Bug 2376018 - SELinux is preventing (sd-parse-elf) from 'mounton' accesses on the directory /.
Summary: SELinux is preventing (sd-parse-elf) from 'mounton' accesses on the directory /.
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 42
Hardware: x86_64
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:c662b47b0e8e5ad6f4d20b92bd8...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-07-03 03:51 UTC by shanehowe1109
Modified: 2025-07-22 01:11 UTC (History)
8 users (show)

Fixed In Version: selinux-policy-42.1-1.fc42
Clone Of:
Environment:
Last Closed: 2025-07-16 21:58:02 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
File: os_info (767 bytes, text/plain)
2025-07-03 03:51 UTC, shanehowe1109
no flags Details
File: description (1.91 KB, text/plain)
2025-07-03 03:51 UTC, shanehowe1109
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Github fedora-selinux selinux-policy pull 2765 0 None open Allow systemd-coredump mount on tmpfs filesystems 2025-07-08 11:22:53 UTC

Description shanehowe1109 2025-07-03 03:51:39 UTC
Description of problem:
SELinux is preventing (sd-parse-elf) from 'mounton' accesses on the directory /.

*****  Plugin catchall (100. confidence) suggests   **************************

If you believe that (sd-parse-elf) should be allowed mounton access on the  directory by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c '(sd-parse-elf)' --raw | audit2allow -M my-sdparseelf
# semodule -X 300 -i my-sdparseelf.pp

Additional Information:
Source Context                system_u:system_r:systemd_coredump_t:s0
Target Context                system_u:object_r:tmpfs_t:s0
Target Objects                / [ dir ]
Source                        (sd-parse-elf)
Source Path                   (sd-parse-elf)
Port                          <Unknown>
Host                          (removed)
Source RPM Packages           
Target RPM Packages           
SELinux Policy RPM            selinux-policy-targeted-41.34-1.fc42.noarch
Local Policy RPM              selinux-policy-targeted-41.34-1.fc42.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     (removed)
Platform                      Linux (removed) 6.14.0-63.fc42.x86_64 #1 SMP
                              PREEMPT_DYNAMIC Mon Mar 24 19:53:37 UTC 2025
                              x86_64
Alert Count                   1
First Seen                    2025-07-03 03:41:03 UTC
Last Seen                     2025-07-03 03:41:03 UTC
Local ID                      9b8d73cf-1d57-44e6-9d5a-33ac6e76b559

Raw Audit Messages
type=AVC msg=audit(1751514063.987:201): avc:  denied  { mounton } for  pid=4828 comm="(sd-parse-elf)" path="/" dev="overlay" ino=2 scontext=system_u:system_r:systemd_coredump_t:s0 tcontext=system_u:object_r:tmpfs_t:s0 tclass=dir permissive=0


Hash: (sd-parse-elf),systemd_coredump_t,tmpfs_t,dir,mounton

Version-Release number of selected component:
selinux-policy-targeted-41.34-1.fc42.noarch

Additional info:
reporter:       libreport-2.17.15
kernel:         6.14.0-63.fc42.x86_64
type:           libreport
hashmarkername: setroubleshoot
component:      selinux-policy
package:        selinux-policy-targeted-41.34-1.fc42.noarch
reason:         SELinux is preventing (sd-parse-elf) from 'mounton' accesses on the directory /.
component:      selinux-policy

Comment 1 shanehowe1109 2025-07-03 03:51:42 UTC
Created attachment 2096001 [details]
File: os_info

Comment 2 shanehowe1109 2025-07-03 03:51:44 UTC
Created attachment 2096002 [details]
File: description

Comment 3 Zdenek Pytela 2025-07-08 11:22:53 UTC
Hi,

Is there any special setup needed to trigger this denial?

Comment 4 Fedora Update System 2025-07-15 14:58:38 UTC
FEDORA-2025-42c191342a (selinux-policy-42.1-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-42c191342a

Comment 5 Fedora Update System 2025-07-16 01:40:46 UTC
FEDORA-2025-42c191342a has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-42c191342a`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-42c191342a

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 shanehowe1109 2025-07-16 21:58:02 UTC
Sorry for the wait in response. I am unsure how it can be triggered. I am currently learning more about basic tasks from the Linux Bible and trying to absorb as much as possible. My laptop lost power and the issue happened after rebooting when I had restarted the machine. A further restart seemed to solve the issue. Thank you.

Comment 7 Fedora Update System 2025-07-22 01:11:44 UTC
FEDORA-2025-42c191342a (selinux-policy-42.1-1.fc42) has been pushed to the Fedora 42 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.