-
Notifications
You must be signed in to change notification settings - Fork 75
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Libvirt + cockpit-machines got blocked/denied permissions by SELinux #1818
Comments
LOL cursing out the beta version is pretty funny |
Do you still have the logs of the AVC denial? We did have some SELinux policy regressions in F41 but they all seem to be closed and our CI runs with https://bugzilla.redhat.com/show_bug.cgi?id=2297965 @mac2net please be respectful to users filling issues even though they had a frustrating experience. |
I updated Fedora Silverblue 41 with |
@thepragmaticmero which selinux-policy version do you have? |
This version |
Rolledback to Fedora 40 Stable using |
FWIW, there's a new SELinux policy in F41 beta: Changelog after 41.16-2:
It seems to be fixed, possibly from 41.17-1's "Allow virtstoraged execute mount programs in the mount domain". |
There's a new bug report that seems to be tracking this: |
Now that Fedora 41 has been released (out of beta), this same bug it's still happening. The band-aid solution keeps being the same
Weirdly on Fedora Workstation it works just fine........ huh. I'll dive more into it Anyone knows how to restore it? |
FWIW, I've been hitting this again, even though it really seemed fixed in the version I listed above. Is this Atomic-specific somehow? I've been chatting with @martinpitt in matrix and he says Cockpit tests are fine for Cockpit Machines on Fedora 41. (There have been a few issues that are specific to Atomic OSTree distros, like a few with grub, which incidentally should be fixed in F41. Atomic versions of Fedora are pretty close to the non-Atomic ones, but aren't fully 1:1.) |
I'm seeing this on Fedora Workstation 41, so it's apparently not atomic-specific. :/ |
|
At least on Fedora 41 (pre-release) I guess it will be fixed soon, IDK. SELinux works in misterious ways.
I have a saying: "The best way to use SELinux is with the
sudo setenforce 0
command"Now SELinux was doing this:
The fix... well:
sudo setenforce 0
. Bandaid fix for now. It wil get sorted out later I guess. I lost too much time trying to solve this, so no "proper" command to get libvirt to pass through SELinuxThe text was updated successfully, but these errors were encountered: