PDA

View Full Version : SELinux and I are no longer friends!


Dan
6th April 2011, 03:55 PM
Up until now, we've gotten along reasonably well, but that all changed when I tried to add my printer this morning. I guess it woke up cranky. I suspected it might get ugly about a few things I was going to try today, so I appended enforcing=0 to the kernel boot line in Grub, and it booted just hunky-dorey. Until I plugged in the printer. Then it got just as ugly as I thought it would ... if it were allowed to be. The theory being, that boot appendage should have muzzled it.

It didn't. <..:dis:..>

And ... of course ... there's no SE dialog/tweak tool included in F15 at the moment.

So ... if it won't be tamed ... and it won't be polite ... how do I shoot this little beasty behind the left ear? <..http://www.zyloo-enterprises.com/graphics/smileys/really-disgusted-fedora.gif..>

bob
6th April 2011, 04:03 PM
Bugzilla, oh Bugzilla, my friend! And, be sure you print out the details for later review....oh wait.... :p

PabloTwo
6th April 2011, 04:09 PM

Hii Dan,

Are you saying that there is no getenforce or, more importantly, setenforce command(s) in F15?

Normally, at the command prompt, "# setenforce permissive" or "# setenforce 0" will put SELinux into permissive mode.

Dan
6th April 2011, 04:16 PM
Oh, they seem to be there ... and report as permissive. Then it promptly slaps down a number of functions. PulseAudio among them ... which I kind of viewed with a secret little smile, but it also still persists in killing my printer.

soundfreely
6th April 2011, 04:48 PM
I had a similar issue. In my case, I had also disabled SElinux in the kernel line of grub. Then installed some updates and got the latest SELinux policies (just via yum update). However, I believe the policies aren't applied when SELinux is disabled - so, "fixfiles onboot" needs to be run.

Dan
6th April 2011, 05:04 PM
Oh, my! This is sooooo broken ... again. Just rebooted and got this ... again.

http://forums.fedoraforum.org/picture.php?albumid=218&pictureid=891

I'm feeling an extensive release date slip coming on. <..:p..>

Dan
6th April 2011, 05:58 PM
Okey Jokey. By way of much puzzling and a relabel -- and enforcing=0 (and jerking the USB printer connection out before/while the system boots), we're back into GUI.

And the printer is installed, for the most part. It printed a test page anyway. My question now is ... why the devil do I have to resort to a terminal to open the hp-toolbox?

GoinEasy9
6th April 2011, 07:17 PM
I had to do a relabel before my problems went away. I'm back to enforcing without problems.

mariuszs
6th April 2011, 08:09 PM
After weekend update I cant boot FC15 :(

http://twitpic.com/4hol1t

Failed to load selinux policy....

I have selinux disabled :(

CronoCloud
7th April 2011, 01:40 AM
Okey Jokey. By way of much puzzling and a relabel -- and enforcing=0 (and jerking the USB printer connection out before/while the system boots), we're back into GUI.

SELinux is teh devil, and as a desktop user...I have it disabled.

My question now is ... why the devil do I have to resort to a terminal to open the hp-toolbox?

You shouldn't, check for the F15 equivalent to:

System>Administration>HP Device Manager

Ron Rogers Jr. (CronoCloud)

DBelton
7th April 2011, 01:52 AM
well Dan, I too am having selinux troubles with pulseaudio. so don't feel too special :D

I am ghetting ready to reboot anyway, so will try a complete relabel then and see what happens.

Dan
7th April 2011, 01:55 AM
... check for the F15 equivalent to: System>Administration>HP Device Manager

Hmmmm.

Yeah. That sounds like a helluva good idea. I'll do that. But ... the challenge is the menu. Finding it that is. Gnome 3 (Gnome shell) is sorta lean on menus.


... I am getting ready to reboot anyway, so will try a complete relabel then and see what happens. That's what I did. Seemed to work, too. Just don't leave your USB HP 7000 series printer plugged in when you re-boot. It gets a little ugly if you do. <..:p..>

DBelton
7th April 2011, 02:34 AM
didn't work for me, though :(

I did a complete relabel, and I still get selinux errors on pulseaudio on boot..


Apr 6 20:28:02 tower11 setroubleshoot: SELinux is preventing /usr/bin/pulseaudio from open access on the file c189:128. For complete SELinux messages. run sealert -l 8dfc375c-f180-4ef1-a029-70922471eea9
Apr 6 20:28:02 tower11 setroubleshoot: SELinux is preventing /usr/bin/pulseaudio from open access on the file +sound:card0. For complete SELinux messages. run sealert -l 8dfc375c-f180-4ef1-a029-70922471eea9

CronoCloud
7th April 2011, 02:38 AM
Yeah. That sounds like a helluva good idea. I'll do that. But ... the challenge is the menu. Finding it that is. Gnome 3 (Gnome shell) is sorta lean on menus.

It's that BAD? I hadn't been following the ruckus over gnome shell/gnome 3 closely so I didn't know. So no Applications, Places, and System menu's on a nice panel/taskbar? What were they thinking?

Ron Rogers Jr. (CronoCloud)

DBelton
7th April 2011, 02:48 AM
no application, places and system menu's at all in gnome 3. Makes it really hard to find anything.

And when you get to gnome 3 shell.. you will forget what a panel and taskbar is as well. They are gone.

