Bug 2523504
| Summary: | Newest update to selinux breaks ssh | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | fygdxcyw |
| Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> |
| Status: | MODIFIED --- | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | high | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 44 | CC: | dwalsh, fedora-kernel-selinux, lvrabec, mmalik, omosnacek, pkoncity, ppywlkiqletw, vmojzis, zpytela |
| Target Milestone: | --- | Keywords: | Regression, Reopened, SELinux |
| Target Release: | --- | Flags: | fygdxcyw:
needinfo?
(fedora-kernel-selinux) fygdxcyw: needinfo? (zpytela) |
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2026-09-11 09:42:25 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
fygdxcyw
2026-08-25 14:44:42 UTC
Probably a variant of Bug 2523732 But a copy of the AVC lines from /var/log/audit/audit.log could be useful. Please update to selinux-policy-44.8-1.fc44 and if the issue persists, attach output of ausearch -i -m avc,user_avc,selinux_err,user_selinux_err -ts today I updated server and client to selinux-policy-44.8-1.fc44, but the issue persists. Here is the output of "ausearch -i -m avc,user_avc,selinux_err,user_selinux_err -ts today":
# When sshfs is working with an older version of selinux-policy:
----
type=AVC msg=audit(09/01/2026 ##:06:17.357:6913950) : avc: denied { search } for pid=37526 comm=sshd-session name=/ dev="dm-4" ino=256 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unlabeled_t:s0 tclass=dir permissive=1
----
# When sshfs not working with selinux-policy-44.8-1.fc44:
----
type=AVC msg=audit(09/01/2026 ##:41:27.155:158) : avc: denied { getattr } for pid=3924 comm=sshd-session path=/servername/.ssh/authorized_keys dev="dm-1" ino=17094554 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:default_t:s0 tclass=file permissive=0
----
type=AVC msg=audit(09/01/2026 ##:41:30.294:165) : avc: denied { getattr } for pid=3926 comm=sshd-session path=/servername/.ssh/authorized_keys dev="dm-1" ino=17094554 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:default_t:s0 tclass=file permissive=0
----
Both unlabeled_t and default_t indicate an issue with labeling. The unlabeled_t label is usually displayed when a file was created in SELinux disabled state or when its actual label does not currently exist. The default_t type is assigned to filesystem objects that do not match any pattern in file-context configuration. Besides, the name "/servername" seems a bit unusual for a home directory. sshfs works if the home directory is a subdirectory of /home. I just suggest to update, new builds should be available on Monday. I just got around to testing version 44.11-1.fc44 of selinux-policy and selinux-policy-targeted, and I'm sorry but it is still broken. Downgrading to 43.3-1.fc44 however, makes it work again. So something changed between 43.3-1.fc44 and 44.7-1.fc44 , that must have introduced this regression. |