Fedora Account System
Red Hat Associate
Red Hat Customer
SELinux is preventing blocking-2 from connectto access on the unix_stream_socket /run/systemd/userdb/io.systemd.Machine. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that blocking-2 should be allowed connectto access on the io.systemd.Machine unix_stream_socket by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'blocking-2' --raw | audit2allow -M my-blocking2 # semodule -X 300 -i my-blocking2.pp Additional Information: Source Context unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 Target Context system_u:system_r:systemd_machined_t:s0 Target Objects /run/systemd/userdb/io.systemd.Machine [ unix_stream_socket ] Source blocking-2 Source Path blocking-2 Port <Unknown> Host fedora Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-42.15-1.fc43.noarch Local Policy RPM selinux-policy-targeted-42.15-1.fc43.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name fedora Platform Linux fedora 6.17.7-300.fc43.x86_64 #1 SMP PREEMPT_DYNAMIC Sun Nov 2 15:30:09 UTC 2025 x86_64 Alert Count 102 First Seen 2025-11-15 21:15:23 IST Last Seen 2025-11-16 20:13:11 IST Local ID 6eb80bdb-e19a-475c-a8fa-da4d04277414 Raw Audit Messages type=AVC msg=audit(1763304191.477:305): avc: denied { connectto } for pid=12863 comm="blocking-2" path="/run/systemd/userdb/io.systemd.Machine" scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=system_u:system_r:systemd_machined_t:s0 tclass=unix_stream_socket permissive=0 Hash: blocking-2,thumb_t,systemd_machined_t,unix_stream_socket,connectto Reproducible: Always Steps to Reproduce: 1.On a cinnamon desktop, open Pictures folder and copy images and paste to another folder. 2. 3.
*** This bug has been marked as a duplicate of bug 2408906 ***
Not Duplicate of Bug 2408906 - SELinux is preventing blocking-2 from 'write' accesses on the sock_file io.systemd.DynamicUser. as the both are different at ownership of process being blocked.
Yes it is, please update the package. *** This bug has been marked as a duplicate of bug 2408906 ***
Has the issue resolved yet? when can I expect an updated SELinux package in the repos?
Expectedly resolved already by the previous build, that's why I asked you to update.