This was investigated using selinux-policy-41.14-1.fc41 in the branched stream tracking Fedora 41.
The following AVC denials are observed in several kola ISO tests. The denials are blocking CoreOS Installer from creating directories under /etc as well as it's ability to interact with udevadm.
This was investigated using
selinux-policy-41.14-1.fc41
in thebranched
stream tracking Fedora 41.The following AVC denials are observed in several kola ISO tests. The denials are blocking CoreOS Installer from creating directories under
/etc
as well as it's ability to interact withudevadm
.Test Failures
These denials cause the following kola ISO tests to all fail with the exact same AVC denials:
Log Files
Here's a full journal.txt and console.txt from two of these tests. pxe-online-install.bios.console.txt pxe-online-install.bios.journal.txt
iso-offline-install.bios.console.txt iso-offline-install.bios.journal.txt
Also, for completeness, here's a journal.txt file from a test with the
enforcing=0
karg used: iso-offline-install.bios.enforcing-0.journal.txtAdditional Note
Other packages had to be pinned in the
branched
/rawhide
stream to get around another failure withsystemd-256
.systemd-255.5-1.fc41
lvm2-2.03.23-1.fc40
BugZilla Issue with selinux-policy