#769 SELinux problems with snaps
Closed: invalid 5 years ago Opened 5 years ago by abitrolly.

How to fix issues with snaps and SELinux? Is there any intro into what's going on with them and what is the workflow to report and deal with issues such as this
https://forum.snapcraft.io/t/snap-can-not-execute-its-own-files-on-selinux/5352


Unfortunately it's not FPC's business. Sorry.

Metadata Update from @ignatenkobrain:
- Issue close_status updated to: invalid
- Issue status updated to: Closed (was: Open)

5 years ago

Thanks, but can you explain why?

My logic is that Fedora packaging requires knowledge about SELinux and its security restrictions. snapd is official package in Fedora and it uses packages in different format that SELinux complains about. Who if not people skilled in packaging can explain what is going on and how to fix these problems?

This simply has absolutely nothing to do with the packaging committee. We maintain the Fedora packaging guidelines. We can't address individual bugs, be they in the selinux policy or in in some snap that you downloaded from somewhere. It's just not at all what we do.

And, really, this isn't even about packaging, so it's really, really far away from what we do. What you need is someone skilled in selinux. Fedora has an selinux mailing list: https://lists.fedoraproject.org/archives/list/selinux@lists.fedoraproject.org/. Perhaps you would find some help there.

I don't understand why SELinux policy is not a part of packaging guidelines, but thanks for the pointer to SELinux mailing list - it makes this issue more useful in search results.

There are guidelines in progress currently.

Even if there were packaging guidelines in place currently, they wouldn't cover your situation. That's what we keep trying to tell you. They would give you the mechanics and recommended scriptlets for including selinux policy in your packages. They wouldn't tell you how to do anything with snaps, write selinux policy, or fix selinux bugs.

Login to comment on this ticket.

Metadata