View Issue Details

IDProjectCategoryView StatusLast Update
0010627Rocky-Linux-10selinux-policypublic2025-10-24 04:03
ReporterDavid Cunningham Assigned To 
PrioritynormalSeverityminorReproducibilityalways
Status newResolutionopen 
Product Version10.0 
Summary0010627: No selinux module for asterisk
DescriptionRocky 8 installed with a module for asterisk in /var/lib/selinux/targeted/active/modules/100/asterisk. It seems that Rocky 10 does not.
If this is intentional and can't be changed then this report can be closed, but we would prefer that it be added to Rocky 10, as some policies for other products rely on the asterisk module for selinux existing.
Steps To ReproduceInstall Rocky 8 and Rocky 10. Check /var/lib/selinux/targeted/active/modules/ and output of "semodule -l | grep asterisk".
Tagsselinux

Activities

David Cunningham

David Cunningham

2025-10-23 01:03

reporter   ~0011353

I know that "any update"? comments aren't particularly useful, but... any update? Is there someone in particular we can talk to about it?
Michael Young

Michael Young

2025-10-24 00:04

reporter   ~0011419

Hola David,

I didn't see this come through. Usually Asterisk stuff catches my eye. Nice to see you over here. Anyways, I did a bit of research. It looks like the policy modules are now in an epel package.

If you have `epel-release` installed, you can:

`dnf install selinux-policy-epel-targeted`

The directory is here:
`/var/lib/selinux/targeted/active/modules/200/asterisk`

You can confirm that it is loaded:
`semodule -l | grep asterisk`

Hope that helps!
David Cunningham

David Cunningham

2025-10-24 01:47

reporter   ~0011452

Thanks for your help Michael, however I can't see selinux-policy-epel-targeted. The output is as follows. Am I doing something wrong?

[root@dev-rocky-10 ~]# dnf list epel-release
Last metadata expiration check: 0:47:47 ago on Fri 24 Oct 2025 13:59:00.
Installed Packages
epel-release.noarch 10-6.el10_0 @extras

[root@dev-rocky-10 ~]# dnf install selinux-policy-epel-targeted
Last metadata expiration check: 0:47:51 ago on Fri 24 Oct 2025 13:59:00.
No match for argument: selinux-policy-epel-targeted
Error: Unable to find a match: selinux-policy-epel-targeted
Michael Young

Michael Young

2025-10-24 02:01

reporter   ~0011485

Hmm. That is odd. Here is a screenshot on a clean Rocky 10 VM.

Maybe try doing a `dnf clean all` or add `--refresh` flag to the dnf command? Something like ` dnf install selinux-policy-epel-targeted --refresh`.

Just some ideas.
image-2.png (100,233 bytes)   
image-2.png (100,233 bytes)   
image.png (83,139 bytes)   
image.png (83,139 bytes)   
David Cunningham

David Cunningham

2025-10-24 03:22

reporter   ~0011518

Weird, still nothing. I wonder what I'm doing wrong?

[root@dev-rocky-10 ~]# dnf clean all
45 files removed

[root@dev-rocky-10 ~]# dnf install selinux-policy-epel-targeted --refresh
Node.js Packages for Linux RPM based distros - x86_64 13 kB/s | 5.7 kB 00:00
Extra Packages for Enterprise Linux 10 - x86_64 2.8 MB/s | 5.7 MB 00:02
Rocky Linux 10 - BaseOS 31 MB/s | 21 MB 00:00
Rocky Linux 10 - AppStream 3.2 MB/s | 2.2 MB 00:00
Rocky Linux 10 - CRB 843 kB/s | 527 kB 00:00
Rocky Linux 10 - Extras 7.5 kB/s | 5.4 kB 00:00
RPM Fusion for EL 10 - Free - Updates 38 kB/s | 47 kB 00:01
No match for argument: selinux-policy-epel-targeted
Error: Unable to find a match: selinux-policy-epel-targeted

[root@dev-rocky-10 ~]# cat /etc/redhat-release
Rocky Linux release 10.0 (Red Quartz)
Michael Young

Michael Young

2025-10-24 03:55

reporter   ~0011551

What does your `/etc/yum.repos.d/epel.repo` file look like?

[epel]
name=Extra Packages for Enterprise Linux $releasever - $basearch
# It is much more secure to use the metalink, but if you wish to use a local mirror
# place its address here.
#baseurl=https://download.example/pub/epel/$releasever${releasever_minor:+z}/Everything/$basearch/
metalink=https://mirrors.fedoraproject.org/metalink?repo=epel${releasever_minor:+-z}-$releasever&arch=$basearch
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-$releasever_major
gpgcheck=1
repo_gpgcheck=0
metadata_expire=24h
countme=1
enabled=1
David Cunningham

David Cunningham

2025-10-24 03:59

reporter   ~0011552

It's the same but with other packages:

[root@dev-rocky-10 ~]# cat /etc/yum.repos.d/epel.repo
[epel]
name=Extra Packages for Enterprise Linux $releasever - $basearch
# It is much more secure to use the metalink, but if you wish to use a local mirror
# place its address here.
#baseurl=https://download.example/pub/epel/$releasever${releasever_minor:+z}/Everything/$basearch/
metalink=https://mirrors.fedoraproject.org/metalink?repo=epel${releasever_minor:+-z}-$releasever&arch=$basearch
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-$releasever_major
gpgcheck=1
repo_gpgcheck=0
metadata_expire=24h
countme=1
enabled=1

[epel-debuginfo]
name=Extra Packages for Enterprise Linux $releasever - $basearch - Debug
# It is much more secure to use the metalink, but if you wish to use a local mirror
# place its address here.
#baseurl=https://download.example/pub/epel/$releasever${releasever_minor:+z}/Everything/$basearch/debug/
metalink=https://mirrors.fedoraproject.org/metalink?repo=epel${releasever_minor:+-z}-debug-$releasever&arch=$basearch
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-$releasever_major
gpgcheck=1
repo_gpgcheck=0
metadata_expire=24h
enabled=0

[epel-source]
name=Extra Packages for Enterprise Linux $releasever - $basearch - Source
# It is much more secure to use the metalink, but if you wish to use a local mirror
# place its address here.
#baseurl=https://download.example/pub/epel/$releasever${releasever_minor:+z}/Everything/source/tree/
metalink=https://mirrors.fedoraproject.org/metalink?repo=epel${releasever_minor:+-z}-source-$releasever&arch=source
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-$releasever_major
gpgcheck=1
repo_gpgcheck=0
metadata_expire=24h
enabled=0
Michael Young

Michael Young

2025-10-24 04:03

reporter   ~0011553

I am at a loss. The only other possibility is that you are hitting a mirror that is not in sync, perhaps.

Issue History

Date Modified Username Field Change
2025-09-10 00:01 David Cunningham New Issue
2025-09-10 00:01 David Cunningham Tag Attached: selinux
2025-10-23 01:03 David Cunningham Note Added: 0011353
2025-10-24 00:04 Michael Young Note Added: 0011419
2025-10-24 01:47 David Cunningham Note Added: 0011452
2025-10-24 02:01 Michael Young Note Added: 0011485
2025-10-24 02:01 Michael Young File Added: image.png
2025-10-24 02:01 Michael Young File Added: image-2.png
2025-10-24 03:22 David Cunningham Note Added: 0011518
2025-10-24 03:55 Michael Young Note Added: 0011551
2025-10-24 03:59 David Cunningham Note Added: 0011552
2025-10-24 04:03 Michael Young Note Added: 0011553