Bug 2408907 - SELinux is preventing bwrap from 'sys_admin' accesses on the cap_userns Неизвестно.
Summary: SELinux is preventing bwrap from 'sys_admin' accesses on the cap_userns Неизв...
Keywords:
Status: CLOSED DUPLICATE of bug 2415016
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 43
Hardware: x86_64
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:d1b6261164e00f7c55cc7295c2b...
: 2412462 2413099 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-10-31 19:32 UTC by KsenkoLopa
Modified: 2025-11-25 13:34 UTC (History)
11 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2025-11-25 13:34:57 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
File: description (2.15 KB, text/plain)
2025-10-31 19:32 UTC, KsenkoLopa
no flags Details
File: os_info (630 bytes, text/plain)
2025-10-31 19:32 UTC, KsenkoLopa
no flags Details

Description KsenkoLopa 2025-10-31 19:32:27 UTC
Description of problem:
SELinux is preventing bwrap from 'sys_admin' accesses on the cap_userns Неизвестно.

*****  Plugin catchall (100. confidence) suggests   **************************

Если вы считаете, что bwrap должно быть разрешено sys_admin доступ к Неизвестно cap_userns по умолчанию.
Then рекомендуется создать отчет об ошибке.
Чтобы разрешить доступ, можно создать локальный модуль политики.
Do
разрешить этот доступ сейчас, выполнив:
# ausearch -c 'bwrap' --raw | audit2allow -M my-bwrap
# semodule -X 300 -i my-bwrap.pp

Additional Information:
Source Context                unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023
Target Context                unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023
Target Objects                Неизвестно [ cap_userns ]
Source                        bwrap
Source Path                   bwrap
Port                          <Неизвестно>
Host                          (removed)
Source RPM Packages           
Target RPM Packages           
SELinux Policy RPM            selinux-policy-targeted-42.14-1.fc43.noarch
Local Policy RPM              selinux-policy-targeted-42.14-1.fc43.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     (removed)
Platform                      Linux (removed) 6.17.5-300.fc43.x86_64 #1 SMP
                              PREEMPT_DYNAMIC Thu Oct 23 15:35:13 UTC 2025
                              x86_64
Alert Count                   1
First Seen                    2025-11-01 01:27:48 +06
Last Seen                     2025-11-01 01:27:48 +06
Local ID                      6fbe7a75-8946-473b-bf6d-d88597e7dfd9

Raw Audit Messages
type=AVC msg=audit(1761938868.997:178): avc:  denied  { sys_admin } for  pid=6801 comm="bwrap" capability=21  scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tclass=cap_userns permissive=0


Hash: bwrap,thumb_t,thumb_t,cap_userns,sys_admin

Version-Release number of selected component:
selinux-policy-targeted-42.14-1.fc43.noarch

Additional info:
reporter:       libreport-2.17.15
reason:         SELinux is preventing bwrap from 'sys_admin' accesses on the cap_userns Неизвестно.
component:      selinux-policy
package:        selinux-policy-targeted-42.14-1.fc43.noarch
hashmarkername: setroubleshoot
kernel:         6.17.5-300.fc43.x86_64
type:           libreport
component:      selinux-policy

Comment 1 KsenkoLopa 2025-10-31 19:32:31 UTC
Created attachment 2111666 [details]
File: description

Comment 2 KsenkoLopa 2025-10-31 19:32:33 UTC
Created attachment 2111667 [details]
File: os_info

Comment 3 Zdenek Pytela 2025-11-03 15:32:08 UTC
Hello,

Can you tell when exactly this denial appears?
Is there any functional problem?
Can you reproduce the issue with full auditing enabled?
https://fedoraproject.org/wiki/SELinux/Debugging#Enable_full_auditing

Comment 4 KsenkoLopa 2025-11-05 07:13:55 UTC
(In reply to Zdenek Pytela from comment #3)
> Hello,
> 
> Can you tell when exactly this denial appears?
> Is there any functional problem?
> Can you reproduce the issue with full auditing enabled?
> https://fedoraproject.org/wiki/SELinux/Debugging#Enable_full_auditing

Hello.

This denial had appeared after i had updated from Fedora 42 to Fedora 43. Update process was succesful. First boot after updating this denial has appeared, therefore i created this bug report. But after that such denial never had happend, so, i guess, there is no need in further reproducing this issue with full auditing?

