Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: I started Plasma 6.5.2 on Wayland in a Fedora 43 KDE installation. I ran Dolphin. I selected the Trash folder on the left bar in Dolphin which had some deleted videos. I moved the cursor over the video files. There were repeated SELinux denial notifications shown. bwrap was denied the sys admin capability. blocking-1 and blocking-2 were denied connecting to /run/systemd/userdb/io.systemd.Home. Nov 14 11:50:49 audit[12549]: AVC avc: denied { sys_admin } for pid=12549 comm="bwrap" capability=21 scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tclass=cap_userns permissive=0 Nov 14 11:50:49 audit[12513]: AVC avc: denied { connectto } for pid=12513 comm="blocking-1" path="/run/systemd/userdb/io.systemd.Home" scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=system_u:system_r:systemd_homed_t:s0 tclass=unix_stream_socket permissive=0 ... Nov 14 11:50:51 audit[12672]: AVC avc: denied { sys_admin } for pid=12672 comm="bwrap" capability=21 scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tclass=cap_userns permissive=0 Nov 14 11:50:51 audit[12658]: AVC avc: denied { connectto } for pid=12658 comm="blocking-2" path="/run/systemd/userdb/io.systemd.Home" scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=system_u:system_r:systemd_homed_t:s0 tclass=unix_stream_socket permissive=0 No thumbnails were shown for the videos. I guess that the denials were due to the thumbnails trying to be created given the thumb_t labels. I had previously seen similar denials when doing the same thing. The denials of blocking-1 and blocking-2 to connecting to /run/systemd/userdb/io.systemd.Home started after I updated to selinux-policy-42.15-1.fc43. SELinux is preventing blocking-1 from 'connectto' accesses on the unix_stream_socket /run/systemd/userdb/io.systemd.Home. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that blocking-1 should be allowed connectto access on the io.systemd.Home unix_stream_socket by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'blocking-1' --raw | audit2allow -M my-blocking1 # semodule -X 300 -i my-blocking1.pp Additional Information: Source Context unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 Target Context system_u:system_r:systemd_homed_t:s0 Target Objects /run/systemd/userdb/io.systemd.Home [ unix_stream_socket ] Source blocking-1 Source Path blocking-1 Port <Unknown> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-42.15-1.fc43.noarch Local Policy RPM selinux-policy-targeted-42.15-1.fc43.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 6.17.7-300.fc43.x86_64 #1 SMP PREEMPT_DYNAMIC Sun Nov 2 15:30:09 UTC 2025 x86_64 Alert Count 16 First Seen 2025-11-14 11:50:49 EST Last Seen 2025-11-14 11:51:01 EST Local ID 8fedc037-362b-4142-ba4a-004dbefebadf Raw Audit Messages type=AVC msg=audit(1763139061.112:568): avc: denied { connectto } for pid=13188 comm="blocking-1" path="/run/systemd/userdb/io.systemd.Home" scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=system_u:system_r:systemd_homed_t:s0 tclass=unix_stream_socket permissive=0 Hash: blocking-1,thumb_t,systemd_homed_t,unix_stream_socket,connectto Version-Release number of selected component: selinux-policy-targeted-42.15-1.fc43.noarch Additional info: reporter: libreport-2.17.15 hashmarkername: setroubleshoot type: libreport kernel: 6.17.7-300.fc43.x86_64 component: selinux-policy package: selinux-policy-targeted-42.15-1.fc43.noarch reason: SELinux is preventing blocking-1 from 'connectto' accesses on the unix_stream_socket /run/systemd/userdb/io.systemd.Home. component: selinux-policy
Created attachment 2114439 [details] File: os_info
Created attachment 2114440 [details] File: description
*** This bug has been marked as a duplicate of bug 2408906 ***
/run/systemd/userdb/io.systemd.Home has the label systemd_homed_t, but in bug 2408906 io.systemd.DynamicUser has the label systemd_userdbd_runtime_t. This denial involving /run/systemd/userdb/io.systemd.Home started with selinux-policy-42.15-1.fc43 which had the patch for bug 2408906. Thanks.