Bug 2524485
| Summary: | SELinux prevents ssh X11 Forwarding due to removal of permissive sshd_session_t domain | ||||||
|---|---|---|---|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Jonathan Billings <jbilling> | ||||
| Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> | ||||
| Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||
| Severity: | high | Docs Contact: | |||||
| Priority: | unspecified | ||||||
| Version: | 44 | CC: | dwalsh, edgar.hoch, lvrabec, mmalik, omosnacek, pkoncity, vmojzis, zpytela | ||||
| Target Milestone: | --- | Keywords: | Regression | ||||
| Target Release: | --- | ||||||
| Hardware: | Unspecified | ||||||
| OS: | Linux | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | selinux-policy-44.8-1.fc44 | Doc Type: | --- | ||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2026-08-31 17:18:57 UTC | Type: | --- | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Attachments: |
|
||||||
Created attachment 2155704 [details]
Reverts the removal of the sshd_auth_t and sshd_session_t permissive domains
Related upstream issue: https://github.com/fedora-selinux/selinux-policy/issues/3384 FEDORA-2026-16b888c99f (selinux-policy-44.8-1.fc44) has been submitted as an update to Fedora 44. https://bodhi.fedoraproject.org/updates/FEDORA-2026-16b888c99f FEDORA-2026-16b888c99f has been pushed to the Fedora 44 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-16b888c99f` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-16b888c99f See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. FEDORA-2026-16b888c99f (selinux-policy-44.8-1.fc44) has been pushed to the Fedora 44 stable repository. If problem still persists, please make note of it in this bug report. |
When I attempt to ssh into a fully updated Fedora Linux 44 system, I see this: $ ssh -X fedora-test X11 forwarding request failed on channel 1 fedora-test $ If I look at recent selinux AVCs, I see: $ sudo ausearch -m avc -ts recent time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:561): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6010 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:562): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6011 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:563): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6012 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:564): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6013 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:565): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6014 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:566): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6015 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:567): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6016 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:568): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6017 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:569): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6018 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:570): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6019 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:571): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6020 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:572): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6021 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:573): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6022 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:574): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6023 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:575): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6024 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:576): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6025 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:577): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6026 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:578): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6027 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0 ---- (for thousands of AVCs) Just for example: $ sudo ausearch -m avc -ts recent | grep -c sshd_session_t 1857 Putting SELinux into permissive mode makes the issue go away. I believe this is due to the change to remove the sshd_session_t permissive domain (https://github.com/fedora-selinux/selinux-policy/commit/963c9ea0194da33f0058e8e6840ba484bb1c9aaa) Reproducible: Always Steps to Reproduce: 1. Have a remote Fedora 44 system with sshd running 2. run "ssh -X remotehost" Actual Results: X11 forwarding is not enabled Expected Results: X11 forwarding works Additional Information: I built a custom selinux-policy package which just reverts the removal of those permissive domains, and the ssh -X now works, which is a good indicator that the commit mentioned above introduced this behavior.