# sesearch -s gnome_remote_desktop_t -t policykit_t -c dbus -p send_msg -A allow gnome_remote_desktop_t policykit_t:dbus send_msg; # sesearch -t gnome_remote_desktop_t -s policykit_t -c dbus -p send_msg -A allow policykit_t gnome_remote_desktop_t:dbus send_msg; # ps ax | grep polkit 839 ? Ssl 0:00 /usr/lib/polkit-1/polkitd --no-debug --log-level=err 17029 pts/0 S+ 0:00 grep --color=auto polkit # service gdm status Redirecting to /bin/systemctl status gdm.service Warning: The unit file, source configuration file or drop-ins of gdm.service changed on disk. R> ● gdm.service - GNOME Display Manager Loaded: loaded (/usr/lib/systemd/system/gdm.service; enabled; preset: enabled) Active: active (running) since Wed 2025-01-08 09:32:37 CET; 29s ago Invocation: 8ba9900760114410a1a9b9919cb467fd Main PID: 16421 (gdm) Tasks: 4 (limit: 11028) Memory: 3.5M (peak: 5.3M) CPU: 90ms CGroup: /system.slice/gdm.service └─16421 /usr/sbin/gdm Jan 08 09:32:40 localhost.localdomain gdm[16421]: Gdm: Child process -16697 was already dead. Jan 08 09:32:40 localhost.localdomain gdm[16421]: Gdm: GdmDisplay: Session never registered, fa> Jan 08 09:32:40 localhost.localdomain gdm[16421]: Gdm: Child process -16697 was already dead. Jan 08 09:32:41 localhost.localdomain gdm[16421]: Gdm: GdmDisplay: Session never registered, fa> Jan 08 09:32:41 localhost.localdomain gdm[16421]: Gdm: Child process -16777 was already dead. Jan 08 09:32:41 localhost.localdomain gdm[16421]: Gdm: GdmDisplay: Session never registered, fa> Jan 08 09:32:41 localhost.localdomain gdm[16421]: Gdm: Child process -16777 was already dead. Jan 08 09:32:42 localhost.localdomain gdm[16421]: Gdm: GdmDisplay: Session never registered, fa> Jan 08 09:32:42 localhost.localdomain gdm[16421]: Gdm: GdmLocalDisplayFactory: maximum number o> Jan 08 09:32:42 localhost.localdomain gdm[16421]: Gdm: Child process -16856 was already dead. # make run chmod a+x runtest.sh chcon -t bin_t runtest.sh ./runtest.sh :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: Setup :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: [ 09:33:09 ] :: [ BEGIN ] :: Running 'rlImport 'selinux-policy/common'' :: [ 09:33:09 ] :: [ INFO ] :: rlImport: Found 'selinux-policy/common', version '43' during upwards traversal :: [ 09:33:09 ] :: [ INFO ] :: rlImport: Will try to import selinux-policy/common from /root/selinux/selinux-policy/Library/common/lib.sh :: [ 09:33:09 ] :: [ INFO ] :: found dependencies: 'distribution/epel ' :: [ 09:33:09 ] :: [ INFO ] :: rlImport: Found 'distribution/epel', version '2' during upwards traversal :: [ 09:33:09 ] :: [ INFO ] :: rlImport: Will try to import distribution/epel from /root/distribution/Library/epel/lib.sh :: [ 09:33:09 ] :: [ INFO ] :: found dependencies: ' distribution/LibrariesWrapper distribution/epel-internal' :: [ 09:33:09 ] :: [ INFO ] :: rlImport: Found 'distribution/LibrariesWrapper', version '9' during upwards traversal :: [ 09:33:09 ] :: [ INFO ] :: rlImport: Will try to import distribution/LibrariesWrapper from /root/distribution/Library/LibrariesWrapper/lib.sh :: [ 09:33:09 ] :: [ INFO ] :: found dependencies: '' :: [ 09:33:09 ] :: [ INFO ] :: rlImport: Found 'distribution/epel-internal', version '3' during upwards traversal :: [ 09:33:09 ] :: [ INFO ] :: rlImport: Will try to import distribution/epel-internal from /root/distribution/Library/epel-internal/lib.sh :: [ 09:33:09 ] :: [ INFO ] :: found dependencies: '' done. done. :: [ 09:33:09 ] :: [ BEGIN ] :: Running 'rlImport distribution/LibrariesWrapper' :: [ 09:33:09 ] :: [ PASS ] :: Command 'rlImport distribution/LibrariesWrapper' (Expected 0, got 0) :: [ 09:33:09 ] :: [ INFO ] :: LibrariesWrapperImport(): library fetched already :: [ 09:33:09 ] :: [ BEGIN ] :: Running 'git checkout "master" -- "epel"' :: [ 09:33:09 ] :: [ PASS ] :: Command 'git checkout "master" -- "epel"' (Expected 0, got 0) :: [ 09:33:09 ] :: [ INFO ] :: found epel v41 from https://github.com/beakerlib/epel.git?75ee923134493bf22efcd92b1aa418a2a2e5be63#epel in /root/distribution/Library/epel/lib/epel loading library distribution/epel v41... done. :: [ 09:33:09 ] :: [ LOG ] :: Determined distro is 'rhel' :: [ 09:33:09 ] :: [ LOG ] :: Determined rhel release is '10' :: [ 09:33:09 ] :: [ LOG ] :: epel repo is not accessible :: [ 09:33:09 ] :: [ LOG ] :: found candidate source of 'epel-release-latest-10.noarch.rpm', using url https://dl.fedoraproject.org/pub/epel/epel-release-latest-10.noarch.rpm :: [ 09:33:09 ] :: [ LOG ] :: install epel repo :: [ 09:33:09 ] :: [ LOG ] :: curl --fail --location --retry-connrefused --retry-delay 3 --retry-max-time 3600 --retry 3 --connect-timeout 20 --max-time 1800 --insecure -o "/tmp/epel_release_OMclWhmb.rpm" "https://dl.fedoraproject.org/pub/epel/epel-release-latest-10.noarch.rpm" % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 18435 100 18435 0 0 32423 0 --:--:-- --:--:-- --:--:-- 32455 :: [ 09:33:10 ] :: [ BEGIN ] :: Running 'rpm --install "/tmp/epel_release_OMclWhmb.rpm" || rpm --reinstall "/tmp/epel_release_OMclWhmb.rpm"' warning: /tmp/epel_release_OMclWhmb.rpm: Header V4 RSA/SHA256 Signature, key ID e37ed158: NOKEY package epel-release-10-3.el10_0.noarch is already installed warning: /tmp/epel_release_OMclWhmb.rpm: Header V4 RSA/SHA256 Signature, key ID e37ed158: NOKEY :: [ 09:33:11 ] :: [ PASS ] :: Command 'rpm --install "/tmp/epel_release_OMclWhmb.rpm" || rpm --reinstall "/tmp/epel_release_OMclWhmb.rpm"' (Expected 0, got 0) :: [ 09:33:11 ] :: [ BEGIN ] :: Running 'rm -f "/tmp/epel_release_OMclWhmb.rpm"' :: [ 09:33:11 ] :: [ PASS ] :: Command 'rm -f "/tmp/epel_release_OMclWhmb.rpm"' (Expected 0, got 0) :: [ 09:33:11 ] :: [ LOG ] :: epel repo is not accessible :: [ 09:33:11 ] :: [ LOG ] :: disabling epel repos :: [ 09:33:11 ] :: [ LOG ] :: setting skip if unavailable :: [ 09:33:11 ] :: [ INFO ] :: SELinux: using 'semodule -lfull' to list modules :: [ 09:33:11 ] :: [ INFO ] :: Running with policy located in /etc/selinux/targeted/policy/policy.34 :: [ 09:33:11 ] :: [ LOG ] :: enriched audit log format already enabled :: [ 09:33:11 ] :: [ LOG ] :: stop the audit daemon first :: [ 09:33:11 ] :: [ BEGIN ] :: Running 'service auditd stop' Stopping logging: :: [ 09:33:11 ] :: [ PASS ] :: Command 'service auditd stop' (Expected 0,2, got 0) :: [ 09:33:16 ] :: [ LOG ] :: audit daemon configuration file is updated, starting the audit service Redirecting to /bin/systemctl status auditd.service Redirecting to /bin/systemctl start auditd.service :: [ 09:33:16 ] :: [ LOG ] :: rlServiceStart: Service auditd