Fedora Account System
Red Hat Associate
Red Hat Customer
After Fedora CoreOS automatically upgraded to 42.20251012.3.0, SSH passthrough to a Forgejo container no longer worked. Reverting to the previous version, 42.20250929.3.0, continues to work. CoreOS 42.20251012.3.0 includes an update for the selinux-policy packages: selinux-policy-42.9-1.fc42.noarch ⟶ 42.12-1.fc42.noarch selinux-policy-targeted-42.9-1.fc42.noarch ⟶ 42.12-1.fc42.noarch selinux-policy-targeted 42.10 contains a commit to use sshd_session_t for the SSH sessions while previously it seems the sessions were labeled sshd_t. That appears to break the sshd_launch_containers boolean from working. Reproducible: Always Steps to Reproduce: 1. ssh -T git Actual Results: git: Permission denied (publickey,gssapi-keyex,gssapi-with-mic). Expected Results: Hi there, <name>! You've successfully authenticated with the key named <keyname>, but Forgejo does not provide shell access.
I guess the policy behind sshd_launch_containers should rather be in selinux-policy. Anyway, can you show audit log entries or journal?
Here's what's in the journal during the failure. Oct 29 17:55:22 ikonicre audit[1822]: CRYPTO_KEY_USER pid=1822 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:9b:b3:58:8f:96:b9:77:fd:b6:88:39:0c:3e:39:88:07:9a:8f:4c:4d:0e:9f:ed:b5:e0:cf:c1:0d:16:9e:26:da direction=? spid=1822 suid=0 exe="/usr/libexec/openssh/sshd-session" hostname=? addr=10.1.1.93 terminal=? res=success' Oct 29 17:55:22 ikonicre audit[1822]: CRYPTO_KEY_USER pid=1822 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:79:8b:3a:d5:8f:ae:c8:f2:48:cd:c5:8e:70:2c:77:a6:03:04:11:be:ab:a9:71:d2:45:2a:65:c9:2d:91:94:72 direction=? spid=1822 suid=0 exe="/usr/libexec/openssh/sshd-session" hostname=? addr=10.1.1.93 terminal=? res=success' Oct 29 17:55:22 ikonicre audit[1822]: CRYPTO_KEY_USER pid=1822 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:41:d6:ef:e2:57:2e:4b:e6:f7:26:83:e2:0c:dd:08:ae:86:b7:9b:b0:85:cd:ba:ce:bc:4d:67:1b:96:2a:9d:ad direction=? spid=1822 suid=0 exe="/usr/libexec/openssh/sshd-session" hostname=? addr=10.1.1.93 terminal=? res=success' Oct 29 17:55:22 ikonicre audit[1821]: CRYPTO_SESSION pid=1821 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes256-gcm ksize=256 mac=<implicit> pfs=curve25519-sha256 spid=1822 suid=74 rport=53360 laddr=10.1.1.7 lport=22 exe="/usr/libexec/openssh/sshd-session" hostname=? addr=10.1.1.93 terminal=? res=success' Oct 29 17:55:22 ikonicre audit[1821]: CRYPTO_SESSION pid=1821 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes256-gcm ksize=256 mac=<implicit> pfs=curve25519-sha256 spid=1822 suid=74 rport=53360 laddr=10.1.1.7 lport=22 exe="/usr/libexec/openssh/sshd-session" hostname=? addr=10.1.1.93 terminal=? res=success' Oct 29 17:55:22 ikonicre audit[1824]: AVC avc: denied { execute } for pid=1824 comm="forgejo-keys" name="podman" dev="overlay" ino=4194 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:container_runtime_exec_t:s0 tclass=file permissive=1 Oct 29 17:55:22 ikonicre audit[1824]: AVC avc: denied { read open } for pid=1824 comm="forgejo-keys" path="/usr/bin/podman" dev="overlay" ino=4194 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:container_runtime_exec_t:s0 tclass=file permissive=1 Oct 29 17:55:22 ikonicre audit[1824]: AVC avc: denied { execute_no_trans } for pid=1824 comm="forgejo-keys" path="/usr/bin/podman" dev="overlay" ino=4194 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:container_runtime_exec_t:s0 tclass=file permissive=1 Oct 29 17:55:22 ikonicre audit[1824]: AVC avc: denied { map } for pid=1824 comm="podman" path="/usr/bin/podman" dev="overlay" ino=4194 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:container_runtime_exec_t:s0 tclass=file permissive=1 Oct 29 17:55:22 ikonicre audit[1824]: AVC avc: denied { getattr } for pid=1824 comm="podman" path="/run/user/1002/bus" dev="tmpfs" ino=22 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:session_dbusd_tmp_t:s0 tclass=sock_file permissive=1 Oct 29 17:55:22 ikonicre audit[1824]: AVC avc: denied { read } for pid=1824 comm="podman" path="/run/log/journal" dev="tmpfs" ino=76 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:syslogd_var_run_t:s0 tclass=dir permissive=1 Oct 29 17:55:22 ikonicre audit[1824]: AVC avc: denied { write } for pid=1824 comm="podman" name="db.sql" dev="nvme0n1p1" ino=315332 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:data_home_t:s0 tclass=file permissive=1 Oct 29 17:55:22 ikonicre audit[1824]: AVC avc: denied { read write } for pid=1824 comm="podman" name="libpod_rootless_lock_1002" dev="tmpfs" ino=3 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:container_runtime_tmpfs_t:s0 tclass=file permissive=1 Oct 29 17:55:22 ikonicre audit[1824]: AVC avc: denied { open } for pid=1824 comm="podman" path="/dev/shm/libpod_rootless_lock_1002" dev="tmpfs" ino=3 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:container_runtime_tmpfs_t:s0 tclass=file permissive=1 Oct 29 17:55:22 ikonicre audit[1824]: AVC avc: denied { map } for pid=1824 comm="podman" path="/dev/shm/libpod_rootless_lock_1002" dev="tmpfs" ino=3 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:container_runtime_tmpfs_t:s0 tclass=file permissive=1 Oct 29 17:55:23 ikonicre audit[1824]: AVC avc: denied { getattr } for pid=1824 comm="podman" path="/run/systemd/system" dev="tmpfs" ino=3 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:systemd_unit_file_t:s0 tclass=dir permissive=1 Oct 29 17:55:23 ikonicre audit[1824]: AVC avc: denied { signull } for pid=1824 comm="podman" scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:unconfined_r:container_runtime_t:s0-s0:c0.c1023 tclass=process permissive=1 Oct 29 17:55:23 ikonicre audit[1824]: AVC avc: denied { sys_ptrace } for pid=1824 comm="podman" capability=19 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tclass=cap_userns permissive=1 Oct 29 17:55:23 ikonicre audit[1824]: AVC avc: denied { read } for pid=1824 comm="podman" dev="nsfs" ino=4026532663 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:nsfs_t:s0 tclass=file permissive=1 Oct 29 17:55:23 ikonicre audit[1824]: AVC avc: denied { open } for pid=1824 comm="podman" path="user:[4026532663]" dev="nsfs" ino=4026532663 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:nsfs_t:s0 tclass=file permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { sys_admin } for pid=1834 comm="podman" capability=21 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tclass=cap_userns permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { sys_chroot } for pid=1834 comm="podman" capability=18 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tclass=cap_userns permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { mounton } for pid=1834 comm="exe" path="/var/home/git/.local/share/containers/storage/overlay" dev="nvme0n1p1" ino=1610764289 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:container_ro_file_t:s0 tclass=dir permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { write } for pid=1834 comm="exe" name="images.lock" dev="nvme0n1p1" ino=315367 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:container_ro_file_t:s0 tclass=file permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { write } for pid=1834 comm="exe" name="bus" dev="tmpfs" ino=22 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:session_dbusd_tmp_t:s0 tclass=sock_file permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { connectto } for pid=1834 comm="exe" path="/run/user/1002/bus" scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:unconfined_r:unconfined_dbusd_t:s0-s0:c0.c1023 tclass=unix_stream_socket permissive=1 Oct 29 17:55:23 ikonicre systemd[1302]: selinux: avc: denied { start } for auid=n/a uid=1002 gid=1002 cmdline="/usr/bin/podman exec forgejo /usr/local/bin/forgejo keys -e git -u git -t ssh-ed25519 -k AAAAC..." function="method_start_transient_unit" scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tclass=system permissive=1 Oct 29 17:55:23 ikonicre systemd[1302]: Started podman-1834.scope. Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { add_name } for pid=1834 comm="exe" name="db.sql-journal" scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:data_home_t:s0 tclass=dir permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { create } for pid=1834 comm="exe" name="db.sql-journal" scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=file permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { write } for pid=1834 comm="exe" path="/var/home/git/.local/share/containers/storage/db.sql-journal" dev="nvme0n1p1" ino=5798365 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=file permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { setattr } for pid=1834 comm="exe" name="db.sql-journal" dev="nvme0n1p1" ino=5798365 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=file permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { remove_name } for pid=1834 comm="exe" name="db.sql-journal" dev="nvme0n1p1" ino=5798365 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:data_home_t:s0 tclass=dir permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { unlink } for pid=1834 comm="exe" name="db.sql-journal" dev="nvme0n1p1" ino=5798365 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=file permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { create } for pid=1834 comm="exe" name="25392b7e3d55de8854d09a29572aa574b05851247d372f6817ff664fd2298e9c" scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=dir permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { add_name } for pid=1834 comm="exe" name="exit" scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=dir permissive=1 Oct 29 17:55:23 ikonicre audit[1846]: AVC avc: denied { setpgid } for pid=1846 comm="exe" scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tclass=process permissive=1 Oct 29 17:55:23 ikonicre audit[1846]: AVC avc: denied { execute } for pid=1846 comm="exe" name="conmon" dev="overlay" ino=1581 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:conmon_exec_t:s0 tclass=file permissive=1 Oct 29 17:55:23 ikonicre audit[1846]: AVC avc: denied { read open } for pid=1846 comm="exe" path="/usr/bin/conmon" dev="overlay" ino=1581 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:conmon_exec_t:s0 tclass=file permissive=1 Oct 29 17:55:23 ikonicre audit[1846]: AVC avc: denied { execute_no_trans } for pid=1846 comm="exe" path="/usr/bin/conmon" dev="overlay" ino=1581 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:conmon_exec_t:s0 tclass=file permissive=1 Oct 29 17:55:23 ikonicre audit[1846]: AVC avc: denied { map } for pid=1846 comm="conmon" path="/usr/bin/conmon" dev="overlay" ino=1581 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:conmon_exec_t:s0 tclass=file permissive=1 Oct 29 17:55:23 ikonicre audit[1847]: AVC avc: denied { create } for pid=1847 comm="conmon" name="attach" scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=sock_file permissive=1 Oct 29 17:55:23 ikonicre audit[1847]: AVC avc: denied { setattr } for pid=1847 comm="conmon" name="attach" dev="nvme0n1p1" ino=1075818409 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=sock_file permissive=1 Oct 29 17:55:23 ikonicre audit[1847]: AVC avc: denied { create } for pid=1847 comm="conmon" name="ctl" scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=fifo_file permissive=1 Oct 29 17:55:23 ikonicre audit[1847]: AVC avc: denied { read } for pid=1847 comm="conmon" name="ctl" dev="nvme0n1p1" ino=1075818410 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=fifo_file permissive=1 Oct 29 17:55:23 ikonicre audit[1847]: AVC avc: denied { open } for pid=1847 comm="conmon" path="/var/home/git/.local/share/containers/storage/overlay-containers/96b85c7e646a7ce7ca73c649d2e2419dc7d8fac32e05584415a7f5a426567c91/userdata/25392b7e3d55de8854d09a29572aa574b05851247d372f6817ff664fd2298e9c/ctl" dev="nvme0n1p1" ino=1075818410 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=fifo_file permissive=1 Oct 29 17:55:23 ikonicre audit[1847]: AVC avc: denied { write } for pid=1847 comm="conmon" name="ctl" dev="nvme0n1p1" ino=1075818410 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=fifo_file permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { write } for pid=1834 comm="exe" name="attach" dev="nvme0n1p1" ino=1075818409 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=sock_file permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { connectto } for pid=1834 comm="exe" path="/var/home/git/.local/share/containers/storage/overlay-containers/96b85c7e646a7ce7ca73c649d2e2419dc7d8fac32e05584415a7f5a426567c91/userdata/25392b7e3d55de8854d09a29572aa574b05851247d372f6817ff664fd2298e9c/attach" scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tclass=unix_stream_socket permissive=1 Oct 29 17:55:23 ikonicre audit[1848]: AVC avc: denied { append } for pid=1848 comm="crun" path="/var/home/git/.local/share/containers/storage/overlay-containers/96b85c7e646a7ce7ca73c649d2e2419dc7d8fac32e05584415a7f5a426567c91/userdata/25392b7e3d55de8854d09a29572aa574b05851247d372f6817ff664fd2298e9c/oci-log" dev="nvme0n1p1" ino=1075818412 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=file permissive=1 Oct 29 17:55:23 ikonicre audit[1848]: AVC avc: denied { kill } for pid=1848 comm="crun" capability=5 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tclass=cap_userns permissive=1 Oct 29 17:55:23 ikonicre audit[1848]: AVC avc: denied { signull } for pid=1848 comm="crun" scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:system_r:container_t:s0:c4,c904 tclass=process permissive=1 Oct 29 17:55:23 ikonicre audit[1849]: AVC avc: denied { sys_admin } for pid=1849 comm="crun" capability=21 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tclass=cap_userns permissive=1 Oct 29 17:55:23 ikonicre audit[1849]: AVC avc: denied { sys_chroot } for pid=1849 comm="crun" capability=18 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tclass=cap_userns permissive=1 Oct 29 17:55:23 ikonicre audit[1850]: AVC avc: denied { read } for pid=1850 comm="crun" name="forgejo" dev="overlay" ino=537451342 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:container_file_t:s0:c4,c904 tclass=lnk_file permissive=1 Oct 29 17:55:23 ikonicre audit[1850]: AVC avc: denied { execute } for pid=1850 comm="crun" name="gitea" dev="overlay" ino=537451337 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:container_file_t:s0:c4,c904 tclass=file permissive=1 Oct 29 17:55:23 ikonicre audit[1850]: AVC avc: denied { setgid } for pid=1850 comm="crun" capability=6 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tclass=cap_userns permissive=1 Oct 29 17:55:23 ikonicre audit[1850]: AVC avc: denied { chown } for pid=1850 comm="crun" capability=0 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tclass=cap_userns permissive=1 Oct 29 17:55:23 ikonicre audit[1850]: AVC avc: denied { setpcap } for pid=1850 comm="crun" capability=8 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tclass=cap_userns permissive=1 Oct 29 17:55:23 ikonicre audit[1850]: AVC avc: denied { setuid } for pid=1850 comm="crun" capability=7 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tclass=cap_userns permissive=1 Oct 29 17:55:23 ikonicre audit[1850]: AVC avc: denied { transition } for pid=1850 comm="crun" path="/usr/local/bin/gitea" dev="overlay" ino=537451337 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:system_r:container_t:s0:c4,c904 tclass=process permissive=1 Oct 29 17:55:23 ikonicre audit[1850]: AVC avc: denied { write } for pid=1850 comm="forgejo" path="pipe:[15326]" dev="pipefs" ino=15326 scontext=system_u:system_r:container_t:s0:c4,c904 tcontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tclass=fifo_file permissive=0 Oct 29 17:55:23 ikonicre audit[1850]: AVC avc: denied { write } for pid=1850 comm="forgejo" path="pipe:[15327]" dev="pipefs" ino=15327 scontext=system_u:system_r:container_t:s0:c4,c904 tcontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tclass=fifo_file permissive=0 Oct 29 17:55:23 ikonicre podman[1834]: 2025-10-29 17:55:23.099638315 -0400 EDT m=+0.089954740 container exec 96b85c7e646a7ce7ca73c649d2e2419dc7d8fac32e05584415a7f5a426567c91 (image=codeberg.org/forgejo/forgejo:12-rootless, name=forgejo, PODMAN_SYSTEMD_UNIT=forgejo.service, org.opencontainers.image.authors=Forgejo, org.opencontainers.image.licenses=GPL-3.0-or-later, org.opencontainers.image.title=Forgejo. Beyond coding. We forge., maintainer=contact, org.opencontainers.image.documentation=https://forgejo.org/download/#container-image, org.opencontainers.image.version=12.0.4, io.containers.autoupdate=registry, org.opencontainers.image.description=Forgejo is a self-hosted lightweight software forge. Easy to install and low maintenance, it just does the job., org.opencontainers.image.url=https://forgejo.org, org.opencontainers.image.source=https://codeberg.org/forgejo/forgejo, org.opencontainers.image.vendor=Forgejo) Oct 29 17:55:23 ikonicre forgejo[1419]: 2025/10/29 17:55:23 ...eb/routing/logger.go:102:func1() [I] router: completed POST /api/internal/ssh/authorized_keys for 127.0.0.1:0, 200 OK in 0.6ms @ private/key.go:50(private.AuthorizedPublicKeyByContent) Oct 29 17:55:23 ikonicre audit[1847]: AVC avc: denied { remove_name } for pid=1847 comm="conmon" name="exit.2EA4E3" dev="nvme0n1p1" ino=537388773 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=dir permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { watch } for pid=1834 comm="exe" path="/var/home/git/.local/share/containers/storage/overlay-containers/96b85c7e646a7ce7ca73c649d2e2419dc7d8fac32e05584415a7f5a426567c91/userdata/25392b7e3d55de8854d09a29572aa574b05851247d372f6817ff664fd2298e9c/exit" dev="nvme0n1p1" ino=1610945413 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=dir permissive=1 Oct 29 17:55:23 ikonicre audit[1847]: AVC avc: denied { rename } for pid=1847 comm="conmon" name="exit.2EA4E3" dev="nvme0n1p1" ino=537388773 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=file permissive=1 Oct 29 17:55:23 ikonicre audit[1847]: AVC avc: denied { unlink } for pid=1847 comm="conmon" name="attach" dev="nvme0n1p1" ino=1075818409 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=sock_file permissive=1 Oct 29 17:55:23 ikonicre podman[1834]: 2025-10-29 17:55:23.201324993 -0400 EDT m=+0.191641378 container exec_died 96b85c7e646a7ce7ca73c649d2e2419dc7d8fac32e05584415a7f5a426567c91 (image=codeberg.org/forgejo/forgejo:12-rootless, name=forgejo, PODMAN_SYSTEMD_UNIT=forgejo.service, io.containers.autoupdate=registry, org.opencontainers.image.url=https://forgejo.org, org.opencontainers.image.source=https://codeberg.org/forgejo/forgejo, org.opencontainers.image.authors=Forgejo, org.opencontainers.image.description=Forgejo is a self-hosted lightweight software forge. Easy to install and low maintenance, it just does the job., org.opencontainers.image.licenses=GPL-3.0-or-later, org.opencontainers.image.title=Forgejo. Beyond coding. We forge., maintainer=contact, org.opencontainers.image.documentation=https://forgejo.org/download/#container-image, org.opencontainers.image.vendor=Forgejo, org.opencontainers.image.version=12.0.4) Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { rmdir } for pid=1834 comm="exe" name="25392b7e3d55de8854d09a29572aa574b05851247d372f6817ff664fd2298e9c" dev="nvme0n1p1" ino=1075818395 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=dir permissive=1 Oct 29 17:55:23 ikonicre audit[1834]: AVC avc: denied { unlink } for pid=1834 comm="exe" name="ctl" dev="nvme0n1p1" ino=1075818410 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:data_home_t:s0 tclass=fifo_file permissive=1 Oct 29 17:55:23 ikonicre audit[1821]: USER_AUTH pid=1821 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 msg='op=pubkey acct="git" exe="/usr/libexec/openssh/sshd-session" hostname=? addr=10.1.1.93 terminal=ssh res=failed' Oct 29 17:55:23 ikonicre audit[1821]: CRYPTO_KEY_USER pid=1821 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1822 suid=74 rport=53360 laddr=10.1.1.7 lport=22 exe="/usr/libexec/openssh/sshd-session" hostname=? addr=10.1.1.93 terminal=? res=success' Oct 29 17:55:23 ikonicre sshd-session[1821]: Connection closed by authenticating user git 10.1.1.93 port 53360 [preauth] Oct 29 17:55:23 ikonicre audit[1821]: USER_ERR pid=1821 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/libexec/openssh/sshd-session" hostname=10.1.1.93 addr=10.1.1.93 terminal=ssh res=failed' Oct 29 17:55:23 ikonicre audit[1821]: USER_LOGIN pid=1821 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 msg='op=login acct="git" exe="/usr/libexec/openssh/sshd-session" hostname=? addr=10.1.1.93 terminal=ssh res=failed'
This clearly needs to be resolved where the boolean is defined, i.e. in container-selinux. As an alternative, we can move the content to selinux-policy, what do you think, Lokesh? It would mean a side-tag builds and probably need to update mutual dependencies.
(In reply to Zdenek Pytela from comment #3) > This clearly needs to be resolved where the boolean is defined, i.e. in > container-selinux. > > As an alternative, we can move the content to selinux-policy, what do you > think, Lokesh? > It would mean a side-tag builds and probably need to update mutual > dependencies. @zpytela I'd be cool with moving this to selinux-policy. I can give you access to do builds for container-selinux if need be.
This message is a reminder that Fedora Linux 42 is nearing its end of life. Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13. It is Fedora's policy to close all bug reports from releases that are no longer maintained. At that time this bug will be closed as EOL if it remains open with a 'version' of '42'. Package Maintainer: If you wish for this bug to remain open because you plan to fix it in a currently maintained version, change the 'version' to a later Fedora Linux version. Note that the version field may be hidden. Click the "Show advanced fields" button if you do not see it. Thank you for reporting this issue and we are sorry that we were not able to fix it before Fedora Linux 42 is end of life. If you would still like to see this bug fixed and are able to reproduce it against a later version of Fedora Linux, you are encouraged to change the 'version' to a later version prior to this bug being closed.
> @zpytela I'd be cool with moving this to selinux-policy. I can > give you access to do builds for container-selinux if need be. Are we moving ahead with this?
I reproduced this with Fedora CoreOS 44 in a VM so I updated the version to keep the bug from being automatically closed. I should be able to test this with a new package with the fix.
Should be fixed in container-selinux-2.251.0-1 for all supported releases