Comment 5 Zdenek Pytela 2025-11-05 12:36:37 UTC
It probably is not that important then, but still, can you help me how I can reproduce it?
Do you have any specific configuration, many bubblewrap apps running?

Comment 6 Zdenek Pytela 2025-11-05 12:36:59 UTC
*** Bug 2412462 has been marked as a duplicate of this bug. ***

Comment 7 KsenkoLopa 2025-11-05 18:35:06 UTC
(In reply to Zdenek Pytela from comment #5)
> It probably is not that important then, but still, can you help me how I can
> reproduce it?
> Do you have any specific configuration, many bubblewrap apps running?

I`m using absolutely standard installation of Fedora 43. I use it on my laptop at home, mainly for work (using Libre Office, Radmin for remote accses into office), surfing in internet via Mozilla Firefox, watching movies, listen music, play games via Steam and etc. So no any specific configuration, especially no bubblewrap apps running. If you need more information, please, tell me which one exactly. I`ll try to do my best to help you.
About link (https://fedoraproject.org/wiki/SELinux/Debugging#Enable_full_auditing) you`ve sent me earlier - should i perform it? Because i don`t know which of my action led to this denial to happen ("5. Run the scenario which effects in SELinux denials.").

Comment 8 Zdenek Pytela 2025-11-06 14:08:47 UTC
*** Bug 2413099 has been marked as a duplicate of this bug. ***

Comment 9 Jakub T. Jankiewicz 2025-11-09 18:21:38 UTC
I have the same error, after upgrating to Fedora 43. I needed to google bubblewrap, and it says that it's used by flatpack. Have it installed, but I don't have any packages installed.

This is the error I have. I updated few days ago, and booted yesterday, and checking all SELinux errors if there is a bug for report.

This is the errror:

SELinux is preventing bwrap from sys_admin access on the cap_userns Nieznane.

*****  Plugin catchall (100. confidence) suggests   **************************

If you believe that bwrap should be allowed sys_admin access on the Nieznane cap_userns by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c 'bwrap' --raw | audit2allow -M my-bwrap
# semodule -X 300 -i my-bwrap.pp


Additional Information:
Source Context                unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023
Target Context                unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023
Target Objects                Nieznane [ cap_userns ]
Source                        bwrap
Source Path                   bwrap
Port                          <Unknown>
Host                          jcubic
Source RPM Packages           
Target RPM Packages           
SELinux Policy RPM            selinux-policy-targeted-42.14-1.fc43.noarch
Local Policy RPM              selinux-policy-targeted-42.14-1.fc43.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     jcubic
Platform                      Linux jcubic 6.17.7-300.fc43.x86_64 #1 SMP
                              PREEMPT_DYNAMIC Sun Nov  2 15:30:09 UTC 2025
                              x86_64
Alert Count                   25
First Seen                    2025-11-05 16:49:28 CET
Last Seen                     2025-11-09 18:59:46 CET
Local ID                      40773a9b-b4fd-47ff-9ee5-29ba38da4d08

Raw Audit Messages
type=AVC msg=audit(1762711186.412:553): avc:  denied  { sys_admin } for  pid=1073585 comm="bwrap" capability=21  scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tclass=cap_userns permissive=0


Hash: bwrap,thumb_t,thumb_t,cap_userns,sys_admin

Comment 10 tsugumomorawandshit 2025-11-10 14:01:39 UTC
I noticed that this seem to happen whenever I have an image/video file that does not have a generated thumbnail. I have also upgraded from Fedora 42 to 43.

Comment 11 Jakub T. Jankiewicz 2025-11-10 14:37:07 UTC
You can reproduce the issue with this:

use any jpeg file and create a new copy using Image Magick.

mkdir ~/selinux
magick ~/Path/to/image.jpg -resize 1000 ~/selinux/x.jpg

And open that directory in Thunar (I use xfce).

Comment 12 Jakub T. Jankiewicz 2025-11-10 14:41:57 UTC
No sorry I was checking again, and it was for:

SELinux powstrzymuje blocking-1 przed dostępem connectto w unix_stream_socket /run/systemd/userdb/io.systemd.DynamicUser.

Comment 13 Zdenek Pytela 2025-11-25 13:34:57 UTC

*** This bug has been marked as a duplicate of bug 2415016 ***


Note You need to log in before you can comment on or make changes to this bug.