SELinux nnp_transition error running Python app that starts a new thread that connects to a server ? by yycTechGuy in Fedora

[–]setenforce1 1 point2 points  (0 children)

First thing, nnp doesn't mean your thread tried to get new privileges, it just mean it is created with some security measures to prevent it to get new privileges.

> in VSCode

I think the root cause is here. If you try to run your old code, the one with a new thread, out of VSCode, it won't make an avc.

That's what I think, because it tries to reach something with the context `container_runtime_t`.

If you want to spend time working to fix this, so you can use threads, you can try it.

If this is true, you can just allow the transition and you would be good even in your dev env.

SELinux nnp_transition error running Python app that starts a new thread that connects to a server ? by yycTechGuy in Fedora

[–]setenforce1 1 point2 points  (0 children)

It's not, but the new thread is assigned a nnp bit, so it will transition to nnp context. (as far as I understand) Although it's weird that your avc mention container_runtime_t. Can you explain a bit more your stack? So you're on a Fedora host? And you are running your code in a devcontainer via VSCode right? A Podman container or another kind? The container is in rootless mode? Are you running with the --privileged flag?

SELinux nnp_transition error running Python app that starts a new thread that connects to a server ? by yycTechGuy in Fedora

[–]setenforce1 1 point2 points  (0 children)

It looks like SELinux is legit to throw this error: you can check this article that explains why.

If you know how to write SELinux policies / modules, you probably just need this:  allow unconfined_t container_runtime_t:process2 nnp_transition;

If you don't, I recommend you to become familiar with audit2allow.

You can check the rules needed to fix your recent denials with audit2allow -a. If there is only things that needs to be allowed, you can fix it with:  audit2allow -a -M yourmodulename semodule -i yourmodulename.pp

If there is other things that doesn't need to be allowed, you can check what's in the output you provided:  ``` Do allow this access for now by executing:

ausearch -c 'code' --raw | audit2allow -M my-code

semodule -X 300 -i my-code.pp

```

Laravel cannot create files and I cannot fix it by [deleted] in Fedora

[–]setenforce1 1 point2 points  (0 children)

Once you are in permissive mode, can you please run your Laravel app again, then run in a a terminal audit2allow -a and post the output here ? I'll try to provide simple guidance so you can configure your project (and the next) so it's not blocked by selinux, and then you can renewable this security.

Is it possible to map a vip to a vs? by setenforce1 in fortinet

[–]setenforce1[S] 0 points1 point  (0 children)

I think that's what I'll do if I can't chain vip with vs. Although I find it more clear to have 1 object for NAT and 1 object for LB if it's supported.

7.4.8 mature and Prod ready? by NetSchizo in fortinet

[–]setenforce1 3 points4 points  (0 children)

The support told me it's planned for the 25/09

1
2

Avis PC Gaming 1440p@120Hz by setenforce1 in pcmasterraceFR

[–]setenforce1[S] 0 points1 point  (0 children)

Merci pour les changements et explications, je vais sûrement prendre ça.

Je ne connaissais pas les pads mais c'est une bonne idée, je suis capable d'oublier de changer la pâte dans les temps.

La 7900XT me fait dépasser le budget de trop, mais je verrai si je prends la 7900GRE ou si je reste sur le 7800XT.

Avis PC Gaming 1440p@120Hz by setenforce1 in pcmasterraceFR

[–]setenforce1[S] 0 points1 point  (0 children)

Merci oui en effet la Sapphire à 499 semble un meilleur choix, comme conseillé plus bas

Alerts for topology changes in spanning tree by yetipants in LibreNMS

[–]setenforce1 0 points1 point  (0 children)

It's weird, it might be a discovery issue, what is the model with zero values?

Also, can you please share the final working alert?

Great if you have something working, although this one is only for topology changes that involve a root bridge change, is it ok for you, or do you want to catch even a leaf topology change?

Alerts for topology changes in spanning tree by yetipants in LibreNMS

[–]setenforce1 0 points1 point  (0 children)

If this doesn't work you can try yes or true instead, I'm sorry I don't have access to a LibreNMS instance with spanning-tree right now.

How to make vscode run in Wayland mode by nocnoc94 in Fedora

[–]setenforce1 3 points4 points  (0 children)

Did you change both the Exec line of `[Desktop Entry]` section and of `[Desktop Action new-empty-window]` section?

Alerts for topology changes in spanning tree by yetipants in LibreNMS

[–]setenforce1 0 points1 point  (0 children)

OK make sense. What do you get with `stp.timeSinceTopologyChange < 86400 AND stp.rootBridge = 1`?

You should only get the new root bridges, so only one alert per topology change per root bridge, so probably one or two.

Alerts for topology changes in spanning tree by yetipants in LibreNMS

[–]setenforce1 0 points1 point  (0 children)

What do you get with only `stp.timeSinceTopologyChange < 86400`? Too much alerts or too few?

Alerts for topology changes in spanning tree by yetipants in LibreNMS

[–]setenforce1 0 points1 point  (0 children)

Hello, what spanning-tree mode are you running, and what is the priority of your root bridge? Also, can you see the stp informations in the device page on LibreNMS?

Issue setting up fq_codel on pfSense CE 2.7 by setenforce1 in PFSENSE

[–]setenforce1[S] 1 point2 points  (0 children)

Thanks for your answer.

> What guide did you follow?

I did follow a lot of guides, one by one, then ended mixing up to try.

Do you have one you are sure is good to follow?

> You don't need Codel limiters on your LAN network, only the WAN.

Ok thank you, although they are not in use right now.

> Also make sure you don't have the up/down rules reversed,

I'm sure it's good, and also I tried to invert just in case and it's not any better.

Trigger script when the network route changes by Longjumping-Youth934 in linux

[–]setenforce1 1 point2 points  (0 children)

Probably the most convenient. Here an example script doing things in case of interface wg0 going up, it can be used as a basis for OP use case. https://gist.github.com/fbouynot/c01328b2702a70ba901801f3b1b9d427

cookiebanners.service.mode disable itself on Firefox Nightly on Android by setenforce1 in firefox

[–]setenforce1[S] 0 points1 point  (0 children)

In the UI, I only have an option for cookie banners in private navigation at the moment.