Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-82438

selinux-policy-automotive erroneously depends on policycoreutils-python-utils in %post

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • selinux-policy-38.1.55-2.el9
    • None
    • Important
    • ZStream
    • 1
    • rhel-security-selinux
    • ssg_security
    • 0.5
    • QE ack, Dev ack
    • False
    • No
    • SELINUX 250806: 10
    • Approved Blocker
    • Hide

      Installation or upgrade of the selinux-policy-automotive package does not require the policycoreutils-python-utils package.

      Show
      Installation or upgrade of the selinux-policy-automotive package does not require the policycoreutils-python-utils package.
    • Pass
    • Automated
    • Release Note Not Required
    • None

      What were you trying to do that didn't work?

      Installing selinux-policy-automotive pulls in additional dependencies compared to selinux-policy-targeted, extending the footprint of all automotive deployments.

      What is the impact of this issue to you?

      As a result, Python is also pulled in, significantly expanding automotive safety scope and, potentially, attack surface.

      Please provide the package NVR for which the bug is seen:

      selinux-policy-38.1.53-2.el9

      How reproducible is this bug?:

      Always

      Steps to reproduce

      1. Install selinux-policy-automotive in a minimal automotive environment, compare the resulting installed package set to that of installing selinux-policy targeted instead.
      2. Notice the difference, notably policycoreutils-python-utils and its dependencies being pulled in.

      Expected results

      policycoreutils-python-utils and its dependencies are installed.

      Actual results

      policycoreutils-python-utils and its dependencies are NOT installed.

              vmojzis@redhat.com Vit Mojzis
              rhn-support-psabata Petr Ĺ abata
              Zdenek Pytela Zdenek Pytela
              Milos Malik Milos Malik
              Votes:
              0 Vote for this issue
              Watchers:
              10 Start watching this issue

                Created:
                Updated:
                Resolved: