Bug 2524485

Summary: SELinux prevents ssh X11 Forwarding due to removal of permissive sshd_session_t domain
Product: [Fedora] Fedora Reporter: Jonathan Billings <jbilling>
Component: selinux-policyAssignee: Zdenek Pytela <zpytela>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: unspecified    
Version: 44CC: dwalsh, edgar.hoch, lvrabec, mmalik, omosnacek, pkoncity, vmojzis, zpytela
Target Milestone: ---Keywords: Regression
Target Release: ---   
Hardware: Unspecified   
OS: Linux   
Whiteboard:
Fixed In Version: selinux-policy-44.8-1.fc44 Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-08-31 17:18:57 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
Reverts the removal of the sshd_auth_t and sshd_session_t permissive domains none

Description Jonathan Billings 2026-08-26 14:59:50 UTC
When I attempt to ssh into a fully updated Fedora Linux 44 system, I see this:

$ ssh -X fedora-test
X11 forwarding request failed on channel 1
fedora-test $

If I look at recent selinux AVCs, I see:

$ sudo ausearch -m avc -ts recent
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:561): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6010 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:562): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6011 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:563): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6012 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:564): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6013 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:565): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6014 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:566): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6015 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:567): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6016 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:568): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6017 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:569): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6018 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:570): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6019 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:571): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6020 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:572): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6021 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:573): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6022 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:574): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6023 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:575): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6024 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:576): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6025 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:577): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6026 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:578): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6027 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0
----
(for thousands of AVCs)

Just for example:
$ sudo ausearch -m avc -ts recent | grep -c sshd_session_t
1857

Putting SELinux into permissive mode makes the issue go away.

I believe this is due to the change to remove the sshd_session_t permissive domain (https://github.com/fedora-selinux/selinux-policy/commit/963c9ea0194da33f0058e8e6840ba484bb1c9aaa)

Reproducible: Always

Steps to Reproduce:
1. Have a remote Fedora 44 system with sshd running
2. run "ssh -X remotehost"

Actual Results:
X11 forwarding is not enabled

Expected Results:
X11 forwarding works

Additional Information:
I built a custom selinux-policy package which just reverts the removal of those permissive domains, and the ssh -X now works, which is a good indicator that the commit mentioned above introduced this behavior.

Comment 1 Jonathan Billings 2026-08-26 15:02:27 UTC
Created attachment 2155704 [details]
Reverts the removal of the sshd_auth_t and sshd_session_t permissive domains

Comment 2 Jonathan Billings 2026-08-26 15:08:18 UTC
Related upstream issue:  https://github.com/fedora-selinux/selinux-policy/issues/3384

Comment 3 Fedora Update System 2026-08-27 21:53:34 UTC
FEDORA-2026-16b888c99f (selinux-policy-44.8-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-16b888c99f

Comment 4 Fedora Update System 2026-08-28 02:01:12 UTC
FEDORA-2026-16b888c99f has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-16b888c99f`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-16b888c99f

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2026-08-31 17:18:57 UTC
FEDORA-2026-16b888c99f (selinux-policy-44.8-1.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.