-
Notifications
You must be signed in to change notification settings - Fork 179
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Confined user show policy issue: camera cannot be accessed in Firefox (any confinement affected: user_u, staff_u, sysadm_u), tested with MS Teams & Zoom #2080
Comments
@zpytela I think to have read that you also use KDE with confined users? I was wondering if you also experience this problem? Video conferences in Firefox and such? I can reproduce it on new installations, too. I'm wondering if that is really inherited in all our installations or if I provoke it somehow on mine (because other use KDE & confinement too, and I assumed everyone uses video conferences from time to time?). The same for the usb storage issue in #2019 , if you also work in a confined environment, how do you within the GUI from the confined account mount USB storages from other people that usually don't have properly set labels? (I will experiment if Btw, let me know if you prefer to have things in bugzilla rather than here. |
@py0xc3 I use KDE as the staff_u user and Meet in firefox or chrome works for me if that's what you are asking. |
@zpytela I could now verify with Google Meets in Firefox. Just like MS Teams and Zoom, the camera cannot be accessed when the user account is confined with sysadm_u. F41 KDE Spin, up to date as of the test day (5.1.25). I have not done any SELinux modifications on the two systems I could test on (as it comes with the default updates), no external kernel modules or so, and except It might be noted that the earlier test above (of Zoom and Teams) not contain anything from rpmfusion at all, only default repos (I cannot imagine that mesa-va/-vdpau have anything to do with this issue anyway). I am not sure if you have done any modifications beyond the defaults on your system? Or do you use an app? Otherwise, the issue might be related to any difference of the very Fedora release we used to install? There are configurations that ain't touched by release upgrades. I assume one of the two installations has been setup with F37 (based on the delivery date of the hardware), the other any time later. But I cannot imagine this is linked. Below are the related extracts of the 5.1.25 log at the very times I tried to get the camera in Google Meets in Firefox (two attempts):
Attempt 2)
|
Video conferencing is not possible once an account is confined: this affects user_u, staff_u, sysadm_u.
I have tested it many times in the recent months with MS Teams and Zoom (in Firefox). It works fine once the confinement is disabled (unconfined_u), and the issue occurs always when any confinement is enabled.
Audio works fine. Only video is affected. But the logs are comprehensible and explain the issue:
audit[9916]: AVC avc: denied { read } for pid=<firefox> comm="VideoCapture" name="video*" dev="devtmpfs" ino=970
(video* = video0, video1, video2, video3 = 4 entries).MS Teams and Zoom behave the same. The logs are mostly the same, with the exception that the two differ in how often they try to get access to video.
I have provoked related logs with F39 KDE Spin in February 2024 (both for Zoom and MS Teams), and I just re-tried with F40 KDE Spin (MS Teams only). The issue has not changed in F40.
The actual test on F39 KDE:
Related ausearch extract: seissuevideo_ausearch_f39
Related journalctl extract: seissuevideo_journalctl_f39
Just to have an immediate verification that F40 KDE Spin remains affected, here is a journalctl extract of F40 I just made, tested only with MS Teams: seissuevideo_journalctl_f40 (the behavior of MS Teams has not changed on F40). I expect that Zoom has not changed on F40 as well. I assume that other tools for browser video conferencing would behave the same, too. I have not tested separately on Workstation/Gnome, but I don't see a reason to assume that Firefox & video conferencing would behave different there. I have not tested video conferencing tools without browser.
The text was updated successfully, but these errors were encountered: