'systemd-pcrextend' is not able to create '/run/log/systemd/tpm2-measure.log' in initramfs (systemd-pcrphase-initrd.service): Mar 22 09:26:01 vkuznets-f40.1-cvm audit[663]: AVC avc: denied { create } for pid=663 comm="systemd-pcrexte" name="tpm2-measure.log" scontext=system_u:system_r:init_t:s0 tcontext=system_u:object_r:syslogd_var_run_t:s0 tclass=file permissive=0 Reproducible: Always Steps to Reproduce: 1. Boot a UKI ('kernel-uki-virt') based Fedora image 2. Observe AVC denial for systemd-pcrphase-initrd.service (/lib/systemd/systemd-pcrextend binary) Actual Results: AVC denial to create /run/log/systemd/tpm2-measure.log Expected Results: Log creation allowed.
This bug appears to have been reported against 'rawhide' during the Fedora Linux 42 development cycle. Changing version to 42.