Bug 2408906 - SELinux is preventing blocking-2 from 'write' accesses on the sock_file io.systemd.DynamicUser.
Summary: SELinux is preventing blocking-2 from 'write' accesses on the sock_file io.sy...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 43
Hardware: x86_64
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:50343743863dbc9da1e7dc7d834...
: 2405280 2412027 2412469 2412626 2412844 2413098 2413354 2413601 2414560 2414818 2415075 2415153 2415244 2415259 2416817 2416995 2416996 2417717 2417813 2417837 2418073 2418293 2423945 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-10-31 19:31 UTC by KsenkoLopa
Modified: 2025-12-19 19:49 UTC (History)
27 users (show)

Fixed In Version: selinux-policy-42.15-1.fc43
Clone Of:
Environment:
Last Closed: 2025-11-15 00:53:19 UTC
Type: ---
Embargoed:
zpytela: mirror+


Attachments (Terms of Use)
File: description (2.23 KB, text/plain)
2025-10-31 19:31 UTC, KsenkoLopa
no flags Details
File: os_info (630 bytes, text/plain)
2025-10-31 19:31 UTC, KsenkoLopa
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Github fedora-selinux selinux-policy pull 2929 0 None open Allow thumb_t stream connect to systemd-userdbd 2025-11-07 15:19:35 UTC
Red Hat Issue Tracker FC-2833 0 None None None 2025-12-19 19:49:40 UTC

Description KsenkoLopa 2025-10-31 19:31:48 UTC
Description of problem:
SELinux is preventing blocking-2 from 'write' accesses on the sock_file io.systemd.DynamicUser.

*****  Plugin catchall (100. confidence) suggests   **************************

Если вы считаете, что blocking-2 должно быть разрешено write доступ к io.systemd.DynamicUser sock_file по умолчанию.
Then рекомендуется создать отчет об ошибке.
Чтобы разрешить доступ, можно создать локальный модуль политики.
Do
разрешить этот доступ сейчас, выполнив:
# ausearch -c 'blocking-2' --raw | audit2allow -M my-blocking2
# semodule -X 300 -i my-blocking2.pp

Additional Information:
Source Context                unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023
Target Context                system_u:object_r:systemd_userdbd_runtime_t:s0
Target Objects                io.systemd.DynamicUser [ sock_file ]
Source                        blocking-2
Source Path                   blocking-2
Port                          <Неизвестно>
Host                          (removed)
Source RPM Packages           
Target RPM Packages           
SELinux Policy RPM            selinux-policy-targeted-42.14-1.fc43.noarch
Local Policy RPM              selinux-policy-targeted-42.14-1.fc43.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     (removed)
Platform                      Linux (removed) 6.17.5-300.fc43.x86_64 #1 SMP
                              PREEMPT_DYNAMIC Thu Oct 23 15:35:13 UTC 2025
                              x86_64
Alert Count                   12
First Seen                    2025-11-01 01:27:49 +06
Last Seen                     2025-11-01 01:28:32 +06
Local ID                      27db207a-bf1d-46f2-9f0a-9fcbd3b05046

Raw Audit Messages
type=AVC msg=audit(1761938912.344:196): avc:  denied  { write } for  pid=2370 comm="blocking-4" name="io.systemd.DynamicUser" dev="tmpfs" ino=1186 scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=system_u:object_r:systemd_userdbd_runtime_t:s0 tclass=sock_file permissive=0


Hash: blocking-2,thumb_t,systemd_userdbd_runtime_t,sock_file,write

Version-Release number of selected component:
selinux-policy-targeted-42.14-1.fc43.noarch

Additional info:
reporter:       libreport-2.17.15
reason:         SELinux is preventing blocking-2 from 'write' accesses on the sock_file io.systemd.DynamicUser.
component:      selinux-policy
package:        selinux-policy-targeted-42.14-1.fc43.noarch
hashmarkername: setroubleshoot
kernel:         6.17.5-300.fc43.x86_64
type:           libreport
component:      selinux-policy

Comment 1 KsenkoLopa 2025-10-31 19:31:51 UTC
Created attachment 2111664 [details]
File: description

Comment 2 KsenkoLopa 2025-10-31 19:31:53 UTC
Created attachment 2111665 [details]
File: os_info

Comment 3 Zdenek Pytela 2025-11-03 17:14:58 UTC
*** Bug 2412027 has been marked as a duplicate of this bug. ***

Comment 4 Zdenek Pytela 2025-11-05 12:39:38 UTC
Two distinct denials appear:

type=AVC msg=audit(1762189264.579:2369): avc:  denied  { connectto } for  pid=70744 comm="blocking-1" path="/run/systemd/userdb/io.systemd.DynamicUser" scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=system_u:system_r:init_t:s0 tclass=unix_stream_socket permissive=0

type=AVC msg=audit(1762345883.190:455): avc:  denied  { write } for  pid=116974 comm="blocking-1" name="io.systemd.DynamicUser" dev="tmpfs" ino=1482 scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=system_u:object_r:systemd_userdbd_runtime_t:s0 tclass=sock_file permissive=0

Comment 5 Zdenek Pytela 2025-11-05 12:39:50 UTC
*** Bug 2405280 has been marked as a duplicate of this bug. ***

Comment 6 Zdenek Pytela 2025-11-05 12:39:56 UTC
*** Bug 2412469 has been marked as a duplicate of this bug. ***

Comment 7 Zdenek Pytela 2025-11-06 09:20:44 UTC
*** Bug 2412626 has been marked as a duplicate of this bug. ***

Comment 8 Zdenek Pytela 2025-11-06 09:20:56 UTC
*** Bug 2412844 has been marked as a duplicate of this bug. ***

Comment 9 Zdenek Pytela 2025-11-06 14:07:52 UTC
*** Bug 2413098 has been marked as a duplicate of this bug. ***

Comment 10 Zdenek Pytela 2025-11-07 14:11:37 UTC
*** Bug 2413354 has been marked as a duplicate of this bug. ***

Comment 11 Jakub T. Jankiewicz 2025-11-09 18:12:35 UTC
I have similar error after upgrading to Fedora 43, but it says blocking-1 instead of blocking-2 (not sure what is the difference):

SELinux is preventing blocking-1 from write access on the sock_file io.systemd.DynamicUser.

