Bug 2359828 - /usr/bin/run0 tool cannot execute programs in rpm_exec_t domain: avc: denied { entrypoint } scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=system_u:object_r:rpm_exec_t:s0 tclass=file
Summary: /usr/bin/run0 tool cannot execute programs in rpm_exec_t domain: avc: denied...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 43
Hardware: x86_64
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: jjanasek
QA Contact: Fedora Extras Quality Assurance
URL: https://pastebin.com/S4G2SkRN
Whiteboard: abrt_hash:2f90f6540e43d7c9e03713644d6...
: 2346950 2375519 2375778 2392857 2393022 2400835 2405707 2406121 2421016 2424116 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-04-15 18:30 UTC by skoved
Modified: 2026-08-12 13:23 UTC (History)
26 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:
jjanasek: mirror+


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github fedora-selinux selinux-policy issues 2500 0 None open `run0` is almost unusable. 2026-01-26 15:09:44 UTC
Red Hat Issue Tracker FC-2928 0 None None None 2026-01-09 09:56:18 UTC

Description skoved 2025-04-15 18:30:18 UTC
When I run the following command:

run0 dnf install <some package>

the dnf command immediately fails and SELinux Troubleshoot sends a notification saying that it prevented the command from running. I've tried fixing the selinux labels by runing

sudo fixfiles -B onboot

and then restarting to let everything get relabeled, but that did not solve the problem. I also encounter the same issue if I replace dnf with dnf5 in the run0 command. This worked the last time i was messing around with run0 back in November/December of last year (on F41). I also had this issue yesterday on F41 before I updated to F42. The issue persists on F42 as well. I've attached a pastebin with the details from SELinux Troubleshooter.

Reproducible: Always

Steps to Reproduce:
1.execute this command: run0 dnf install emacs (doesn't have to be emacs, can be any package)
2.command will exit immediately with non zero exit code
3.check selinux troubleshooter
Actual Results:
selinux prevents the dnf install command from running

Expected Results:
dnf installs emacs (or whatever package you asked it to install)

Comment 1 Petr Pisar 2025-04-16 08:16:44 UTC
Next time, please add all details here. Especially do not scatter the data across third-party services.

The linked SELinux Troubleshooter content was:


SELinux is preventing (dnf4) from entrypoint access on the file /usr/bin/dnf5.

*****  Plugin catchall (100. confidence) suggests   **************************

If you believe that (dnf4) should be allowed entrypoint access on the dnf5 file by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c '(dnf4)' --raw | audit2allow -M my-dnf4
# semodule -X 300 -i my-dnf4.pp

Additional Information:
Source Context                unconfined_u:unconfined_r:unconfined_t:s0-
                              s0:c0.c1023
Target Context                system_u:object_r:rpm_exec_t:s0
Target Objects                /usr/bin/dnf5 [ file ]
Source                        (dnf4)
Source Path                   (dnf4)
Port                          <Unknown>
Host                          thinkpad
Source RPM Packages           
Target RPM Packages           dnf5-5.2.12.0-2.fc42.x86_64
SELinux Policy RPM            selinux-policy-targeted-41.36-1.fc42.noarch
Local Policy RPM              selinux-policy-targeted-41.36-1.fc42.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     thinkpad
Platform                      Linux thinkpad
                              6.14.2-300.fc42.x86_64 #1 SMP PREEMPT_DYNAMIC Thu
                              Apr 10 21:50:55 UTC 2025 x86_64
Alert Count                   10
First Seen                    2025-01-30 11:23:28 EST
Last Seen                     2025-04-15 12:16:09 EDT
Local ID                      e7f36bbb-2dee-4b9c-86e3-76e7994fa499

Raw Audit Messages
type=AVC msg=audit(1744733769.238:318): avc:  denied  { entrypoint } for  pid=12651 comm="(dnf)" path="/usr/bin/dnf5" dev="dm-0" ino=14053400 scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=system_u:object_r:rpm_exec_t:s0 tclass=file permissive=0


Hash: (dnf4),unconfined_t,rpm_exec_t,file,entrypoint

Comment 2 Petr Pisar 2025-04-16 09:01:05 UTC
I confirm the issue. Here is a complete log from Fedora 43 (selinux-policy-41.37-1.fc43.noarch) for executing "run0 /usr/bin/dnf5 --help":

dub 16 10:25:55 fedora-43 systemd[1]: Starting run-p9736-i9737.service - [run0] /usr/bin/dnf5 --help...
dub 16 10:25:55 fedora-43 audit[9737]: USER_ACCT pid=9737 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='op=PAM:accounting grantors=pam_unix acct="root" exe="/usr/lib/systemd/systemd-executor" hostname=? addr=? terminal=/dev/pts/4 res=success'
dub 16 10:25:55 fedora-43 kernel: kauditd_printk_skb: 1 callbacks suppressed
dub 16 10:25:55 fedora-43 kernel: audit: type=1101 audit(1744791955.529:266): pid=9737 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='op=PAM:accounting grantors=pam_unix acct="root" exe="/usr/lib/systemd/systemd-executor" hostname=? addr=? terminal=/dev/pts/4 res=success'
dub 16 10:25:55 fedora-43 audit[9737]: CRED_ACQ pid=9737 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='op=PAM:setcred grantors=? acct="root" exe="/usr/lib/systemd/systemd-executor" hostname=? addr=? terminal=/dev/pts/4 res=failed'
dub 16 10:25:55 fedora-43 kernel: audit: type=1103 audit(1744791955.529:267): pid=9737 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='op=PAM:setcred grantors=? acct="root" exe="/usr/lib/systemd/systemd-executor" hostname=? addr=? terminal=/dev/pts/4 res=failed'
dub 16 10:25:55 fedora-43 kernel: audit: type=2300 audit(1744791955.529:268): pid=9737 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='op=pam_selinux default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/lib/systemd/systemd-executor" hostname=? addr=? terminal=/dev/pts/4 res=success'
dub 16 10:25:55 fedora-43 audit[9737]: USER_ROLE_CHANGE pid=9737 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='op=pam_selinux default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/lib/systemd/systemd-executor" hostname=? addr=? terminal=/dev/pts/4 res=success'
dub 16 10:25:55 fedora-43 systemd-logind[806]: New session 7 of user root.
dub 16 10:25:55 fedora-43 kernel: audit: type=1006 audit(1744791955.529:269): pid=9737 uid=0 subj=system_u:system_r:init_t:s0 old-auid=4294967295 auid=0 tty=pts4 old-ses=4294967295 ses=7 res=1
dub 16 10:25:55 fedora-43 kernel: audit: type=1300 audit(1744791955.529:269): arch=c000003e syscall=1 success=yes exit=1 a0=7 a1=7ffda7b35480 a2=1 a3=0 items=0 ppid=1 pid=9737 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts4 ses=7 comm="(dnf5)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null)
dub 16 10:25:55 fedora-43 audit[9737]: SYSCALL arch=c000003e syscall=1 success=yes exit=1 a0=7 a1=7ffda7b35480 a2=1 a3=0 items=0 ppid=1 pid=9737 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts4 ses=7 comm="(dnf5)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null)
dub 16 10:25:55 fedora-43 systemd[1]: Started session-7.scope - Session 7 of User root.
dub 16 10:25:55 fedora-43 (dnf5)[9737]: pam_unix(systemd-run0:session): session opened for user root(uid=0) by root(uid=0)
dub 16 10:25:55 fedora-43 kernel: audit: type=1327 audit(1744791955.529:269): proctitle="(dnf5)"