You do however gain a screen full of super huge icons instead of your applications menu


They must think that all users need to wear coke bottle thick glasses and still can't see anything. :D

I tried to change the size of the icons in the css file, but I ended up with small icons that had the large image in them, just cut off. not scaled.

Dan
7th April 2011, 03:02 AM
It's that BAD? I hadn't been following the ruckus over gnome shell/gnome 3 closely so I didn't know. So no Applications, Places, and System menu's on a nice panel/taskbar? What were they thinking?

Ron Rogers Jr. (CronoCloud)

Uhm ... Yeah. Check below for the photos.

Now ... the Beta has improved a helluva bunch .. but ... it has a long way to go, and the basic structure remains the same.

Dan
7th April 2011, 07:14 AM
Okey dokey.

Screenshots!

Figure 1. The basic desktop.
http://forums.fedoraforum.org/picture.php?albumid=218&pictureid=897

Figure 2. The "Overlay" activated, showing the "favorites" on the left, and the workspace switcher on the right.
http://forums.fedoraforum.org/picture.php?albumid=218&pictureid=898

Figure 3. The Applications selector. Yeah, they're that big. (Icons by Playskool.)
http://forums.fedoraforum.org/picture.php?albumid=218&pictureid=899

Figure 4. File Manager Preferences. Only accessible via the file browser.
http://forums.fedoraforum.org/picture.php?albumid=218&pictureid=900

Figure 5. The overlay and workspace/application switcher active.
http://forums.fedoraforum.org/picture.php?albumid=218&pictureid=901

Figure 6. The file manager window.
http://forums.fedoraforum.org/picture.php?albumid=218&pictureid=902

Figure 7. The default settings selector. That's all there is, and all you get by default.
http://forums.fedoraforum.org/picture.php?albumid=218&pictureid=903


And there it is. Warts and all. Again.

RahulSundaram
7th April 2011, 08:46 AM
Hi

There is a SELinux troubleshooter and it should help you diagnose, workaround and even report bugs

The PulseAudio issue is already reported in bugzilla

https://bugzilla.redhat.com/show_bug.cgi?id=693247

DBelton
7th April 2011, 03:48 PM
Thanks Rahul.

I followed your link in another thread to the release blocker list and noticed the PulseAudio issue was shown on it as well. I feel somewhat better knowing I'm not the only one with a bug this time :D

However, there is one I am thinking about filing. It's not really a bug per se, but it's been driving me nuts every time it happens.

systemd-fsck doesn't show any kind of progress indicator if it checks a filesystem on boot. You realize how long you are sitting there looking at blank screen thinking your system hung if you try checking a 12TB filesystem? You have to look back up in the messages (if you have them show up and didn't "quiet" them down) to even know it's checking a filesystem. Sometimes that message can be over half a screen up.

Without some sort of progress indicator, there will be people that think their system hung and try a reboot right in the middle of a filesystem check.

RahulSundaram
7th April 2011, 04:11 PM
Hi

If you see the bug report, I have nominated it as a blocker and anyone with a bugzilla account can do as well following the process outlined in the blocker bugs list.

File a bug report against systemd and see what the developer says about that issue.

Dangermouse
7th April 2011, 04:43 PM
Nice shots Dan:D

Unfortunately f15 has proven too much for me, much prefer the f14 version :p

mariuszs
7th April 2011, 08:17 PM
Hi

If you see the bug report, I have nominated it as a blocker and anyone with a bugzilla account can do as well following the process outlined in the blocker bugs list.

File a bug report against systemd and see what the developer says about that issue.

I filled my bug https://bugzilla.redhat.com/show_bug.cgi?id=694620
Probably this is not blocker for beta, but I really need help with repairing this.

SlowJet
7th April 2011, 10:11 PM
One or two selinux errors on a developmet version is hardly worth the devils attension or brand.

Gnome3 is so simple to use a Geco's Agent's readhead stepchild could master it in 5 minutes.

:

SJ

DBelton
7th April 2011, 11:08 PM
I filled my bug https://bugzilla.redhat.com/show_bug.cgi?id=694620
Probably this is not blocker for beta, but I really need help with repairing this.

Have you tried getting the latest updates and then doing a full relabel to make sure that all of your files have the correct selinux context?

the best way to do a complete system relabel is to open a a terminal window then sign in as root (Edited after Dan tried to kill his cat by singing LOL)


su -
(root password)

touch /.autorelabel


doing it this way will run a relabel on your next boot to make sure your selinux contexts are correct.

It looks like the selinux problems that prevented a boot were fixed in updates on the 4th (I believe)

---------- Post added at 05:08 PM ---------- Previous post was at 05:07 PM ----------

One or two selinux errors on a developmet version is hardly worth the devils attension or brand.

Gnome3 is so simple to use a Geco's Agent's readhead stepchild could master it in 5 minutes.

:

SJ

Gnome 3 is simple to use.. but try changing anything in it. :D

Dan
7th April 2011, 11:09 PM
Have you tried getting the latest updates and then doing a full relabel to make sure that all of your files have the correct selinux context?

the best way to do a complete system relabel is to open a a terminal window then sing in as root


su -
(root password)

touch /.autorelabel


doing it this way will run a relabel on your next boot to make sure your selinux contexts are correct.

It looks like the selinux problems that prevented a boot were fixed in updates on the 4th (I believe) Wow. That didn't do much for me here. The cat ran and hid, though. <..:p..>

DBelton
7th April 2011, 11:25 PM
blah blah.. yea, I have fat fingers :p