Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: SELinux is preventing bwrap from 'sys_admin' accesses on the cap_userns Неизвестно. ***** Plugin catchall (100. confidence) suggests ************************** Если вы считаете, что bwrap должно быть разрешено sys_admin доступ к Неизвестно cap_userns по умолчанию. Then рекомендуется создать отчет об ошибке. Чтобы разрешить доступ, можно создать локальный модуль политики. Do разрешить этот доступ сейчас, выполнив: # ausearch -c 'bwrap' --raw | audit2allow -M my-bwrap # semodule -X 300 -i my-bwrap.pp Additional Information: Source Context unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 Target Context unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 Target Objects Неизвестно [ cap_userns ] Source bwrap Source Path bwrap Port <Неизвестно> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-42.14-1.fc43.noarch Local Policy RPM selinux-policy-targeted-42.14-1.fc43.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 6.17.5-300.fc43.x86_64 #1 SMP PREEMPT_DYNAMIC Thu Oct 23 15:35:13 UTC 2025 x86_64 Alert Count 1 First Seen 2025-11-01 01:27:48 +06 Last Seen 2025-11-01 01:27:48 +06 Local ID 6fbe7a75-8946-473b-bf6d-d88597e7dfd9 Raw Audit Messages type=AVC msg=audit(1761938868.997:178): avc: denied { sys_admin } for pid=6801 comm="bwrap" capability=21 scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tclass=cap_userns permissive=0 Hash: bwrap,thumb_t,thumb_t,cap_userns,sys_admin Version-Release number of selected component: selinux-policy-targeted-42.14-1.fc43.noarch Additional info: reporter: libreport-2.17.15 reason: SELinux is preventing bwrap from 'sys_admin' accesses on the cap_userns Неизвестно. component: selinux-policy package: selinux-policy-targeted-42.14-1.fc43.noarch hashmarkername: setroubleshoot kernel: 6.17.5-300.fc43.x86_64 type: libreport component: selinux-policy
Created attachment 2111666 [details] File: description
Created attachment 2111667 [details] File: os_info
Hello, Can you tell when exactly this denial appears? Is there any functional problem? Can you reproduce the issue with full auditing enabled? https://fedoraproject.org/wiki/SELinux/Debugging#Enable_full_auditing
(In reply to Zdenek Pytela from comment #3) > Hello, > > Can you tell when exactly this denial appears? > Is there any functional problem? > Can you reproduce the issue with full auditing enabled? > https://fedoraproject.org/wiki/SELinux/Debugging#Enable_full_auditing Hello. This denial had appeared after i had updated from Fedora 42 to Fedora 43. Update process was succesful. First boot after updating this denial has appeared, therefore i created this bug report. But after that such denial never had happend, so, i guess, there is no need in further reproducing this issue with full auditing?
It probably is not that important then, but still, can you help me how I can reproduce it? Do you have any specific configuration, many bubblewrap apps running?
*** Bug 2412462 has been marked as a duplicate of this bug. ***
(In reply to Zdenek Pytela from comment #5) > It probably is not that important then, but still, can you help me how I can > reproduce it? > Do you have any specific configuration, many bubblewrap apps running? I`m using absolutely standard installation of Fedora 43. I use it on my laptop at home, mainly for work (using Libre Office, Radmin for remote accses into office), surfing in internet via Mozilla Firefox, watching movies, listen music, play games via Steam and etc. So no any specific configuration, especially no bubblewrap apps running. If you need more information, please, tell me which one exactly. I`ll try to do my best to help you. About link (https://fedoraproject.org/wiki/SELinux/Debugging#Enable_full_auditing) you`ve sent me earlier - should i perform it? Because i don`t know which of my action led to this denial to happen ("5. Run the scenario which effects in SELinux denials.").
*** Bug 2413099 has been marked as a duplicate of this bug. ***
I have the same error, after upgrating to Fedora 43. I needed to google bubblewrap, and it says that it's used by flatpack. Have it installed, but I don't have any packages installed. This is the error I have. I updated few days ago, and booted yesterday, and checking all SELinux errors if there is a bug for report. This is the errror: SELinux is preventing bwrap from sys_admin access on the cap_userns Nieznane. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that bwrap should be allowed sys_admin access on the Nieznane cap_userns by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'bwrap' --raw | audit2allow -M my-bwrap # semodule -X 300 -i my-bwrap.pp Additional Information: Source Context unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 Target Context unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 Target Objects Nieznane [ cap_userns ] Source bwrap Source Path bwrap Port <Unknown> Host jcubic Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-42.14-1.fc43.noarch Local Policy RPM selinux-policy-targeted-42.14-1.fc43.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name jcubic Platform Linux jcubic 6.17.7-300.fc43.x86_64 #1 SMP PREEMPT_DYNAMIC Sun Nov 2 15:30:09 UTC 2025 x86_64 Alert Count 25 First Seen 2025-11-05 16:49:28 CET Last Seen 2025-11-09 18:59:46 CET Local ID 40773a9b-b4fd-47ff-9ee5-29ba38da4d08 Raw Audit Messages type=AVC msg=audit(1762711186.412:553): avc: denied { sys_admin } for pid=1073585 comm="bwrap" capability=21 scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tclass=cap_userns permissive=0 Hash: bwrap,thumb_t,thumb_t,cap_userns,sys_admin
I noticed that this seem to happen whenever I have an image/video file that does not have a generated thumbnail. I have also upgraded from Fedora 42 to 43.
You can reproduce the issue with this: use any jpeg file and create a new copy using Image Magick. mkdir ~/selinux magick ~/Path/to/image.jpg -resize 1000 ~/selinux/x.jpg And open that directory in Thunar (I use xfce).
No sorry I was checking again, and it was for: SELinux powstrzymuje blocking-1 przed dostępem connectto w unix_stream_socket /run/systemd/userdb/io.systemd.DynamicUser.
*** This bug has been marked as a duplicate of bug 2415016 ***