[Bug 1095151] New: [doc] [SELinux] SELinux Policy files missing in Leap 15
http://bugzilla.opensuse.org/show_bug.cgi?id=1095151 Bug ID: 1095151 Summary: [doc] [SELinux] SELinux Policy files missing in Leap 15 Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.0 Hardware: x86-64 OS: SUSE Other Status: NEW Severity: Major Priority: P5 - None Component: Security Assignee: fs@suse.com Reporter: felix.lange96@gmx.de QA Contact: qa-bugs@suse.de Found By: --- Blocker: Yes Package "selinux-policy" and "selinux-policy-minimum", mentioned in the docs in 31.4 of https://doc.opensuse.org/documentation/leap/security/html/book.security/cha.... are missing in Leap 15. Issue is the same as in Bug #1017272 and #1052493, but for a new release of OpenSuse. Expected behavior: After running step 31.3 of doc mentioned above the package selinux-policy and selinux-policy-minimum are installed. After adopting grub2 config and reboot the commands "seinfo" and "sestatus" should deliver insights on the policy installed and list selinux as running in permissive mode. Actual behavior: The packages mentioning (potentially alongside with others!) are missing. SELinux therefore returns no policy data when running "seinfo" and returns the status "disabled" when running "sestatus", as it cant start without a policy. Differences from former Bugs: - New Leap Version - No issues at boot, in contrast to Bug #1017272 Requested mitigation: Please add the necessary files to the Leap15 Repo. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1095151 http://bugzilla.opensuse.org/show_bug.cgi?id=1095151#c1 Andreas Stieger <astieger@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |astieger@suse.com, | |jsegitz@suse.com --- Comment #1 from Andreas Stieger <astieger@suse.com> --- Johannes, these were removed intentionally I believe? -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1095151 http://bugzilla.opensuse.org/show_bug.cgi?id=1095151#c2 --- Comment #2 from Johannes Segitz <jsegitz@suse.com> --- (In reply to Andreas Stieger from comment #1) yes, they were removed intentionally. The policy didn't work in enforcing mode, so there was no real use in shipping it. I would remove the whole section, but if you like I can help you rewrite it in a way that describes how to get the refpolicy https://github.com/TresysTechnology/refpolicy/wiki installed -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com