[Bug 1188932] New: SELinux prevents systemd-firstboot
https://bugzilla.suse.com/show_bug.cgi?id=1188932 Bug ID: 1188932 Summary: SELinux prevents systemd-firstboot Classification: openSUSE Product: openSUSE Tumbleweed Version: Current Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: MicroOS Assignee: kubic-bugs@opensuse.org Reporter: kukuk@suse.com QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- With active SELinux systemd-firstboot doesn't work: Fri 2021-07-30 13:54:16 UTC init.scope[1]: Starting First Boot Wizard... Fri 2021-07-30 13:54:16 UTC systemd-firstboot.service[560]: systemd-firstboot.service: Failed to set up standard input: Permission denied Fri 2021-07-30 13:54:16 UTC systemd-firstboot.service[560]: systemd-firstboot.service: Failed at step STDIN spawning systemd-firstboot: Permission denied Fri 2021-07-30 13:54:16 UTC init.scope[1]: systemd-firstboot.service: Main process exited, code=exited, status=208/STDIN Fri 2021-07-30 13:54:16 UTC init.scope[1]: systemd-firstboot.service: Failed with result 'exit-code'. Fri 2021-07-30 13:54:16 UTC init.scope[1]: Failed to start First Boot Wizard. Fri 2021-07-30 13:54:16 UTC kernel: audit: type=1400 audit(1627653256.048:3): avc: denied { watch watch_reads } for pid=560 comm="(irstboot)" path="/dev/console" dev="devtmpfs" ino=12 scontext=system_u:system_r:init_t:s0 tcontext=system_u:object_r:console_device_t:s0 tclass=chr_file permissive=0 -- You are receiving this mail because: You are the assignee for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1188932 https://bugzilla.suse.com/show_bug.cgi?id=1188932#c1 --- Comment #1 from Johannes Segitz <jsegitz@suse.com> --- please give the current policy in security:SELinux a try, those watch permissions are pretty new -- You are receiving this mail because: You are the assignee for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1188932 Gayane Osipyan <gayane.osipyan@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |gayane.osipyan@suse.com -- You are receiving this mail because: You are the assignee for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1188932 https://bugzilla.suse.com/show_bug.cgi?id=1188932#c3 Johannes Segitz <jsegitz@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution|--- |FIXED --- Comment #3 from Johannes Segitz <jsegitz@suse.com> --- I'll close this one. I heard from multiple sources that this is solved with the current policy. Please reopen if this isn't true -- You are receiving this mail because: You are the assignee for the bug.
participants (1)
-
bugzilla_noreply@suse.com