Fedora Account System
Red Hat Associate
Red Hat Customer
When I run the following command: run0 dnf install <some package> the dnf command immediately fails and SELinux Troubleshoot sends a notification saying that it prevented the command from running. I've tried fixing the selinux labels by runing sudo fixfiles -B onboot and then restarting to let everything get relabeled, but that did not solve the problem. I also encounter the same issue if I replace dnf with dnf5 in the run0 command. This worked the last time i was messing around with run0 back in November/December of last year (on F41). I also had this issue yesterday on F41 before I updated to F42. The issue persists on F42 as well. I've attached a pastebin with the details from SELinux Troubleshooter. Reproducible: Always Steps to Reproduce: 1.execute this command: run0 dnf install emacs (doesn't have to be emacs, can be any package) 2.command will exit immediately with non zero exit code 3.check selinux troubleshooter Actual Results: selinux prevents the dnf install command from running Expected Results: dnf installs emacs (or whatever package you asked it to install)
Next time, please add all details here. Especially do not scatter the data across third-party services. The linked SELinux Troubleshooter content was: SELinux is preventing (dnf4) from entrypoint access on the file /usr/bin/dnf5. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that (dnf4) should be allowed entrypoint access on the dnf5 file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c '(dnf4)' --raw | audit2allow -M my-dnf4 # semodule -X 300 -i my-dnf4.pp Additional Information: Source Context unconfined_u:unconfined_r:unconfined_t:s0- s0:c0.c1023 Target Context system_u:object_r:rpm_exec_t:s0 Target Objects /usr/bin/dnf5 [ file ] Source (dnf4) Source Path (dnf4) Port <Unknown> Host thinkpad Source RPM Packages Target RPM Packages dnf5-5.2.12.0-2.fc42.x86_64 SELinux Policy RPM selinux-policy-targeted-41.36-1.fc42.noarch Local Policy RPM selinux-policy-targeted-41.36-1.fc42.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name thinkpad Platform Linux thinkpad 6.14.2-300.fc42.x86_64 #1 SMP PREEMPT_DYNAMIC Thu Apr 10 21:50:55 UTC 2025 x86_64 Alert Count 10 First Seen 2025-01-30 11:23:28 EST Last Seen 2025-04-15 12:16:09 EDT Local ID e7f36bbb-2dee-4b9c-86e3-76e7994fa499 Raw Audit Messages type=AVC msg=audit(1744733769.238:318): avc: denied { entrypoint } for pid=12651 comm="(dnf)" path="/usr/bin/dnf5" dev="dm-0" ino=14053400 scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=system_u:object_r:rpm_exec_t:s0 tclass=file permissive=0 Hash: (dnf4),unconfined_t,rpm_exec_t,file,entrypoint
I confirm the issue. Here is a complete log from Fedora 43 (selinux-policy-41.37-1.fc43.noarch) for executing "run0 /usr/bin/dnf5 --help": dub 16 10:25:55 fedora-43 systemd[1]: Starting run-p9736-i9737.service - [run0] /usr/bin/dnf5 --help... dub 16 10:25:55 fedora-43 audit[9737]: USER_ACCT pid=9737 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='op=PAM:accounting grantors=pam_unix acct="root" exe="/usr/lib/systemd/systemd-executor" hostname=? addr=? terminal=/dev/pts/4 res=success' dub 16 10:25:55 fedora-43 kernel: kauditd_printk_skb: 1 callbacks suppressed dub 16 10:25:55 fedora-43 kernel: audit: type=1101 audit(1744791955.529:266): pid=9737 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='op=PAM:accounting grantors=pam_unix acct="root" exe="/usr/lib/systemd/systemd-executor" hostname=? addr=? terminal=/dev/pts/4 res=success' dub 16 10:25:55 fedora-43 audit[9737]: CRED_ACQ pid=9737 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='op=PAM:setcred grantors=? acct="root" exe="/usr/lib/systemd/systemd-executor" hostname=? addr=? terminal=/dev/pts/4 res=failed' dub 16 10:25:55 fedora-43 kernel: audit: type=1103 audit(1744791955.529:267): pid=9737 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='op=PAM:setcred grantors=? acct="root" exe="/usr/lib/systemd/systemd-executor" hostname=? addr=? terminal=/dev/pts/4 res=failed' dub 16 10:25:55 fedora-43 kernel: audit: type=2300 audit(1744791955.529:268): pid=9737 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='op=pam_selinux default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/lib/systemd/systemd-executor" hostname=? addr=? terminal=/dev/pts/4 res=success' dub 16 10:25:55 fedora-43 audit[9737]: USER_ROLE_CHANGE pid=9737 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='op=pam_selinux default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/lib/systemd/systemd-executor" hostname=? addr=? terminal=/dev/pts/4 