year ago

@rocketraman please file a new bz and include denials or reproducing steps negative karma is useful to point to a regression which does not seem to be this case

User Icon rocketraman provided feedback a year ago
karma
BZ#1896648 SELinux is preventing gdb from 'read' accesses on the chr_file renderD128.
User Icon rocketraman commented & provided feedback a year ago
karma

@zpytela thanks, I've reversed my negative karma because you're right -- the policy seems generally functional. However, I've added the denial information to https://bugzilla.redhat.com/show_bug.cgi?id=1896648. Its pretty much exactly the same denial as the OP so I don't think it makes sense to open a new bz issue, at least until 1896648 is closed.

BZ#1896648 SELinux is preventing gdb from 'read' accesses on the chr_file renderD128.
User Icon zpytela commented & provided feedback a year ago

@rocketraman, thank you for understanding

I cannot reproduce the problems directly, but it may turn out this boolean needs to be turned on to proceed with further troubleshooting:

abrt_handle_event (off , off) Determine whether ABRT can run in the abrt_handle_event_t domain to handle ABRT event scripts.

setsebool -P abrt_handle_event on

This update has been submitted for stable by zpytela.

a year ago

This update has been pushed to stable.

a year ago

Please login to add feedback.

Metadata
Type
bugfix
Severity
medium
Karma
4
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-2
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
a year ago
in testing
a year ago
in stable
a year ago
BZ#1896648 SELinux is preventing gdb from 'read' accesses on the chr_file renderD128.
-1
0
BZ#2025931 smbcontrol fails in SELinux Enforcing mode
0
0

Automated Test Results