Description of problem: SELinux is preventing bwrap from 'mounton' accesses on the directory /tmp. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that bwrap should be allowed mounton access on the tmp directory by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'bwrap' --raw | audit2allow -M my-bwrap # semodule -X 300 -i my-bwrap.pp Additional Information: Source Context unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 Target Context system_u:object_r:tmp_t:s0 Target Objects /tmp [ dir ] Source bwrap Source Path bwrap Port <Unknown> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-42.17-1.fc43.noarch Local Policy RPM selinux-policy-targeted-42.17-1.fc43.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 6.17.8-300.fc43.x86_64 #1 SMP PREEMPT_DYNAMIC Fri Nov 14 01:47:12 UTC 2025 x86_64 Alert Count 23 First Seen 2025-12-01 17:13:37 CET Last Seen 2025-12-01 17:20:24 CET Local ID d2941f60-801c-4250-b1ab-3c85c8aa4588 Raw Audit Messages type=AVC msg=audit(1764606024.108:682): avc: denied { mounton } for pid=76276 comm="bwrap" path="/tmp" dev="tmpfs" ino=1 scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmp_t:s0 tclass=dir permissive=0 Hash: bwrap,thumb_t,tmp_t,dir,mounton Version-Release number of selected component: selinux-policy-targeted-42.17-1.fc43.noarch Additional info: reporter: libreport-2.17.15 reason: SELinux is preventing bwrap from 'mounton' accesses on the directory /tmp. package: selinux-policy-targeted-42.17-1.fc43.noarch component: selinux-policy hashmarkername: setroubleshoot type: libreport kernel: 6.17.8-300.fc43.x86_64 component: selinux-policy
Created attachment 2116984 [details] File: description
Created attachment 2116985 [details] File: os_info
Having this same problem and it is not being addressed at all. I am getting it when just dealing with PDF files. It doesn't stop the action from happening but there are the constant SELinux alerts showing up.
Please see my comment over on the Fedora Discussion page. You can either set thumb_t to permissive or build the module. Both will work but one will still give the alerts. This appears to be an upstream issue with SELinux policy.
*** This bug has been marked as a duplicate of bug 2415016 ***