-
Bug
-
Resolution: Done-Errata
-
Major
-
rhel-9.4
-
None
-
selinux-policy-38.1.39-1.el9
-
None
-
Important
-
rhel-sst-security-selinux
-
ssg_security
-
16
-
None
-
QE ack
-
False
-
-
No
-
Red Hat Enterprise Linux
-
None
-
Unspecified Release Note Type - Unknown
-
All
-
None
What were you trying to do that didn't work?
Upgrade from RHEL 9.3 to 9.4 with selinux module 'unconfined' disabled.
Please provide the package NVR for which bug is seen:
selinux-policy-targeted-38.1.35-2.el9_4.0.2.
How reproducible:
Consistently
Steps to reproduce
- Start with an EL 9.3 host
- Disable unconfined policy module (semodule -d unconfined)
- Upgrade to EL 9.4
Or
- Start with generic el 9.4 host
- semodule -d unconfined
Expected results
Selinux policy continue to work without errors post update
Ability to disable unconfined module
Actual results
Failed to resolve typeattributeset statement at /var/lib/selinux/targeted/tmp/modules/100/sap/cil:29
Failed to resolve AST
semodule: Failed!
Custom selinux modules fail to re-apply
Use case 2, unconfined module is not disabled.
Work-Around:
- semodule -e unconfined
- dnf update
- semodule -d sap
- semodule -d unconfined
- links to
-
RHBA-2024:130707 selinux-policy bug fix and enhancement update