dub 16 10:25:55 fedora-43 audit: PROCTITLE proctitle="(dnf5)"
dub 16 10:25:55 fedora-43 (dnf5)[9737]: run-p9736-i9737.service: Failed to execute /usr/bin/dnf5: Permission denied
dub 16 10:25:55 fedora-43 (dnf5)[9737]: run-p9736-i9737.service: Failed at step EXEC spawning /usr/bin/dnf5: Permission denied
dub 16 10:25:55 fedora-43 audit[9737]: USER_START pid=9737 uid=0 auid=0 ses=7 subj=system_u:system_r:init_t:s0 msg='op=PAM:session_open grantors=pam_selinux,pam_selinux,pam_loginuid,pam_keyinit,pam_namespace,pam_systemd_home,pam_umask,pam_systemd,pam_unix acct="root" exe="/usr/lib/systemd/systemd-executor" hostname=? addr=? terminal=/dev/pts/4 res=success'
dub 16 10:25:55 fedora-43 kernel: audit: type=1105 audit(1744791955.537:270): pid=9737 uid=0 auid=0 ses=7 subj=system_u:system_r:init_t:s0 msg='op=PAM:session_open grantors=pam_selinux,pam_selinux,pam_loginuid,pam_keyinit,pam_namespace,pam_systemd_home,pam_umask,pam_systemd,pam_unix acct="root" exe="/usr/lib/systemd/systemd-executor" hostname=? addr=? terminal=/dev/pts/4 res=success'
dub 16 10:25:55 fedora-43 kernel: audit: type=1400 audit(1744791955.538:271): avc:  denied  { entrypoint } for  pid=9737 comm="(dnf5)" path="/usr/bin/dnf5" dev="dm-0" ino=143884 scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=system_u:object_r:rpm_exec_t:s0 tclass=file permissive=0
dub 16 10:25:55 fedora-43 audit[9737]: AVC avc:  denied  { entrypoint } for  pid=9737 comm="(dnf5)" path="/usr/bin/dnf5" dev="dm-0" ino=143884 scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=system_u:object_r:rpm_exec_t:s0 tclass=file permissive=0
dub 16 10:25:55 fedora-43 systemd[1]: run-p9736-i9737.service: Main process exited, code=exited, status=203/EXEC
dub 16 10:25:55 fedora-43 kernel: audit: type=1300 audit(1744791955.538:271): arch=c000003e syscall=59 success=no exit=-13 a0=563c0610b110 a1=563c0610beb0 a2=563c0611a9a0 a3=0 items=0 ppid=1 pid=9737 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts4 ses=7 comm="(dnf5)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null)
dub 16 10:25:55 fedora-43 audit[9737]: SYSCALL arch=c000003e syscall=59 success=no exit=-13 a0=563c0610b110 a1=563c0610beb0 a2=563c0611a9a0 a3=0 items=0 ppid=1 pid=9737 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts4 ses=7 comm="(dnf5)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null)
dub 16 10:25:55 fedora-43 systemd[1]: run-p9736-i9737.service: Failed with result 'exit-code'.
dub 16 10:25:55 fedora-43 systemd[1]: Failed to start run-p9736-i9737.service - [run0] /usr/bin/dnf5 --help.
dub 16 10:25:55 fedora-43 kernel: audit: type=1327 audit(1744791955.538:271): proctitle="(dnf5)"
dub 16 10:25:55 fedora-43 audit: PROCTITLE proctitle="(dnf5)"
dub 16 10:25:55 fedora-43 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=run-p9736-i9737 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed'
dub 16 10:25:55 fedora-43 systemd-logind[806]: Session 7 logged out. Waiting for processes to exit.
dub 16 10:25:55 fedora-43 systemd[1]: session-7.scope: Deactivated successfully.
dub 16 10:25:55 fedora-43 systemd-logind[806]: Removed session 7.

