Re: Fedora 34 selinux blocking out-of-tree module loading even when secureboot is disabled???

2021-02-19 Thread Ondrej Mosnacek
On Fri, Feb 19, 2021 at 5:23 PM Hans de Goede wrote: > Hi, > > On 2/19/21 2:24 PM, Ondrej Mosnacek wrote: > > Hi Hans, > > > > On Fri, Feb 19, 2021 at 1:36 PM Hans de Goede wrote: > >> Hi All, > >> > >> While dogfooding F34 I noticed that out of tree kernel modules (1) are > >> now being

Re: Fedora 34 selinux blocking out-of-tree module loading even when secureboot is disabled???

2021-02-19 Thread Hans de Goede
Hi, On 2/19/21 2:24 PM, Ondrej Mosnacek wrote: > Hi Hans, > > On Fri, Feb 19, 2021 at 1:36 PM Hans de Goede wrote: >> Hi All, >> >> While dogfooding F34 I noticed that out of tree kernel modules (1) are >> now being blocked, not by the kernel's lockdown mechanism (which only >> does this when

Re: Fedora 34 selinux blocking out-of-tree module loading even when secureboot is disabled???

2021-02-19 Thread Ondrej Mosnacek
Hi Hans, On Fri, Feb 19, 2021 at 1:36 PM Hans de Goede wrote: > Hi All, > > While dogfooding F34 I noticed that out of tree kernel modules (1) are > now being blocked, not by the kernel's lockdown mechanism (which only > does this when secureboot is enabled) but by selinux: > > audit: type=1400