res=success' dub 16 10:25:55 fedora-43 systemd-logind[806]: New session 7 of user root. dub 16 10:25:55 fedora-43 kernel: audit: type=1006 audit(1744791955.529:269): pid=9737 uid=0 subj=system_u:system_r:init_t:s0 old-auid=4294967295 auid=0 tty=pts4 old-ses=4294967295 ses=7 res=1 dub 16 10:25:55 fedora-43 kernel: audit: type=1300 audit(1744791955.529:269): arch=c000003e syscall=1 success=yes exit=1 a0=7 a1=7ffda7b35480 a2=1 a3=0 items=0 ppid=1 pid=9737 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts4 ses=7 comm="(dnf5)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null) dub 16 10:25:55 fedora-43 audit[9737]: SYSCALL arch=c000003e syscall=1 success=yes exit=1 a0=7 a1=7ffda7b35480 a2=1 a3=0 items=0 ppid=1 pid=9737 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts4 ses=7 comm="(dnf5)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null) dub 16 10:25:55 fedora-43 systemd[1]: Started session-7.scope - Session 7 of User root. dub 16 10:25:55 fedora-43 (dnf5)[9737]: pam_unix(systemd-run0:session): session opened for user root(uid=0) by root(uid=0) dub 16 10:25:55 fedora-43 kernel: audit: type=1327 audit(1744791955.529:269): proctitle="(dnf5)" dub 16 10:25:55 fedora-43 audit: PROCTITLE proctitle="(dnf5)" dub 16 10:25:55 fedora-43 (dnf5)[9737]: run-p9736-i9737.service: Failed to execute /usr/bin/dnf5: Permission denied dub 16 10:25:55 fedora-43 (dnf5)[9737]: run-p9736-i9737.service: Failed at step EXEC spawning /usr/bin/dnf5: Permission denied dub 16 10:25:55 fedora-43 audit[9737]: USER_START pid=9737 uid=0 auid=0 ses=7 subj=system_u:system_r:init_t:s0 msg='op=PAM:session_open grantors=pam_selinux,pam_selinux,pam_loginuid,pam_keyinit,pam_namespace,pam_systemd_home,pam_umask,pam_systemd,pam_unix acct="root" exe="/usr/lib/systemd/systemd-executor" hostname=? addr=? terminal=/dev/pts/4 res=success' dub 16 10:25:55 fedora-43 kernel: audit: type=1105 audit(1744791955.537:270): pid=9737 uid=0 auid=0 ses=7 subj=system_u:system_r:init_t:s0 msg='op=PAM:session_open grantors=pam_selinux,pam_selinux,pam_loginuid,pam_keyinit,pam_namespace,pam_systemd_home,pam_umask,pam_systemd,pam_unix acct="root" exe="/usr/lib/systemd/systemd-executor" hostname=? addr=? terminal=/dev/pts/4 res=success' dub 16 10:25:55 fedora-43 kernel: audit: type=1400 audit(1744791955.538:271): avc: denied { entrypoint } for pid=9737 comm="(dnf5)" path="/usr/bin/dnf5" dev="dm-0" ino=143884 scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=system_u:object_r:rpm_exec_t:s0 tclass=file permissive=0 dub 16 10:25:55 fedora-43 audit[9737]: AVC avc: denied { entrypoint } for pid=9737 comm="(dnf5)" path="/usr/bin/dnf5" dev="dm-0" ino=143884 scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=system_u:object_r:rpm_exec_t:s0 tclass=file permissive=0 dub 16 10:25:55 fedora-43 systemd[1]: run-p9736-i9737.service: Main process exited, code=exited, status=203/EXEC dub 16 10:25:55 fedora-43 kernel: audit: type=1300 audit(1744791955.538:271): arch=c000003e syscall=59 success=no exit=-13 a0=563c0610b110 a1=563c0610beb0 a2=563c0611a9a0 a3=0 items=0 ppid=1 pid=9737 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts4 ses=7 comm="(dnf5)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null) dub 16 10:25:55 fedora-43 audit[9737]: SYSCALL arch=c000003e syscall=59 success=no exit=-13 a0=563c0610b110 a1=563c0610beb0 a2=563c0611a9a0 a3=0 items=0 ppid=1 pid=9737 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts4 ses=7 comm="(dnf5)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null) dub 16 10:25:55 fedora-43 systemd[1]: run-p9736-i9737.service: Failed with result 'exit-code'. dub 16 10:25:55 fedora-43 systemd[1]: Failed to start run-p9736-i9737.service - [run0] /usr/bin/dnf5 --help. dub 16 10:25:55 fedora-43 kernel: audit: type=1327 audit(1744791955.538:271): proctitle="(dnf5)" dub 16 10:25:55 fedora-43 audit: PROCTITLE proctitle="(dnf5)" dub 16 10:25:55 fedora-43 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=run-p9736-i9737 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed' dub 16 10:25:55 fedora-43 systemd-logind[806]: Session 7 logged out. Waiting for processes to exit. dub 16 10:25:55 fedora-43 systemd[1]: session-7.scope: Deactivated successfully. dub 16 10:25:55 fedora-43 systemd-logind[806]: Removed session 7. Though I don't understand why unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 cannot entrypoint system_u:object_r:rpm_exec_t:s0 if I can do the same without "run0" tool as unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023.