started successfully :: [ 09:33:16 ] :: [ INFO ] :: SELinux related packages listing: :: [ 09:33:18 ] :: [ INFO ] :: checkpolicy-3.8-0.rc3.1.el10.x86_64 libselinux-3.8-0.rc3.1.el10.x86_64 libselinux-devel-3.8-0.rc3.1.el10.x86_64 libselinux-utils-3.8-0.rc3.1.el10.x86_64 libsemanage-3.8-0.rc3.1.el10.x86_64 libsepol-3.8-0.rc3.1.el10.x86_64 libsepol-devel-3.8-0.rc3.1.el10.x86_64 libsepol-static-3.8-0.rc3.1.el10.x86_64 libsepol-utils-3.8-0.rc3.1.el10.x86_64 mcstrans-3.7-2.el10.x86_64 policycoreutils-3.8-0.rc3.1.el10.x86_64 policycoreutils-dbus-3.8-0.rc3.1.el10.noarch policycoreutils-devel-3.8-0.rc3.1.el10.x86_64 policycoreutils-gui-3.8-0.rc3.1.el10.noarch policycoreutils-newrole-3.8-0.rc3.1.el10.x86_64 policycoreutils-python-utils-3.8-0.rc3.1.el10.noarch policycoreutils-restorecond-3.7-3.el10.x86_64 policycoreutils-sandbox-3.8-0.rc3.1.el10.x86_64 selinux-policy-40.13.20-1.el10.noarch selinux-policy-devel-40.13.20-1.el10.noarch selinux-policy-doc-40.13.20-1.el10.noarch selinux-policy-minimum-40.13.20-1.el10.noarch selinux-policy-mls-40.13.20-1.el10.noarch selinux-policy-sandbox-40.13.20-1.el10.noarch selinux-policy-targeted-40.13.20-1.el10.noarch setools-4.5.1-4.el10.x86_64 setools-console-4.5.1-4.el10.x86_64 setools-console-analyses-4.5.1-4.el10.x86_64 setools-gui-4.5.1-4.el10.x86_64 setroubleshoot-3.3.35-1.el10.x86_64 setroubleshoot-plugins-3.3.14-11.el10.noarch setroubleshoot-server-3.3.35-1.el10.x86_64 :: [ 09:33:18 ] :: [ INFO ] :: listing took 2 second(s) :: [ 09:33:18 ] :: [ INFO ] :: package 'setools-console-4.5.1-4.el10.x86_64' covers required package 'setools-console' :: [ 09:33:18 ] :: [ INFO ] :: package 'expect-5.45.4-25.el10.x86_64' covers required package 'expect' :: [ 09:33:18 ] :: [ INFO ] :: package 'policycoreutils-python-utils-3.8-0.rc3.1.el10.noarch' covers required package 'policycoreutils-python-utils' :: [ 09:33:18 ] :: [ INFO ] :: package 'selinux-policy-devel-40.13.20-1.el10.noarch' covers required package 'selinux-policy-devel' :: [ 09:33:18 ] :: [ PASS ] :: Command 'rlImport 'selinux-policy/common'' (Expected 0,1, got 0) :: [ 09:33:18 ] :: [ BEGIN ] :: Running 'epelyum install -y --nobest --nogpgcheck --skip-broken audit libselinux libselinux-utils policycoreutils selinux-policy selinux-policy-targeted setools-console /usr/sbin/service gnome-remote-desktop gdm ' actually running 'yum --enablerepo epel-internal install -y --nobest --nogpgcheck --skip-broken audit libselinux libselinux-utils policycoreutils selinux-policy selinux-policy-targeted setools-console /usr/sbin/service gnome-remote-desktop gdm' Updating Subscription Management repositories. Unable to read consumer identity This system is not registered with an entitlement server. You can use "rhc" or "subscription-manager" to register. internal epel repository 38 kB/s | 2.9 kB 00:00 ResilientStorage 324 B/s | 196 B 00:00 Errors during downloading metadata for repository 'ResilientStorage': - Status code: 404 for http://download-node-02.eng.bos.redhat.com/rhel-10/nightly/RHEL-10/latest-RHEL-10/compose/ResilientStorage/x86_64/os/repodata/repomd.xml (IP: 10.2.129.226) Error: Failed to download metadata for repo 'ResilientStorage': Cannot download repomd.xml: Cannot download repodata/repomd.xml: All mirrors were tried Ignoring repositories: ResilientStorage Package audit-4.0-10.el10.x86_64 is already installed. Package libselinux-3.8-0.rc3.1.el10.x86_64 is already installed. Package libselinux-utils-3.8-0.rc3.1.el10.x86_64 is already installed. Package policycoreutils-3.8-0.rc3.1.el10.x86_64 is already installed. Package selinux-policy-40.13.20-1.el10.noarch is already installed. Package selinux-policy-targeted-40.13.20-1.el10.noarch is already installed. Package setools-console-4.5.1-4.el10.x86_64 is already installed. Package initscripts-service-10.26-2.el10.noarch is already installed. Package gnome-remote-desktop-47.alpha-2.el10.x86_64 is already installed. Package gdm-1:47.0-3.el10.x86_64 is already installed. Dependencies resolved. Nothing to do. Complete! :: [ 09:33:20 ] :: [ PASS ] :: Command 'epelyum install -y --nobest --nogpgcheck --skip-broken audit libselinux libselinux-utils policycoreutils selinux-policy selinux-policy-targeted setools-console /usr/sbin/service gnome-remote-desktop gdm ' (Expected 0,1, got 0) selinux-policy-40.13.20-1.el10.noarch :: [ 09:33:20 ] :: [ PASS ] :: Checking for the presence of selinux-policy rpm :: [ 09:33:20 ] :: [ LOG ] :: Package versions: :: [ 09:33:20 ] :: [ LOG ] :: selinux-policy-40.13.20-1.el10.noarch selinux-policy-targeted-40.13.20-1.el10.noarch :: [ 09:33:20 ] :: [ PASS ] :: Checking for the presence of selinux-policy-targeted rpm :: [ 09:33:20 ] :: [ LOG ] :: Package versions: :: [ 09:33:20 ] :: [ LOG ] :: selinux-policy-targeted-40.13.20-1.el10.noarch gnome-remote-desktop-47.alpha-2.el10.x86_64 :: [ 09:33:20 ] :: [ PASS ] :: Checking for the presence of gnome-remote-desktop rpm :: [ 09:33:20 ] :: [ LOG ] :: Package versions: :: [ 09:33:20 ] :: [ LOG ] :: gnome-remote-desktop-47.alpha-2.el10.x86_64 Redirecting to /bin/systemctl status gnome-remote-desktop.service :: [ 09:33:20 ] :: [ BEGIN ] :: Running 'setenforce 1' :: [ 09:33:20 ] :: [ PASS ] :: Command 'setenforce 1' (Expected 0, got 0) :: [ 09:33:20 ] :: [ BEGIN ] :: Running 'id -Z' unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 :: [ 09:33:20 ] :: [ PASS ] :: Command 'id -Z' (Expected 0, got 0) :: [ 09:33:20 ] :: [ BEGIN ] :: Running 'sestatus' SELinux status: enabled SELinuxfs mount: /sys/fs/selinux SELinux root directory: /etc/selinux Loaded policy name: targeted Current mode: enforcing Mode from config file: enforcing Policy MLS status: enabled Policy deny_unknown status: allowed Memory protection checking: actual (secure) Max kernel policy version: 33 :: [ 09:33:20 ] :: [ PASS ] :: Command 'sestatus' (Expected 0, got 0) :: [ 09:33:20 ] :: [ BEGIN ] :: Running 'semodule --list-modules=full | grep -i disabled' :: [ 09:33:20 ] :: [ PASS ] :: Command 'semodule --list-modules=full | grep -i disabled' (Expected 0,1, got 1) :: [ 09:33:20 ] :: [ LOG ] :: rlSESetTimestamp: Setting timestamp 'TIMESTAMP' [01/08/2025 09:33:20] :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: Duration: 13s :: Assertions: 14 good, 0 bad :: RESULT: PASS (Setup) gnome_remote_desktop_t is defined :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: bz#2321236 :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: /usr/libexec/gnome-remote-desktop-daemon system_u:object_r:gnome_remote_desktop_exec_t:s0 :: [ 09:33:23 ] :: [ PASS ] :: Result of matchpathcon /usr/libexec/gnome-remote-desktop-daemon should contain gnome_remote_desktop_exec_t (Assert: expected 0, got 0) /etc/gnome-remote-desktop system_u:object_r:etc_t:s0 :: [ 09:33:23 ] :: [ PASS ] :: Result of matchpathcon /etc/gnome-remote-desktop should contain etc_t (Assert: expected 0, got 0) :: [ 09:33:23 ] :: [ INFO ] :: rlSESearchRule: checking rule 'allow gnome_remote_desktop_t etc_t : dir { watch } [ ]' FILTERED RULES allow domain base_file_type:dir { getattr open search }; allow domain base_ro_file_type:dir { ioctl lock read }; allow gnome_remote_desktop_t etc_t:dir watch; :: [ 09:33:24 ] :: [ PASS ] :: check permission 'watch' is present (Assert: '0' should equal '0') :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: Duration: 2s :: Assertions: 3 good, 0 bad :: RESULT: PASS (bz#2321236) :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: real scenario :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: [ 09:33:25 ] :: [ BEGIN ] :: Running 'service gnome-remote-desktop start' Redirecting to /bin/systemctl start gnome-remote-desktop.service :: [ 09:33:25 ] :: [ PASS ] :: Command 'service gnome-remote-desktop start' (Expected 0, got 0) :: [ 09:33:26 ] :: [ BEGIN ] :: Running 'ps -efZ | grep -v " grep " | grep -E "gnome-remote-desktop-daemon"' system_u:system_r:gnome_remote_desktop_t:s0 gnome-r+ 20997 1 0 09:33 ? 00:00:00 /usr/libexec/gnome-remote-desktop-daemon --system :: [ 09:33:26 ] :: [ PASS ] :: Command 'ps -efZ | grep -v " grep " | grep -E "gnome-remote-desktop-daemon"' (Expected 0, got 0) :: [ 09:33:26 ] :: [ BEGIN ] :: Running 'ps -efZ | grep -v " grep " | grep -E "gnome_remote_desktop_t.*gnome-remote-desktop-daemon"' system_u:system_r:gnome_remote_desktop_t:s0 gnome-r+ 20997 1 0 09:33 ? 00:00:00 /usr/libexec/gnome-remote-desktop-daemon --system :: [ 09:33:26 ] :: [ PASS ] :: Command 'ps -efZ | grep -v " grep " | grep -E "gnome_remote_desktop_t.*gnome-remote-desktop-daemon"' (Expected 0, got 0) :: [ 09:33:27 ] :: [ BEGIN ] :: Running 'service gnome-remote-desktop status' Redirecting to /bin/systemctl status gnome-remote-desktop.service ● gnome-remote-desktop.service - GNOME Remote Desktop Loaded: loaded (/usr/lib/systemd/system/gnome-remote-desktop.service; enabled; preset: dis> Active: active (running) since Wed 2025-01-08 09:33:25 CET; 2s ago Invocation: 2a90ada1ab6b434d967c52ead43e9322 Main PID: 20997 (gnome-remote-de) Tasks: 5 (limit: 11028) Memory: 9.6M (peak: 10.1M) CPU: 19ms CGroup: /system.slice/gnome-remote-desktop.service └─20997 /usr/libexec/gnome-remote-desktop-daemon --system Jan 08 09:33:25 localhost.localdomain systemd[1]: Starting gnome-remote-desktop.service - GNOME> Jan 08 09:33:25 localhost.localdomain gnome-remote-de[20997]: Init TPM credentials failed becau> Jan 08 09:33:25 localhost.localdomain systemd[1]: Started gnome-remote-desktop.service - GNOME > Jan 08 09:33:25 localhost.localdomain gnome-remote-de[20997]: RDP TLS certificate and key not y> :: [ 09:33:29 ] :: [ PASS ] :: Command 'service gnome-remote-desktop status' (Expected 0,1,3, got 0) :: [ 09:33:30 ] :: [ BEGIN ] :: Running 'grdctl --headless status' Init TPM credentials failed because No TPM device found, using GKeyFile as fallback. RDP: Status: enabled Port: 3389 TLS certificate: /etc/gnome-remote-desktop/client-cert.crt TLS fingerprint: 63:71:44:ec:32:c5:75:09:d3:f8:52:be:74:9a:97:e0:2f:fa:80:18:08:9f:1d:cd:54:4c:95:c2:82:0a:31:93 TLS key: /etc/gnome-remote-desktop/client-private.key View-only: no Negotiate port: yes Username: (hidden) Password: (hidden) :: [ 09:33:30 ] :: [ PASS ] :: Command 'grdctl --headless status' (Expected 0, got 0) :: [ 09:33:30 ] :: [ BEGIN ] :: Running 'grdctl --system status' Init TPM credentials failed because No TPM device found, using GKeyFile as fallback. Overall: Unit status: active RDP: Status: enabled Port: 3389 TLS certificate: (null) TLS fingerprint: (null) TLS key: (null) Username: (empty) Password: (empty) :: [ 09:33:30 ] :: [ PASS ] :: Command 'grdctl --system status' (Expected 0, got 0) :: [ 09:33:30 ] :: [ BEGIN ] :: Running 'grdctl --system rdp enable' Init TPM credentials failed because No TPM device found, using GKeyFile as fallback. :: [ 09:33:30 ] :: [ PASS ] :: Command 'grdctl --system rdp enable' (Expected 0, got 0) :: [ 09:33:30 ] :: [ BEGIN ] :: Running 'grdctl --system vnc enable' Init TPM credentials failed because No TPM device found, using GKeyFile as fallback. Usage: /usr/bin/grdctl [OPTIONS...] COMMAND [SUBCOMMAND]... :: [ 09:33:31 ] :: [ PASS ] :: Command 'grdctl --system vnc enable' (Expected 0, got 0) :: [ 09:33:31 ] :: [ BEGIN ] :: Running 'grdctl --system status' Init TPM credentials failed because No TPM device found, using GKeyFile as fallback. Overall: Unit status: active RDP: Status: enabled Port: 3389 TLS certificate: (null) TLS fingerprint: (null) TLS key: (null) Username: (empty) Password: (empty) :: [ 09:33:31 ] :: [ PASS ] :: Command 'grdctl --system status' (Expected 0, got 0) :: [ 09:33:31 ] :: [ BEGIN ] :: Running 'restorecon -Rv /etc /run /var -e /var/ARTIFACTS' Can't stat exclude path "/var/ARTIFACTS", No such file or directory - ignoring. :: [ 09:33:31 ] :: [ PASS ] :: Command 'restorecon -Rv /etc /run /var -e /var/ARTIFACTS' (Expected 0-255, got 0) :: [ 09:33:31 ] :: [ BEGIN ] :: Running 'service gnome-remote-desktop restart' Redirecting to /bin/systemctl restart gnome-remote-desktop.service :: [ 09:33:31 ] :: [ PASS ] :: Command 'service gnome-remote-desktop restart' (Expected 0, got 0) :: [ 09:33:32 ] :: [ BEGIN ] :: Running 'ps -efZ | grep -v " grep " | grep -E "gnome-remote-desktop-daemon"' system_u:system_r:gnome_remote_desktop_t:s0 gnome-r+ 21816 1 0 09:33 ? 00:00:00 /usr/libexec/gnome-remote-desktop-daemon --system :: [ 09:33:32 ] :: [ PASS ] :: Command 'ps -efZ | grep -v " grep " | grep -E "gnome-remote-desktop-daemon"' (Expected 0, got 0) :: [ 09:33:32 ] :: [ BEGIN ] :: Running 'ps -efZ | grep -v " grep " | grep -E "gnome_remote_desktop_t.*gnome-remote-desktop-daemon"' system_u:system_r:gnome_remote_desktop_t:s0 gnome-r+ 21816 1 0 09:33 ? 00:00:00 /usr/libexec/gnome-remote-desktop-daemon --system :: [ 09:33:32 ] :: [ PASS ] :: Command 'ps -efZ | grep -v " grep " | grep -E "gnome_remote_desktop_t.*gnome-remote-desktop-daemon"' (Expected 0, got 0) :: [ 09:33:34 ] :: [ BEGIN ] :: Running 'service gnome-remote-desktop status' Redirecting to /bin/systemctl status gnome-remote-desktop.service ● gnome-remote-desktop.service - GNOME Remote Desktop Loaded: loaded (/usr/lib/systemd/system/gnome-remote-desktop.service; enabled; preset: dis> Active: active (running) since Wed 2025-01-08 09:33:31 CET; 2s ago Invocation: 1e39c163366c45cb807a784062c87d74 Main PID: 21816 (gnome-remote-de) Tasks: 5 (limit: 11028) Memory: 3.1M (peak: 3.6M) CPU: 21ms CGroup: /system.slice/gnome-remote-desktop.service └─21816 /usr/libexec/gnome-remote-desktop-daemon --system Jan 08 09:33:31 localhost.localdomain systemd[1]: Starting gnome-remote-desktop.service - GNOME> Jan 08 09:33:31 localhost.localdomain gnome-remote-de[21816]: Init TPM credentials failed becau> Jan 08 09:33:31 localhost.localdomain systemd[1]: Started gnome-remote-desktop.service - GNOME > Jan 08 09:33:31 localhost.localdomain gnome-remote-de[21816]: RDP TLS certificate and key not y> :: [ 09:33:34 ] :: [ PASS ] :: Command 'service gnome-remote-desktop status' (Expected 0,1,3, got 0) :: [ 09:33:36 ] :: [ BEGIN ] :: Running 'service gnome-remote-desktop stop' Redirecting to /bin/systemctl stop gnome-remote-desktop.service :: [ 09:33:36 ] :: [ PASS ] :: Command 'service gnome-remote-desktop stop' (Expected 0, got 0) :: [ 09:33:37 ] :: [ BEGIN ] :: Running 'service gnome-remote-desktop status' Redirecting to /bin/systemctl status gnome-remote-desktop.service ○ gnome-remote-desktop.service - GNOME Remote Desktop Loaded: loaded (/usr/lib/systemd/system/gnome-remote-desktop.service; enabled; preset: dis> Active: inactive (dead) since Wed 2025-01-08 09:33:36 CET; 1s ago Duration: 5.024s Invocation: 1e39c163366c45cb807a784062c87d74 Process: 21816 ExecStart=/usr/libexec/gnome-remote-desktop-daemon --system (code=exited, st> Main PID: 21816 (code=exited, status=0/SUCCESS) Jan 08 09:33:31 localhost.localdomain systemd[1]: Starting gnome-remote-desktop.service - GNOME> Jan 08 09:33:31 localhost.localdomain gnome-remote-de[21816]: Init TPM credentials failed becau> Jan 08 09:33:31 localhost.localdomain systemd[1]: Started gnome-remote-desktop.service - GNOME > Jan 08 09:33:31 localhost.localdomain gnome-remote-de[21816]: RDP TLS certificate and key not y> Jan 08 09:33:36 localhost.localdomain systemd[1]: Stopping gnome-remote-desktop.service - GNOME> Jan 08 09:33:36 localhost.localdomain systemd[1]: gnome-remote-desktop.service: Deactivated suc> Jan 08 09:33:36 localhost.localdomain systemd[1]: Stopped gnome-remote-desktop.service - GNOME > :: [ 09:33:39 ] :: [ PASS ] :: Command 'service gnome-remote-desktop status' (Expected 0,1,3, got 3) :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: Duration: 15s :: Assertions: 16 good, 0 bad :: RESULT: PASS (real scenario) :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: Cleanup :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: [ 09:33:42 ] :: [ LOG ] :: rlSEAVCCheck: Search for AVCs, USER_AVCs, SELINUX_ERRs, and USER_SELINUX_ERRs since timestamp 'TIMESTAMP' [01/08/2025 09:33:20] :: [ 09:33:42 ] :: [ INFO ] :: rlSEAVCCheck: ignoring patterns: :: [ 09:33:42 ] :: [ INFO ] :: rlSEAVCCheck: type=USER_AVC.*received (policyload|setenforce) notice :: [ 09:33:42 ] :: [ PASS ] :: Check there are no unexpected AVCs/ERRORs (Assert: expected 0, got 0) Redirecting to /bin/systemctl status gnome-remote-desktop.service :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: Duration: 2s :: Assertions: 1 good, 0 bad :: RESULT: PASS (Cleanup)