SELinux policy not updated correctly for RHEL10+ systems

XMLWordPrintable

    • Type: Problem report
    • Resolution: Unresolved
    • Priority: Critical
    • None
    • Affects Version/s: 7.0.22, 7.4.6, 8.0.0alpha1
    • Component/s: Packages (C)
    • Environment:
      Minimal RHEL 10.+
    • Support backlog

      Issues:

      • Provided policy rely on interfaces or macros that are missing from the minimal RHEL 10 SELinux policy
      • Requires own SELinux interfaces
      • if point 1 and 2 cannot be solved at least point in the documentation which dependencies are needed
      Installing the zabbix-selinux-policy on its own will fail and Zabbix SELinux Booleans / types does not exist
      Installing       : zabbix-selinux-policy-7.0.19-release1.el10.x86_64                                               1/1
        Running scriptlet: zabbix-selinux-policy-7.0.19-release1.el10.x86_64                                               1/1
      Failed to resolve typepermissive statement at /var/lib/selinux/targeted/tmp/modules/400/permissive_zabbix_agent_t/cil:1
      Failed to resolve AST
      semodule:  Failed!
      

      This can be solved by installing selinux-policy-targeted-extra and selinux-policy-mls-extra from the Red Hat CodeReady repo and things work fine.

      However - As the name implies, CodeReady Linux Builder is for developers who develop Red Hat Enterprise Linux applications and includes a number of packages for developers to use when building their applications.

      Similar to the Optional repo in previous versions of Red Hat Enterprise Linux, the CodeReady Linux Builder contains build tooling and -devel packages and is not supported.

      Using these repositories is not welcome in environments with strict security, compliance, or regulatory requirements.

            Assignee:
            Zabbix Development Team
            Reporter:
            Edgar Akhmetshin
            Votes:
            1 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: