Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: SELinux is preventing blocking-2 from 'write' accesses on the sock_file io.systemd.DynamicUser. ***** Plugin catchall (100. confidence) suggests ************************** Если вы считаете, что blocking-2 должно быть разрешено write доступ к io.systemd.DynamicUser sock_file по умолчанию. Then рекомендуется создать отчет об ошибке. Чтобы разрешить доступ, можно создать локальный модуль политики. Do разрешить этот доступ сейчас, выполнив: # ausearch -c 'blocking-2' --raw | audit2allow -M my-blocking2 # semodule -X 300 -i my-blocking2.pp Additional Information: Source Context unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 Target Context system_u:object_r:systemd_userdbd_runtime_t:s0 Target Objects io.systemd.DynamicUser [ sock_file ] Source blocking-2 Source Path blocking-2 Port <Неизвестно> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-42.14-1.fc43.noarch Local Policy RPM selinux-policy-targeted-42.14-1.fc43.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 6.17.5-300.fc43.x86_64 #1 SMP PREEMPT_DYNAMIC Thu Oct 23 15:35:13 UTC 2025 x86_64 Alert Count 12 First Seen 2025-11-01 01:27:49 +06 Last Seen 2025-11-01 01:28:32 +06 Local ID 27db207a-bf1d-46f2-9f0a-9fcbd3b05046 Raw Audit Messages type=AVC msg=audit(1761938912.344:196): avc: denied { write } for pid=2370 comm="blocking-4" name="io.systemd.DynamicUser" dev="tmpfs" ino=1186 scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=system_u:object_r:systemd_userdbd_runtime_t:s0 tclass=sock_file permissive=0 Hash: blocking-2,thumb_t,systemd_userdbd_runtime_t,sock_file,write Version-Release number of selected component: selinux-policy-targeted-42.14-1.fc43.noarch Additional info: reporter: libreport-2.17.15 reason: SELinux is preventing blocking-2 from 'write' accesses on the sock_file io.systemd.DynamicUser. component: selinux-policy package: selinux-policy-targeted-42.14-1.fc43.noarch hashmarkername: setroubleshoot kernel: 6.17.5-300.fc43.x86_64 type: libreport component: selinux-policy
Created attachment 2111664 [details] File: description
Created attachment 2111665 [details] File: os_info
*** Bug 2412027 has been marked as a duplicate of this bug. ***
Two distinct denials appear: type=AVC msg=audit(1762189264.579:2369): avc: denied { connectto } for pid=70744 comm="blocking-1" path="/run/systemd/userdb/io.systemd.DynamicUser" scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=system_u:system_r:init_t:s0 tclass=unix_stream_socket permissive=0 type=AVC msg=audit(1762345883.190:455): avc: denied { write } for pid=116974 comm="blocking-1" name="io.systemd.DynamicUser" dev="tmpfs" ino=1482 scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=system_u:object_r:systemd_userdbd_runtime_t:s0 tclass=sock_file permissive=0
*** Bug 2405280 has been marked as a duplicate of this bug. ***
*** Bug 2412469 has been marked as a duplicate of this bug. ***
*** Bug 2412626 has been marked as a duplicate of this bug. ***
*** Bug 2412844 has been marked as a duplicate of this bug. ***
*** Bug 2413098 has been marked as a duplicate of this bug. ***
*** Bug 2413354 has been marked as a duplicate of this bug. ***
I have similar error after upgrading to Fedora 43, but it says blocking-1 instead of blocking-2 (not sure what is the difference): SELinux is preventing blocking-1 from write access on the sock_file io.systemd.DynamicUser. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that blocking-1 should be allowed write access on the io.systemd.DynamicUser sock_file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'blocking-1' --raw | audit2allow -M my-blocking1 # semodule -X 300 -i my-blocking1.pp Additional Information: Source Context unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 Target Context system_u:object_r:systemd_userdbd_runtime_t:s0 Target Objects io.systemd.DynamicUser [ sock_file ] Source blocking-1 Source Path blocking-1 Port <Unknown> Host jcubic Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-42.14-1.fc43.noarch Local Policy RPM selinux-policy-targeted-42.14-1.fc43.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name jcubic Platform Linux jcubic 6.17.7-300.fc43.x86_64 #1 SMP PREEMPT_DYNAMIC Sun Nov 2 15:30:09 UTC 2025 x86_64 Alert Count 135 First Seen 2025-11-05 16:49:28 CET Last Seen 2025-11-09 18:59:46 CET Local ID f1420929-1277-4ec9-8472-314c3858fc0b Raw Audit Messages type=AVC msg=audit(1762711186.427:559): avc: denied { write } for pid=1063397 comm="blocking-1" name="io.systemd.DynamicUser" dev="tmpfs" ino=1262 scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=system_u:object_r:systemd_userdbd_runtime_t:s0 tclass=sock_file permissive=0 Hash: blocking-1,thumb_t,systemd_userdbd_runtime_t,sock_file,write
*** Bug 2413601 has been marked as a duplicate of this bug. ***
*** Bug 2414560 has been marked as a duplicate of this bug. ***
*** Bug 2414818 has been marked as a duplicate of this bug. ***
FEDORA-2025-f9000e422c (selinux-policy-42.15-1.fc43) has been submitted as an update to Fedora 43. https://bodhi.fedoraproject.org/updates/FEDORA-2025-f9000e422c
FEDORA-2025-f9000e422c has been pushed to the Fedora 43 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-f9000e422c` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-f9000e422c See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2025-f9000e422c (selinux-policy-42.15-1.fc43) has been pushed to the Fedora 43 stable repository. If problem still persists, please make note of it in this bug report.
*** Bug 2415075 has been marked as a duplicate of this bug. ***
*** Bug 2415153 has been marked as a duplicate of this bug. ***
*** Bug 2415244 has been marked as a duplicate of this bug. ***
*** Bug 2415259 has been marked as a duplicate of this bug. ***
*** Bug 2416817 has been marked as a duplicate of this bug. ***
*** Bug 2416995 has been marked as a duplicate of this bug. ***
*** Bug 2416996 has been marked as a duplicate of this bug. ***
*** Bug 2417717 has been marked as a duplicate of this bug. ***
*** Bug 2417813 has been marked as a duplicate of this bug. ***
*** Bug 2417837 has been marked as a duplicate of this bug. ***
*** Bug 2418073 has been marked as a duplicate of this bug. ***
*** Bug 2418293 has been marked as a duplicate of this bug. ***
*** Bug 2423945 has been marked as a duplicate of this bug. ***