Though I don't understand why unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 cannot entrypoint system_u:object_r:rpm_exec_t:s0 if I can do the same without "run0" tool as unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023.

Comment 3 Petr Pisar 2025-04-16 09:05:48 UTC
The same issue is for "run0 /usr/bin/rpm --version". Maybe the intermediate with system_u:system_r:init_t has some kind of effect.

Comment 4 Petr Pisar 2025-04-16 10:14:48 UTC
Moving to selinux-policy as I could not find anything interesting in the policy:

# ls -Z /usr/bin/rpm
system_u:object_r:rpm_exec_t:s0 /usr/bin/rpm
root@fedora-43:~ # sesearch -T -t rpm_exec_t
type_transition anaconda_t rpm_exec_t:process rpm_t;
type_transition auditadm_sudo_t rpm_exec_t:process rpm_t;
type_transition cloud_init_t rpm_exec_t:process rpm_t;
type_transition cluster_t rpm_exec_t:process rpm_t;
type_transition condor_startd_t rpm_exec_t:process rpm_t;
type_transition crond_t rpm_exec_t:process rpm_t;
type_transition dbadm_sudo_t rpm_exec_t:process rpm_t;
type_transition glusterd_t rpm_exec_t:process rpm_t;
type_transition init_t rpm_exec_t:process rpm_t;
type_transition initrc_t rpm_exec_t:process rpm_t;
type_transition insights_core_t rpm_exec_t:process rpm_t;
type_transition kdumpctl_t rpm_exec_t:process rpm_t;
type_transition openshift_initrc_t rpm_exec_t:process rpm_t;
type_transition osad_t rpm_exec_t:process rpm_t;
type_transition pegasus_t rpm_exec_t:process rpm_t;
type_transition puppetagent_t rpm_exec_t:process rpm_t;
type_transition rhcd_t rpm_exec_t:process rpm_t;
type_transition rhnsd_t rpm_exec_t:process rpm_t;
type_transition ricci_modrpm_t rpm_exec_t:process rpm_t;
type_transition run_init_t rpm_exec_t:process rpm_t;
type_transition secadm_sudo_t rpm_exec_t:process rpm_t;
type_transition staff_sudo_t rpm_exec_t:process rpm_t;
type_transition sysadm_sudo_t rpm_exec_t:process rpm_t;
type_transition sysadm_t rpm_exec_t:process rpm_t;
type_transition system_cronjob_t rpm_exec_t:process rpm_t;
type_transition system_dbusd_t rpm_exec_t:process rpm_t;

# sesearch -T -s unconfined_t |grep rpm
type_transition unconfined_t rpmdb_exec_t:process rpmdb_t;
type_transition unconfined_t var_lib_t:dir rpm_var_lib_t dnf;
type_transition unconfined_t var_lib_t:dir rpm_var_lib_t rpm;
type_transition unconfined_t var_lib_t:dir rpm_var_lib_t rpmrebuilddb;
type_transition unconfined_t var_lib_t:dir rpm_var_lib_t yum;
type_transition unconfined_t var_log_t:file rpm_log_t dnf.librepo.log;
type_transition unconfined_t var_log_t:file rpm_log_t dnf.log;
type_transition unconfined_t var_log_t:file rpm_log_t dnf.rpm.log;
type_transition unconfined_t var_log_t:file rpm_log_t hawkey.log;
type_transition unconfined_t var_log_t:file rpm_log_t up2date;
type_transition unconfined_t var_log_t:file rpm_log_t yum.log;
type_transition unconfined_t var_t:dir rpm_var_cache_t dnf;
type_transition unconfined_t var_t:dir rpm_var_cache_t yum;

Comment 5 Marcus Müller 2025-09-03 10:13:22 UTC
*** Bug 2375778 has been marked as a duplicate of this bug. ***

Comment 6 Marcus Müller 2025-09-03 10:14:04 UTC
*** Bug 2346950 has been marked as a duplicate of this bug. ***

Comment 7 jjanasek 2025-12-17 10:53:05 UTC
*** Bug 2400835 has been marked as a duplicate of this bug. ***

Comment 8 jjanasek 2025-12-17 10:54:38 UTC
*** Bug 2406121 has been marked as a duplicate of this bug. ***

Comment 9 jjanasek 2025-12-17 10:54:48 UTC
*** Bug 2375519 has been marked as a duplicate of this bug. ***

Comment 10 jjanasek 2025-12-19 08:33:58 UTC
*** Bug 2393022 has been marked as a duplicate of this bug. ***

Comment 11 jjanasek 2025-12-19 08:34:11 UTC
*** Bug 2392857 has been marked as a duplicate of this bug. ***

Comment 12 jjanasek 2025-12-19 08:34:14 UTC
*** Bug 2421016 has been marked as a duplicate of this bug. ***

Comment 13 jjanasek 2026-01-09 07:31:00 UTC
*** Bug 2424116 has been marked as a duplicate of this bug. ***

Comment 14 Tomas Dolezal 2026-01-26 15:07:34 UTC
*** Bug 2405707 has been marked as a duplicate of this bug. ***

Comment 15 Tomas Dolezal 2026-01-26 15:09:44 UTC
same bug 2405707 for
`sudo run0 tmux`
workaround: `sudo run0 sh -c tmux`

Comment 16 Gurenko Alex 2026-03-30 09:03:56 UTC
Still the case for F44 KDE Beta


Note You need to log in before you can comment on or make changes to this bug.