View Full Version : SELinux and I are no longer friends!
Dan
6th April 2011, 03:55 PM
Up until now, we've gotten along reasonably well, but that all changed when I tried to add my printer this morning. I guess it woke up cranky. I suspected it might get ugly about a few things I was going to try today, so I appended enforcing=0 to the kernel boot line in Grub, and it booted just hunky-dorey. Until I plugged in the printer. Then it got just as ugly as I thought it would ... if it were allowed to be. The theory being, that boot appendage should have muzzled it.
It didn't. <..:dis:..>
And ... of course ... there's no SE dialog/tweak tool included in F15 at the moment.
So ... if it won't be tamed ... and it won't be polite ... how do I shoot this little beasty behind the left ear? <..http://www.zyloo-enterprises.com/graphics/smileys/really-disgusted-fedora.gif..>
bob
6th April 2011, 04:03 PM
Bugzilla, oh Bugzilla, my friend! And, be sure you print out the details for later review....oh wait.... :p
PabloTwo
6th April 2011, 04:09 PM
Hii Dan,
Are you saying that there is no getenforce or, more importantly, setenforce command(s) in F15?
Normally, at the command prompt, "# setenforce permissive" or "# setenforce 0" will put SELinux into permissive mode.
Dan
6th April 2011, 04:16 PM
Oh, they seem to be there ... and report as permissive. Then it promptly slaps down a number of functions. PulseAudio among them ... which I kind of viewed with a secret little smile, but it also still persists in killing my printer.
soundfreely
6th April 2011, 04:48 PM
I had a similar issue. In my case, I had also disabled SElinux in the kernel line of grub. Then installed some updates and got the latest SELinux policies (just via yum update). However, I believe the policies aren't applied when SELinux is disabled - so, "fixfiles onboot" needs to be run.
Dan
6th April 2011, 05:04 PM
Oh, my! This is sooooo broken ... again. Just rebooted and got this ... again.
http://forums.fedoraforum.org/picture.php?albumid=218&pictureid=891
I'm feeling an extensive release date slip coming on. <..:p..>
Dan
6th April 2011, 05:58 PM
Okey Jokey. By way of much puzzling and a relabel -- and enforcing=0 (and jerking the USB printer connection out before/while the system boots), we're back into GUI.
And the printer is installed, for the most part. It printed a test page anyway. My question now is ... why the devil do I have to resort to a terminal to open the hp-toolbox?
GoinEasy9
6th April 2011, 07:17 PM
I had to do a relabel before my problems went away. I'm back to enforcing without problems.
mariuszs
6th April 2011, 08:09 PM
After weekend update I cant boot FC15 :(
http://twitpic.com/4hol1t
Failed to load selinux policy....
I have selinux disabled :(
CronoCloud
7th April 2011, 01:40 AM
Okey Jokey. By way of much puzzling and a relabel -- and enforcing=0 (and jerking the USB printer connection out before/while the system boots), we're back into GUI.
SELinux is teh devil, and as a desktop user...I have it disabled.
My question now is ... why the devil do I have to resort to a terminal to open the hp-toolbox?
You shouldn't, check for the F15 equivalent to:
System>Administration>HP Device Manager
Ron Rogers Jr. (CronoCloud)
DBelton
7th April 2011, 01:52 AM
well Dan, I too am having selinux troubles with pulseaudio. so don't feel too special :D
I am ghetting ready to reboot anyway, so will try a complete relabel then and see what happens.
Dan
7th April 2011, 01:55 AM
... check for the F15 equivalent to: System>Administration>HP Device Manager
Hmmmm.
Yeah. That sounds like a helluva good idea. I'll do that. But ... the challenge is the menu. Finding it that is. Gnome 3 (Gnome shell) is sorta lean on menus.
... I am getting ready to reboot anyway, so will try a complete relabel then and see what happens. That's what I did. Seemed to work, too. Just don't leave your USB HP 7000 series printer plugged in when you re-boot. It gets a little ugly if you do. <..:p..>
DBelton
7th April 2011, 02:34 AM
didn't work for me, though :(
I did a complete relabel, and I still get selinux errors on pulseaudio on boot..
Apr 6 20:28:02 tower11 setroubleshoot: SELinux is preventing /usr/bin/pulseaudio from open access on the file c189:128. For complete SELinux messages. run sealert -l 8dfc375c-f180-4ef1-a029-70922471eea9
Apr 6 20:28:02 tower11 setroubleshoot: SELinux is preventing /usr/bin/pulseaudio from open access on the file +sound:card0. For complete SELinux messages. run sealert -l 8dfc375c-f180-4ef1-a029-70922471eea9
CronoCloud
7th April 2011, 02:38 AM
Yeah. That sounds like a helluva good idea. I'll do that. But ... the challenge is the menu. Finding it that is. Gnome 3 (Gnome shell) is sorta lean on menus.
It's that BAD? I hadn't been following the ruckus over gnome shell/gnome 3 closely so I didn't know. So no Applications, Places, and System menu's on a nice panel/taskbar? What were they thinking?
Ron Rogers Jr. (CronoCloud)
DBelton
7th April 2011, 02:48 AM
no application, places and system menu's at all in gnome 3. Makes it really hard to find anything.
And when you get to gnome 3 shell.. you will forget what a panel and taskbar is as well. They are gone.
