Description of problem: I am installing a virtual machine using SLES. SELinux is preventing rpc-virtstorage from 'unlink' accesses on the file SLE-15-SP5-Online-x86_64-GM-Media1.iso. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that rpc-virtstorage should be allowed unlink access on the SLE-15-SP5-Online-x86_64-GM-Media1.iso file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'rpc-virtstorage' --raw | audit2allow -M my-rpcvirtstorage # semodule -X 300 -i my-rpcvirtstorage.pp Additional Information: Source Context system_u:system_r:virtstoraged_t:s0 Target Context system_u:object_r:virt_content_t:s0 Target Objects SLE-15-SP5-Online-x86_64-GM-Media1.iso [ file ] Source rpc-virtstorage Source Path rpc-virtstorage Port <Unknown> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-40.22-1.fc40.noarch Local Policy RPM selinux-policy-targeted-40.22-1.fc40.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 6.9.4-200.fc40.x86_64 #1 SMP PREEMPT_DYNAMIC Wed Jun 12 13:33:34 UTC 2024 x86_64 Alert Count 1 First Seen 2024-06-22 21:14:53 CST Last Seen 2024-06-22 21:14:53 CST Local ID 469c5a5a-fe16-4f39-9297-5bf4ba831a1f Raw Audit Messages type=AVC msg=audit(1719112493.442:366): avc: denied { unlink } for pid=9807 comm="rpc-virtstorage" name="SLE-15-SP5-Online-x86_64-GM-Media1.iso" dev="sda1" ino=1076 scontext=system_u:system_r:virtstoraged_t:s0 tcontext=system_u:object_r:virt_content_t:s0 tclass=file permissive=1 Hash: rpc-virtstorage,virtstoraged_t,virt_content_t,file,unlink Version-Release number of selected component: selinux-policy-targeted-40.22-1.fc40.noarch Additional info: reporter: libreport-2.17.15 reason: SELinux is preventing rpc-virtstorage from 'unlink' accesses on the file SLE-15-SP5-Online-x86_64-GM-Media1.iso. package: selinux-policy-targeted-40.22-1.fc40.noarch component: selinux-policy hashmarkername: setroubleshoot type: libreport kernel: 6.9.4-200.fc40.x86_64 comment: I am installing a virtual machine using SLES. component: selinux-policy
Created attachment 2038013 [details] File: description
Created attachment 2038014 [details] File: os_info
FEDORA-2024-f6d12d5c36 (selinux-policy-40.26-1.fc40) has been submitted as an update to Fedora 40. https://bodhi.fedoraproject.org/updates/FEDORA-2024-f6d12d5c36
FEDORA-2024-f6d12d5c36 has been pushed to the Fedora 40 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2024-f6d12d5c36` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2024-f6d12d5c36 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2024-f6d12d5c36 (selinux-policy-40.26-1.fc40) has been pushed to the Fedora 40 stable repository. If problem still persists, please make note of it in this bug report.