The same issue is for "run0 /usr/bin/rpm --version". Maybe the intermediate with system_u:system_r:init_t has some kind of effect.
Moving to selinux-policy as I could not find anything interesting in the policy: # ls -Z /usr/bin/rpm system_u:object_r:rpm_exec_t:s0 /usr/bin/rpm root@fedora-43:~ # sesearch -T -t rpm_exec_t type_transition anaconda_t rpm_exec_t:process rpm_t; type_transition auditadm_sudo_t rpm_exec_t:process rpm_t; type_transition cloud_init_t rpm_exec_t:process rpm_t; type_transition cluster_t rpm_exec_t:process rpm_t; type_transition condor_startd_t rpm_exec_t:process rpm_t; type_transition crond_t rpm_exec_t:process rpm_t; type_transition dbadm_sudo_t rpm_exec_t:process rpm_t; type_transition glusterd_t rpm_exec_t:process rpm_t; type_transition init_t rpm_exec_t:process rpm_t; type_transition initrc_t rpm_exec_t:process rpm_t; type_transition insights_core_t rpm_exec_t:process rpm_t; type_transition kdumpctl_t rpm_exec_t:process rpm_t; type_transition openshift_initrc_t rpm_exec_t:process rpm_t; type_transition osad_t rpm_exec_t:process rpm_t; type_transition pegasus_t rpm_exec_t:process rpm_t; type_transition puppetagent_t rpm_exec_t:process rpm_t; type_transition rhcd_t rpm_exec_t:process rpm_t; type_transition rhnsd_t rpm_exec_t:process rpm_t; type_transition ricci_modrpm_t rpm_exec_t:process rpm_t; type_transition run_init_t rpm_exec_t:process rpm_t; type_transition secadm_sudo_t rpm_exec_t:process rpm_t; type_transition staff_sudo_t rpm_exec_t:process rpm_t; type_transition sysadm_sudo_t rpm_exec_t:process rpm_t; type_transition sysadm_t rpm_exec_t:process rpm_t; type_transition system_cronjob_t rpm_exec_t:process rpm_t; type_transition system_dbusd_t rpm_exec_t:process rpm_t; # sesearch -T -s unconfined_t |grep rpm type_transition unconfined_t rpmdb_exec_t:process rpmdb_t; type_transition unconfined_t var_lib_t:dir rpm_var_lib_t dnf; type_transition unconfined_t var_lib_t:dir rpm_var_lib_t rpm; type_transition unconfined_t var_lib_t:dir rpm_var_lib_t rpmrebuilddb; type_transition unconfined_t var_lib_t:dir rpm_var_lib_t yum; type_transition unconfined_t var_log_t:file rpm_log_t dnf.librepo.log; type_transition unconfined_t var_log_t:file rpm_log_t dnf.log; type_transition unconfined_t var_log_t:file rpm_log_t dnf.rpm.log; type_transition unconfined_t var_log_t:file rpm_log_t hawkey.log; type_transition unconfined_t var_log_t:file rpm_log_t up2date; type_transition unconfined_t var_log_t:file rpm_log_t yum.log; type_transition unconfined_t var_t:dir rpm_var_cache_t dnf; type_transition unconfined_t var_t:dir rpm_var_cache_t yum;
*** Bug 2375778 has been marked as a duplicate of this bug. ***
*** Bug 2346950 has been marked as a duplicate of this bug. ***
*** Bug 2400835 has been marked as a duplicate of this bug. ***
*** Bug 2406121 has been marked as a duplicate of this bug. ***
*** Bug 2375519 has been marked as a duplicate of this bug. ***
*** Bug 2393022 has been marked as a duplicate of this bug. ***
*** Bug 2392857 has been marked as a duplicate of this bug. ***
*** Bug 2421016 has been marked as a duplicate of this bug. ***
*** Bug 2424116 has been marked as a duplicate of this bug. ***
*** Bug 2405707 has been marked as a duplicate of this bug. ***
same bug 2405707 for `sudo run0 tmux` workaround: `sudo run0 sh -c tmux`
Still the case for F44 KDE Beta