You do however gain a screen full of super huge icons instead of your applications menu
They must think that all users need to wear coke bottle thick glasses and still can't see anything. :D
I tried to change the size of the icons in the css file, but I ended up with small icons that had the large image in them, just cut off. not scaled.
Dan
7th April 2011, 03:02 AM
It's that BAD? I hadn't been following the ruckus over gnome shell/gnome 3 closely so I didn't know. So no Applications, Places, and System menu's on a nice panel/taskbar? What were they thinking?
Ron Rogers Jr. (CronoCloud)
Uhm ... Yeah. Check below for the photos.
Now ... the Beta has improved a helluva bunch .. but ... it has a long way to go, and the basic structure remains the same.
Dan
7th April 2011, 07:14 AM
Okey dokey.
Screenshots!
Figure 1. The basic desktop.
http://forums.fedoraforum.org/picture.php?albumid=218&pictureid=897
Figure 2. The "Overlay" activated, showing the "favorites" on the left, and the workspace switcher on the right.
http://forums.fedoraforum.org/picture.php?albumid=218&pictureid=898
Figure 3. The Applications selector. Yeah, they're that big. (Icons by Playskool.)
http://forums.fedoraforum.org/picture.php?albumid=218&pictureid=899
Figure 4. File Manager Preferences. Only accessible via the file browser.
http://forums.fedoraforum.org/picture.php?albumid=218&pictureid=900
Figure 5. The overlay and workspace/application switcher active.
http://forums.fedoraforum.org/picture.php?albumid=218&pictureid=901
Figure 6. The file manager window.
http://forums.fedoraforum.org/picture.php?albumid=218&pictureid=902
Figure 7. The default settings selector. That's all there is, and all you get by default.
http://forums.fedoraforum.org/picture.php?albumid=218&pictureid=903
And there it is. Warts and all. Again.
RahulSundaram
7th April 2011, 08:46 AM
Hi
There is a SELinux troubleshooter and it should help you diagnose, workaround and even report bugs
The PulseAudio issue is already reported in bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=693247
DBelton
7th April 2011, 03:48 PM
Thanks Rahul.
I followed your link in another thread to the release blocker list and noticed the PulseAudio issue was shown on it as well. I feel somewhat better knowing I'm not the only one with a bug this time :D
However, there is one I am thinking about filing. It's not really a bug per se, but it's been driving me nuts every time it happens.
systemd-fsck doesn't show any kind of progress indicator if it checks a filesystem on boot. You realize how long you are sitting there looking at blank screen thinking your system hung if you try checking a 12TB filesystem? You have to look back up in the messages (if you have them show up and didn't "quiet" them down) to even know it's checking a filesystem. Sometimes that message can be over half a screen up.
Without some sort of progress indicator, there will be people that think their system hung and try a reboot right in the middle of a filesystem check.
RahulSundaram
7th April 2011, 04:11 PM
Hi
If you see the bug report, I have nominated it as a blocker and anyone with a bugzilla account can do as well following the process outlined in the blocker bugs list.
File a bug report against systemd and see what the developer says about that issue.
Dangermouse
7th April 2011, 04:43 PM
Nice shots Dan:D
Unfortunately f15 has proven too much for me, much prefer the f14 version :p
mariuszs
7th April 2011, 08:17 PM
Hi
If you see the bug report, I have nominated it as a blocker and anyone with a bugzilla account can do as well following the process outlined in the blocker bugs list.
File a bug report against systemd and see what the developer says about that issue.
I filled my bug https://bugzilla.redhat.com/show_bug.cgi?id=694620
Probably this is not blocker for beta, but I really need help with repairing this.
SlowJet
7th April 2011, 10:11 PM
One or two selinux errors on a developmet version is hardly worth the devils attension or brand.
Gnome3 is so simple to use a Geco's Agent's readhead stepchild could master it in 5 minutes.
:
SJ
DBelton
7th April 2011, 11:08 PM
I filled my bug https://bugzilla.redhat.com/show_bug.cgi?id=694620
Probably this is not blocker for beta, but I really need help with repairing this.
Have you tried getting the latest updates and then doing a full relabel to make sure that all of your files have the correct selinux context?
the best way to do a complete system relabel is to open a a terminal window then sign in as root (Edited after Dan tried to kill his cat by singing LOL)
su -
(root password)
touch /.autorelabel
doing it this way will run a relabel on your next boot to make sure your selinux contexts are correct.
It looks like the selinux problems that prevented a boot were fixed in updates on the 4th (I believe)
---------- Post added at 05:08 PM ---------- Previous post was at 05:07 PM ----------
One or two selinux errors on a developmet version is hardly worth the devils attension or brand.
Gnome3 is so simple to use a Geco's Agent's readhead stepchild could master it in 5 minutes.
:
SJ
Gnome 3 is simple to use.. but try changing anything in it. :D
Dan
7th April 2011, 11:09 PM
Have you tried getting the latest updates and then doing a full relabel to make sure that all of your files have the correct selinux context?
the best way to do a complete system relabel is to open a a terminal window then sing in as root
su -
(root password)
touch /.autorelabel
doing it this way will run a relabel on your next boot to make sure your selinux contexts are correct.
It looks like the selinux problems that prevented a boot were fixed in updates on the 4th (I believe) Wow. That didn't do much for me here. The cat ran and hid, though. <..:p..>
DBelton
7th April 2011, 11:25 PM
blah blah.. yea, I have fat fingers :p
vBulletin® v3.8.7, Copyright ©2000-2013, vBulletin Solutions, Inc.