Fedora Account System
Red Hat Associate
Red Hat Customer
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Description of problem: > ~~~ > RokeJulianLockhart@Beedell:~$ getent group wireshark | grep $USER > wireshark:x:969:RokeJulianLockhart > RokeJulianLockhart@Beedell:~$ groups > RokeJulianLockhart wheel libvirt usershares > RokeJulianLockhart@Beedell:~$ sudo groupadd wireshark > [sudo] password for RokeJulianLockhart: > groupadd: group 'wireshark' already exists > RokeJulianLockhart@Beedell:~$ run0 gpasswd -a $USER wireshark > ==== AUTHENTICATING FOR org.freedesktop.systemd1.manage-units ==== > Authentication is required to start transient unit 'run-p150752-i150753.service'. > Authenticating as: Mr. Roke Julian Lockhart Beedell (RJLB) (RokeJulianLockhart) > Password: > ==== AUTHENTICATION COMPLETE ==== > Adding user RokeJulianLockhart to group wireshark > ~~~ SELinux is preventing /usr/bin/gpasswd from 'entrypoint' accesses on the file /usr/bin/gpasswd. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that gpasswd should be allowed entrypoint access on the gpasswd file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'gpasswd' --raw | audit2allow -M my-gpasswd # semodule -X 300 -i my-gpasswd.pp Additional Information: Source Context unconfined_u:unconfined_r:unconfined_t:s0- s0:c0.c1023 Target Context system_u:object_r:groupadd_exec_t:s0 Target Objects /usr/bin/gpasswd [ file ] Source gpasswd Source Path /usr/bin/gpasswd Port <Unknown> Host (removed) Source RPM Packages shadow-utils-4.18.0-3.fc43.x86_64 Target RPM Packages shadow-utils-4.18.0-3.fc43.x86_64 SELinux Policy RPM selinux-policy-targeted-42.19-1.fc43.noarch Local Policy RPM selinux-policy-targeted-42.19-1.fc43.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Permissive Host Name (removed) Platform Linux (removed) 6.17.10-300.fc43.x86_64 #1 SMP PREEMPT_DYNAMIC Mon Dec 1 14:59:36 UTC 2025 x86_64 Alert Count 3 First Seen 2025-12-11 20:28:18 GMT Last Seen 2025-12-11 20:29:30 GMT Local ID d3a2a46c-4d21-436d-aad3-194d0d2856af Raw Audit Messages type=AVC msg=audit(1765484970.265:1431): avc: denied { entrypoint } for pid=152447 comm="(gpasswd)" path="/usr/bin/gpasswd" dev="nvme2n1p4" ino=9621643 scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=system_u:object_r:groupadd_exec_t:s0 tclass=file permissive=1 type=SYSCALL msg=audit(1765484970.265:1431): arch=x86_64 syscall=execve success=yes exit=0 a0=562ac0ac6740 a1=562ac0ac5fb0 a2=562ac0ae1040 a3=0 items=2 ppid=1 pid=152447 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts2 ses=17 comm=gpasswd exe=/usr/bin/gpasswd subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null) type=CWD msg=audit(1765484970.265:1431): cwd=/home/RokeJulianLockhart type=PATH msg=audit(1765484970.265:1431): item=0 name=/usr/bin/gpasswd inode=9621643 dev=00:22 mode=0104755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:groupadd_exec_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0 type=PATH msg=audit(1765484970.265:1431): item=1 name=/lib64/ld-linux-x86-64.so.2 inode=9573248 dev=00:22 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0 Hash: gpasswd,unconfined_t,groupadd_exec_t,file,entrypoint Version-Release number of selected component: selinux-policy-targeted-42.19-1.fc43.noarch Additional info: reporter: libreport-2.17.15 reason: SELinux is preventing /usr/bin/gpasswd from 'entrypoint' accesses on the file /usr/bin/gpasswd. package: selinux-policy-targeted-42.19-1.fc43.noarch component: selinux-policy hashmarkername: setroubleshoot type: libreport kernel: 6.17.10-300.fc43.x86_64 event_log: 2025-12-11-20:33:50> Looking for similar problems in bugzilla component: selinux-policy -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQTACnqipLcrwkiYEfPr9NsMQDxLLgUCaY3rYwAKCRDr9NsMQDxL LqzrAQCPph01LVPnd9aSE1K/E+vNOuGbt84J72tKTYnGOMgZWQEAnWxHNhHu71y3 ZhQKPJaUdBzM06SygfgW5khJ65qZiQk= =f2eK -----END PGP SIGNATURE-----
Created attachment 2118410 [details] File: description
Created attachment 2118411 [details] File: os_info
See https://bugzilla.redhat.com/show_bug.cgi?id=2421016#c0.