Description of problem: This happens when systemd updated from 255~rc4-3.fc40 to 255-1.fc40 version. ❯ dnf5 upgrade Updating and loading repositories: Repositories loaded. Package Arch Version Repository Size Upgrading: systemd x86_64 255-1.fc40 rawhide 14.8 MiB replacing systemd x86_64 255~rc4-3.fc40 rawhide 14.8 MiB systemd-container x86_64 255-1.fc40 rawhide 1.4 MiB replacing systemd-container x86_64 255~rc4-3.fc40 rawhide 1.4 MiB systemd-libs i686 255-1.fc40 rawhide 2.0 MiB replacing systemd-libs i686 255~rc4-3.fc40 rawhide 2.0 MiB systemd-libs x86_64 255-1.fc40 rawhide 2.0 MiB replacing systemd-libs x86_64 255~rc4-3.fc40 rawhide 2.0 MiB systemd-networkd x86_64 255-1.fc40 rawhide 2.0 MiB replacing systemd-networkd x86_64 255~rc4-3.fc40 rawhide 2.0 MiB systemd-oomd-defaults noarch 255-1.fc40 rawhide 187.0 B replacing systemd-oomd-defaults noarch 255~rc4-3.fc40 rawhide 187.0 B systemd-pam x86_64 255-1.fc40 rawhide 1.1 MiB replacing systemd-pam x86_64 255~rc4-3.fc40 rawhide 1.1 MiB systemd-resolved x86_64 255-1.fc40 rawhide 638.0 KiB replacing systemd-resolved x86_64 255~rc4-3.fc40 rawhide 638.0 KiB systemd-rpm-macros noarch 255-1.fc40 rawhide 9.5 KiB replacing systemd-rpm-macros noarch 255~rc4-3.fc40 rawhide 9.5 KiB systemd-udev x86_64 255-1.fc40 rawhide 11.5 MiB replacing systemd-udev x86_64 255~rc4-3.fc40 rawhide 11.5 MiB Transaction Summary: Upgrading: 10 packages Replacing: 10 packages Total size of inbound packages is 11 MiB. Need to download 11 MiB. After this operation 2 KiB will be used (install 35 MiB, remove 35 MiB). Is this ok [y/N]: y [ 1/10] systemd-rpm-macros-0:255-1.fc40.noarch 100% | 258.0 KiB/s | 31.2 KiB | 00m00s [ 2/10] systemd-libs-0:255-1.fc40.x86_64 100% | 2.4 MiB/s | 702.4 KiB | 00m00s [ 3/10] systemd-pam-0:255-1.fc40.x86_64 100% | 2.3 MiB/s | 383.5 KiB | 00m00s [ 4/10] systemd-resolved-0:255-1.fc40.x86_64 100% | 6.1 MiB/s | 298.3 KiB | 00m00s [ 5/10] systemd-0:255-1.fc40.x86_64 100% | 10.1 MiB/s | 4.9 MiB | 00m00s [ 6/10] systemd-networkd-0:255-1.fc40.x86_64 100% | 4.2 MiB/s | 678.7 KiB | 00m00s [ 7/10] systemd-oomd-defaults-0:255-1.fc40.noarch 100% | 506.1 KiB/s | 27.3 KiB | 00m00s [ 8/10] systemd-libs-0:255-1.fc40.i686 100% | 5.9 MiB/s | 742.8 KiB | 00m00s [ 9/10] systemd-container-0:255-1.fc40.x86_64 100% | 2.4 MiB/s | 588.0 KiB | 00m00s [10/10] systemd-udev-0:255-1.fc40.x86_64 100% | 3.6 MiB/s | 2.3 MiB | 00m01s -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- [10/10] Total 100% | 6.1 MiB/s | 10.6 MiB | 00m02s Running transaction [ 1/22] Verify package files 100% | 217.0 B/s | 10.0 B | 00m00s [ 2/22] Prepare transaction 100% | 21.0 B/s | 20.0 B | 00m01s [ 3/22] Upgrading systemd-libs-0:255-1.fc40.x86_64 100% | 15.7 MiB/s | 2.0 MiB | 00m00s [ 4/22] Upgrading systemd-pam-0:255-1.fc40.x86_64 100% | 16.5 MiB/s | 1.1 MiB | 00m00s [ 5/22] Upgrading systemd-resolved-0:255-1.fc40.x86_64 100% | 2.8 MiB/s | 642.0 KiB | 00m00s >>> Running post-install scriptlet: systemd-resolved-0:255-1.fc40.x86_64 >>> Stop post-install scriptlet: systemd-resolved-0:255-1.fc40.x86_64 [ 6/22] Upgrading systemd-networkd-0:255-1.fc40.x86_64 100% | 5.7 MiB/s | 2.0 MiB | 00m00s >>> Running post-install scriptlet: systemd-networkd-0:255-1.fc40.x86_64 >>> Stop post-install scriptlet: systemd-networkd-0:255-1.fc40.x86_64 [ 7/22] Upgrading systemd-0:255-1.fc40.x86_64 100% | 3.9 MiB/s | 14.9 MiB | 00m04s >>> Running post-install scriptlet: systemd-0:255-1.fc40.x86_64 >>> Stop post-install scriptlet: systemd-0:255-1.fc40.x86_64 [ 8/22] Upgrading systemd-udev-0:255-1.fc40.x86_64 100% | 6.7 MiB/s | 11.6 MiB | 00m02s >>> Running post-install scriptlet: systemd-udev-0:255-1.fc40.x86_64 >>> Stop post-install scriptlet: systemd-udev-0:255-1.fc40.x86_64 [ 9/22] Upgrading systemd-oomd-defaults-0:255-1.fc40.noarch 100% | 36.7 KiB/s | 976.0 B | 00m00s [10/22] Upgrading systemd-container-0:255-1.fc40.x86_64 100% | 10.3 MiB/s | 1.5 MiB | 00m00s [11/22] Upgrading systemd-rpm-macros-0:255-1.fc40.noarch 100% | 669.5 KiB/s | 10.0 KiB | 00m00s [12/22] Upgrading systemd-libs-0:255-1.fc40.i686 100% | 17.7 MiB/s | 2.0 MiB | 00m00s [13/22] Erasing systemd-oomd-defaults-0:255~rc4-3.fc40.noarch 100% | 235.0 B/s | 4.0 B | 00m00s [14/22] Erasing systemd-libs-0:255~rc4-3.fc40.i686 100% | 500.0 B/s | 22.0 B | 00m00s [15/22] Erasing systemd-rpm-macros-0:255~rc4-3.fc40.noarch 100% | 26.0 B/s | 3.0 B | 00m00s >>> Running pre-uninstall scriptlet: systemd-udev-0:255~rc4-3.fc40.x86_64 >>> Stop pre-uninstall scriptlet: systemd-udev-0:255~rc4-3.fc40.x86_64 [16/22] Erasing systemd-udev-0:255~rc4-3.fc40.x86_64 100% | 1.2 KiB/s | 551.0 B | 00m00s >>> Running post-uninstall scriptlet: systemd-udev-0:255~rc4-3.fc40.x86_64 >>> Stop post-uninstall scriptlet: systemd-udev-0:255~rc4-3.fc40.x86_64 [17/22] Erasing systemd-container-0:255~rc4-3.fc40.x86_64 100% | 771.0 B/s | 64.0 B | 00m00s [18/22] Erasing systemd-0:255~rc4-3.fc40.x86_64 100% | 495.0 B/s | 935.0 B | 00m02s >>> Running post-uninstall scriptlet: systemd-0:255~rc4-3.fc40.x86_64 >>> Stop post-uninstall scriptlet: systemd-0:255~rc4-3.fc40.x86_64 [19/22] Erasing systemd-libs-0:255~rc4-3.fc40.x86_64 100% | 395.0 B/s | 19.0 B | 00m00s [20/22] Erasing systemd-pam-0:255~rc4-3.fc40.x86_64 100% | 95.0 B/s | 12.0 B | 00m00s >>> Running pre-uninstall scriptlet: systemd-networkd-0:255~rc4-3.fc40.x86_64 >>> Stop pre-uninstall scriptlet: systemd-networkd-0:255~rc4-3.fc40.x86_64 [21/22] Erasing systemd-networkd-0:255~rc4-3.fc40.x86_64 100% | 377.0 B/s | 51.0 B | 00m00s >>> Running pre-uninstall scriptlet: systemd-resolved-0:255~rc4-3.fc40.x86_64 >>> Stop pre-uninstall scriptlet: systemd-resolved-0:255~rc4-3.fc40.x86_64 [22/22] Erasing systemd-resolved-0:255~rc4-3.fc40.x86_64 100% | 1.0 B/s | 24.0 B | 00m13s >>> Running post-transaction scriptlet: systemd-resolved-0:255-1.fc40.x86_64 >>> Stop post-transaction scriptlet: systemd-resolved-0:255-1.fc40.x86_64 >>> Running trigger-install scriptlet: glibc-common-0:2.38.9000-26.fc40.x86_64 >>> Stop trigger-install scriptlet: glibc-common-0:2.38.9000-26.fc40.x86_64 >>> Running trigger-install scriptlet: man-db-0:2.12.0-3.fc40.x86_64 >>> Stop trigger-install scriptlet: man-db-0:2.12.0-3.fc40.x86_64 >>> Running trigger-post-uninstall scriptlet: systemd-0:255-1.fc40.x86_64 >>> Stop trigger-post-uninstall scriptlet: systemd-0:255-1.fc40.x86_64 >>> Running trigger-post-uninstall scriptlet: systemd-0:255-1.fc40.x86_64 >>> Stop trigger-post-uninstall scriptlet: systemd-0:255-1.fc40.x86_64 >>> Running trigger-post-uninstall scriptlet: man-db-0:2.12.0-3.fc40.x86_64 >>> Stop trigger-post-uninstall scriptlet: man-db-0:2.12.0-3.fc40.x86_64 >>> Running trigger-post-uninstall scriptlet: systemd-0:255-1.fc40.x86_64 >>> Stop trigger-post-uninstall scriptlet: systemd-0:255-1.fc40.x86_64 >>> Running trigger-post-uninstall scriptlet: systemd-0:255-1.fc40.x86_64 >>> Stop trigger-post-uninstall scriptlet: systemd-0:255-1.fc40.x86_64 >>> Running trigger-install scriptlet: systemd-0:255-1.fc40.x86_64 >>> Stop trigger-install scriptlet: systemd-0:255-1.fc40.x86_64 >>> Running trigger-install scriptlet: systemd-0:255-1.fc40.x86_64 >>> Stop trigger-install scriptlet: systemd-0:255-1.fc40.x86_64 >>> Running trigger-install scriptlet: systemd-0:255-1.fc40.x86_64 >>> Stop trigger-install scriptlet: systemd-0:255-1.fc40.x86_64 >>> Running trigger-install scriptlet: systemd-0:255-1.fc40.x86_64 >>> Stop trigger-install scriptlet: systemd-0:255-1.fc40.x86_64 >>> Running trigger-install scriptlet: systemd-0:255-1.fc40.x86_64 >>> Stop trigger-install scriptlet: systemd-0:255-1.fc40.x86_64 >>> Running trigger-install scriptlet: systemd-0:255-1.fc40.x86_64 >>> Stop trigger-install scriptlet: systemd-0:255-1.fc40.x86_64 >>> Running trigger-install scriptlet: systemd-0:255-1.fc40.x86_64 >>> Stop trigger-install scriptlet: systemd-0:255-1.fc40.x86_64 >>> Running trigger-install scriptlet: systemd-udev-0:255-1.fc40.x86_64 >>> Stop trigger-install scriptlet: systemd-udev-0:255-1.fc40.x86_64 >>> Running trigger-install scriptlet: systemd-udev-0:255-1.fc40.x86_64 >>> Stop trigger-install scriptlet: systemd-udev-0:255-1.fc40.x86_64 SELinux is preventing systemd from 'getattr' accesses on the netlink_netfilter_socket labeled init_t. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that systemd should be allowed getattr access on netlink_netfilter_socket labeled init_t by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'systemd' --raw | audit2allow -M my-systemd # semodule -X 300 -i my-systemd.pp Additional Information: Source Context system_u:system_r:init_t:s0 Target Context system_u:system_r:init_t:s0 Target Objects Unknown [ netlink_netfilter_socket ] Source systemd Source Path systemd Port <Unknown> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-40.6-1.fc40.noarch Local Policy RPM selinux-policy-targeted-40.6-1.fc40.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Permissive Host Name (removed) Platform Linux (removed) 6.7.0- 0.rc4.20231206gitbee0e7762ad2.37.fc40.x86_64+debug #1 SMP PREEMPT_DYNAMIC Wed Dec 6 17:47:20 UTC 2023 x86_64 Alert Count 1 First Seen 2023-12-08 10:59:47 +05 Last Seen 2023-12-08 10:59:47 +05 Local ID d18c2b3e-d963-416c-a365-eee8dcf44044 Raw Audit Messages type=AVC msg=audit(1702015187.486:547): avc: denied { getattr } for pid=1 comm="systemd" scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:init_t:s0 tclass=netlink_netfilter_socket permissive=1 Hash: systemd,init_t,init_t,netlink_netfilter_socket,getattr Version-Release number of selected component: selinux-policy-targeted-40.6-1.fc40.noarch Additional info: reporter: libreport-2.17.11 reason: SELinux is preventing systemd from 'getattr' accesses on the netlink_netfilter_socket labeled init_t. package: selinux-policy-targeted-40.6-1.fc40.noarch component: selinux-policy hashmarkername: setroubleshoot type: libreport kernel: 6.7.0-0.rc4.20231206gitbee0e7762ad2.37.fc40.x86_64+debug component: selinux-policy
Created attachment 2003296 [details] File: description
Created attachment 2003297 [details] File: os_info
Created attachment 2003299 [details] Demonstration
*** This bug has been marked as a duplicate of bug 2250935 ***