Bug 2443825

Summary: Selinux failure for bootupctl
Product: [Fedora] Fedora Reporter: Cristian Le <fedora>
Component: selinux-policyAssignee: Zdenek Pytela <zpytela>
Status: ASSIGNED --- QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: high    
Version: rawhideCC: dwalsh, lvrabec, mmalik, omosnacek, pkoncity, vmojzis, zpytela
Target Milestone: ---Flags: zpytela: mirror+
Target Release: ---   
Hardware: Unspecified   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
avc.txt none

Description Cristian Le 2026-03-02 14:04:37 UTC
Started to get these selinux failure for bootpctl (part of bootc)

```
----
type=AVC msg=audit(02/27/26 15:09:37.739:2040) : avc:  denied  { nnp_transition nosuid_transition } for  pid=13078 comm=bootupctl scontext=system_u:system_r:install_t:s0:c75,c789 tcontext=system_u:system_r:mount_t:s0:c75,c789 tclass=process2 permissive=0 
----
type=SELINUX_ERR msg=audit(02/27/26 15:09:37.739:2041) : op=security_bounded_transition seresult=denied oldcontext=system_u:system_r:install_t:s0:c75,c789 newcontext=system_u:system_r:mount_t:s0:c75,c789
```

Is it known or tracked?

Reproducible: Always

Comment 1 Cristian Le 2026-03-02 14:05:24 UTC
Created attachment 2131676 [details]
avc.txt