Bug 2354219 - SELinux is preventing gnome-session-b from 'watch' accesses on the directory /run/media. (excessive spam and notification spam as well, 20fps on the desktop on a 4070TI)
Summary: SELinux is preventing gnome-session-b from 'watch' accesses on the directory ...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 41
Hardware: x86_64
OS: Unspecified
medium
unspecified
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:01e83d05d1d54d4c5c9141e4fe1...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-03-21 23:23 UTC by NO SPAM OR DIE...
Modified: 2025-05-14 01:19 UTC (History)
8 users (show)

Fixed In Version: selinux-policy-41.39-1.fc41
Clone Of:
Environment:
Last Closed: 2025-05-14 01:19:35 UTC
Type: ---
Embargoed:
zpytela: mirror+


Attachments (Terms of Use)
File: description (2.86 KB, text/plain)
2025-03-21 23:23 UTC, NO SPAM OR DIE...
no flags Details
File: os_info (754 bytes, text/plain)
2025-03-21 23:23 UTC, NO SPAM OR DIE...
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Github fedora-selinux selinux-policy pull 2654 0 None open Allow xdm watch a mnt_t directory 2025-04-22 17:18:50 UTC
Red Hat Issue Tracker FC-1617 0 None None None 2025-04-22 17:39:36 UTC

Description NO SPAM OR DIE... 2025-03-21 23:23:13 UTC
Description of problem:
IT WENT CRAZY ON MY DRIVE ITS WREAKING HAVOC

Help me Fedora people you are my only hope
SELinux is preventing gnome-session-b from 'watch' accesses on the directory /run/media.

*****  Plugin catchall_labels (83.8 confidence) suggests   *******************

If you want to allow gnome-session-b to have watch access on the media directory
Then you need to change the label on /run/media
Do
# semanage fcontext -a -t FILE_TYPE '/run/media'
where FILE_TYPE is one of the following: abrt_var_cache_t, accountsd_var_lib_t, auth_cache_t, auth_home_t, cache_home_t, cgroup_t, config_home_t, data_home_t, dbus_home_t, dbusd_etc_t, etc_t, faillog_t, fonts_cache_t, fonts_t, gconf_home_t, gkeyringd_gnome_home_t, gkeyringd_tmp_t, gnome_home_t, gnome_initial_setup_var_run_t, gstreamer_home_t, icc_data_home_t, lib_t, locale_t, mount_var_run_t, mozilla_plugin_tmp_t, mozilla_plugin_tmpfs_t, pam_var_run_t, systemd_logind_sessions_t, user_home_dir_t, user_tmp_t, usr_t, var_auth_t, var_lib_t, var_run_t, xdm_home_t, xdm_log_t, xdm_spool_t, xdm_tmpfs_t, xdm_var_lib_t, xdm_var_run_t, xkb_var_lib_t, xserver_log_t.
Then execute:
restorecon -v '/run/media'


*****  Plugin catchall (17.1 confidence) suggests   **************************

If you believe that gnome-session-b should be allowed watch access on the media directory by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c 'gnome-session-b' --raw | audit2allow -M my-gnomesessionb
# semodule -X 300 -i my-gnomesessionb.pp

Additional Information:
Source Context                system_u:system_r:xdm_t:s0-s0:c0.c1023
Target Context                system_u:object_r:mnt_t:s0
Target Objects                /run/media [ dir ]
Source                        gnome-session-b
Source Path                   gnome-session-b
Port                          <Unknown>
Host                          (removed)
Source RPM Packages           
Target RPM Packages           
SELinux Policy RPM            selinux-policy-targeted-41.34-1.fc41.noarch
Local Policy RPM              selinux-policy-targeted-41.34-1.fc41.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     (removed)
Platform                      Linux (removed) 6.13.7-200.fc41.x86_64 #1 SMP
                              PREEMPT_DYNAMIC Thu Mar 13 17:46:13 UTC 2025
                              x86_64
Alert Count                   218
First Seen                    2025-03-20 18:24:34 AEDT
Last Seen                     2025-03-22 10:21:32 AEDT
Local ID                      eed0d29e-66a2-4e28-849c-7ba9af40b352

Raw Audit Messages
type=AVC msg=audit(1742599292.479:670): avc:  denied  { watch } for  pid=20478 comm="gmain" path="/run/media" dev="tmpfs" ino=3601 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mnt_t:s0 tclass=dir permissive=0


Hash: gnome-session-b,xdm_t,mnt_t,dir,watch

Version-Release number of selected component:
selinux-policy-targeted-41.34-1.fc41.noarch

Additional info:
reporter:       libreport-2.17.15
package:        selinux-policy-targeted-41.34-1.fc41.noarch
component:      selinux-policy
hashmarkername: setroubleshoot
type:           libreport
kernel:         6.13.7-200.fc41.x86_64
reason:         SELinux is preventing gnome-session-b from 'watch' accesses on the directory /run/media. (excessive spam and notification spam as well, 20fps on the desktop on a 4070TI)
component:      selinux-policy

Comment 1 NO SPAM OR DIE... 2025-03-21 23:23:15 UTC
Created attachment 2081317 [details]
File: description

Comment 2 NO SPAM OR DIE... 2025-03-21 23:23:17 UTC
Created attachment 2081318 [details]
File: os_info

Comment 3 Fedora Update System 2025-05-02 08:11:28 UTC
FEDORA-2025-a84432e770 (selinux-policy-41.39-1.fc41) has been submitted as an update to Fedora 41.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-a84432e770

Comment 4 Fedora Update System 2025-05-03 03:03:31 UTC
FEDORA-2025-a84432e770 has been pushed to the Fedora 41 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-a84432e770`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-a84432e770

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2025-05-14 01:19:35 UTC
FEDORA-2025-a84432e770 (selinux-policy-41.39-1.fc41) has been pushed to the Fedora 41 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.