*****  Plugin catchall (100. confidence) suggests   **************************

If you believe that blocking-1 should be allowed write access on the io.systemd.DynamicUser sock_file by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c 'blocking-1' --raw | audit2allow -M my-blocking1
# semodule -X 300 -i my-blocking1.pp


Additional Information:
Source Context                unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023
Target Context                system_u:object_r:systemd_userdbd_runtime_t:s0
Target Objects                io.systemd.DynamicUser [ sock_file ]
Source                        blocking-1
Source Path                   blocking-1
Port                          <Unknown>
Host                          jcubic
Source RPM Packages           
Target RPM Packages           
SELinux Policy RPM            selinux-policy-targeted-42.14-1.fc43.noarch
Local Policy RPM              selinux-policy-targeted-42.14-1.fc43.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     jcubic
Platform                      Linux jcubic 6.17.7-300.fc43.x86_64 #1 SMP
                              PREEMPT_DYNAMIC Sun Nov  2 15:30:09 UTC 2025
                              x86_64
Alert Count                   135
First Seen                    2025-11-05 16:49:28 CET
Last Seen                     2025-11-09 18:59:46 CET
Local ID                      f1420929-1277-4ec9-8472-314c3858fc0b

Raw Audit Messages
type=AVC msg=audit(1762711186.427:559): avc:  denied  { write } for  pid=1063397 comm="blocking-1" name="io.systemd.DynamicUser" dev="tmpfs" ino=1262 scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=system_u:object_r:systemd_userdbd_runtime_t:s0 tclass=sock_file permissive=0


Hash: blocking-1,thumb_t,systemd_userdbd_runtime_t,sock_file,write

Comment 12 Zdenek Pytela 2025-11-10 09:07:18 UTC
*** Bug 2413601 has been marked as a duplicate of this bug. ***

Comment 13 Zdenek Pytela 2025-11-12 17:03:29 UTC
*** Bug 2414560 has been marked as a duplicate of this bug. ***

Comment 14 Zdenek Pytela 2025-11-13 14:13:48 UTC
*** Bug 2414818 has been marked as a duplicate of this bug. ***

Comment 15 Fedora Update System 2025-11-13 15:35:10 UTC
FEDORA-2025-f9000e422c (selinux-policy-42.15-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-f9000e422c

Comment 16 Fedora Update System 2025-11-14 01:59:35 UTC
FEDORA-2025-f9000e422c has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-f9000e422c`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-f9000e422c

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 17 Fedora Update System 2025-11-15 00:53:19 UTC
FEDORA-2025-f9000e422c (selinux-policy-42.15-1.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 18 Zdenek Pytela 2025-11-18 16:26:57 UTC
*** Bug 2415075 has been marked as a duplicate of this bug. ***

Comment 19 Zdenek Pytela 2025-11-18 17:47:15 UTC
*** Bug 2415153 has been marked as a duplicate of this bug. ***

Comment 20 Zdenek Pytela 2025-11-18 17:52:22 UTC
*** Bug 2415244 has been marked as a duplicate of this bug. ***

Comment 21 Zdenek Pytela 2025-11-18 18:04:28 UTC
*** Bug 2415259 has been marked as a duplicate of this bug. ***

Comment 22 Zdenek Pytela 2025-11-18 18:47:16 UTC
*** Bug 2415259 has been marked as a duplicate of this bug. ***

Comment 23 Zdenek Pytela 2025-11-25 08:22:42 UTC
*** Bug 2416817 has been marked as a duplicate of this bug. ***

Comment 24 Zdenek Pytela 2025-11-25 13:30:19 UTC
*** Bug 2416995 has been marked as a duplicate of this bug. ***

Comment 25 Zdenek Pytela 2025-11-25 13:30:28 UTC
*** Bug 2416996 has been marked as a duplicate of this bug. ***

Comment 26 Zdenek Pytela 2025-11-28 16:56:38 UTC
*** Bug 2417717 has been marked as a duplicate of this bug. ***

Comment 27 Zdenek Pytela 2025-12-03 16:36:06 UTC
*** Bug 2417813 has been marked as a duplicate of this bug. ***

Comment 28 Zdenek Pytela 2025-12-03 16:36:16 UTC
*** Bug 2417837 has been marked as a duplicate of this bug. ***

Comment 29 Zdenek Pytela 2025-12-03 16:36:25 UTC
*** Bug 2418073 has been marked as a duplicate of this bug. ***

Comment 30 Zdenek Pytela 2025-12-03 16:36:35 UTC
*** Bug 2418293 has been marked as a duplicate of this bug. ***

Comment 31 hannes 2025-12-19 19:48:48 UTC
*** Bug 2423945 has been marked as a duplicate of this bug. ***


Note You need to log in before you can comment on or make changes to this bug.