Bug 2435751 - SELinux is preventing bwrap from 'mounton' accesses on the directory /.
Summary: SELinux is preventing bwrap from 'mounton' accesses on the directory /.
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 43
Hardware: x86_64
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:74e05c2e13ad5607664b388638f...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-02-01 10:30 UTC by sk1199
Modified: 2026-02-07 00:58 UTC (History)
8 users (show)

Fixed In Version: selinux-policy-42.23-1.fc43
Clone Of:
Environment:
Last Closed: 2026-02-07 00:58:30 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
File: os_info (699 bytes, text/plain)
2026-02-01 10:30 UTC, sk1199
no flags Details
File: description (1.83 KB, text/plain)
2026-02-01 10:30 UTC, sk1199
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Github fedora-selinux selinux-policy pull 3051 0 None open Support using bubblewrap for confined users 2026-02-03 18:13:47 UTC

Description sk1199 2026-02-01 10:30:36 UTC
Description of problem:
Problem occurs when running any kind of selinux confined user in gnome.
SELinux is preventing bwrap from 'mounton' accesses on the directory /.

*****  Plugin catchall (100. confidence) suggests   **************************

If you believe that bwrap should be allowed mounton access on the  directory by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c 'bwrap' --raw | audit2allow -M my-bwrap
# semodule -X 300 -i my-bwrap.pp

Additional Information:
Source Context                staff_u:staff_r:staff_t:s0-s0:c0.c1023
Target Context                system_u:object_r:root_t:s0
Target Objects                / [ dir ]
Source                        bwrap
Source Path                   bwrap
Port                          <Unknown>
Host                          (removed)
Source RPM Packages           
Target RPM Packages           
SELinux Policy RPM            selinux-policy-targeted-42.22-1.fc43.noarch
Local Policy RPM              selinux-policy-targeted-42.22-1.fc43.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     (removed)
Platform                      Linux (removed) 6.18.7-200.fc43.x86_64 #1 SMP
                              PREEMPT_DYNAMIC Fri Jan 23 16:42:34 UTC 2026
                              x86_64
Alert Count                   8422
First Seen                    2026-01-09 12:21:56 IST
Last Seen                     2026-02-01 15:48:43 IST
Local ID                      0f884186-6304-407a-b616-f790ef9d0435

Raw Audit Messages
type=AVC msg=audit(1769941123.210:8284): avc:  denied  { mounton } for  pid=39070 comm="bwrap" path="/" dev="nvme0n1p2" ino=2 scontext=staff_u:staff_r:staff_t:s0-s0:c0.c1023 tcontext=system_u:object_r:root_t:s0 tclass=dir permissive=0


Hash: bwrap,staff_t,root_t,dir,mounton

Version-Release number of selected component:
selinux-policy-targeted-42.22-1.fc43.noarch

Additional info:
reporter:       libreport-2.17.15
kernel:         6.18.7-200.fc43.x86_64
component:      selinux-policy
comment:        Problem occurs when running any kind of selinux confined user in gnome.
type:           libreport
reason:         SELinux is preventing bwrap from 'mounton' accesses on the directory /.
hashmarkername: setroubleshoot
package:        selinux-policy-targeted-42.22-1.fc43.noarch
component:      selinux-policy

Comment 1 sk1199 2026-02-01 10:30:39 UTC
Created attachment 2127686 [details]
File: os_info

Comment 2 sk1199 2026-02-01 10:30:42 UTC
Created attachment 2127687 [details]
File: description

Comment 3 Zdenek Pytela 2026-02-03 18:13:48 UTC
The resolution turned out to be more complex. Please try copr build from
https://github.com/fedora-selinux/selinux-policy/pull/3051

if you can.

Comment 4 sk1199 2026-02-04 16:10:06 UTC
(In reply to Zdenek Pytela from comment #3)
> The resolution turned out to be more complex. Please try copr build from
> https://github.com/fedora-selinux/selinux-policy/pull/3051
> 
> if you can.

Installing the copr build fixed the issue.

Comment 5 Zdenek Pytela 2026-02-04 20:13:59 UTC
Thanks, merging then. Build on the way.

Comment 6 Fedora Update System 2026-02-05 11:05:44 UTC
FEDORA-2026-3439e5656a (selinux-policy-42.23-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-3439e5656a

Comment 7 Fedora Update System 2026-02-07 00:58:30 UTC
FEDORA-2026-3439e5656a (selinux-policy-42.23-1.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.