Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: Problem occurs when running any kind of selinux confined user in gnome. SELinux is preventing bwrap from 'mounton' accesses on the directory /. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that bwrap should be allowed mounton access on the directory by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'bwrap' --raw | audit2allow -M my-bwrap # semodule -X 300 -i my-bwrap.pp Additional Information: Source Context staff_u:staff_r:staff_t:s0-s0:c0.c1023 Target Context system_u:object_r:root_t:s0 Target Objects / [ dir ] Source bwrap Source Path bwrap Port <Unknown> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-42.22-1.fc43.noarch Local Policy RPM selinux-policy-targeted-42.22-1.fc43.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 6.18.7-200.fc43.x86_64 #1 SMP PREEMPT_DYNAMIC Fri Jan 23 16:42:34 UTC 2026 x86_64 Alert Count 8422 First Seen 2026-01-09 12:21:56 IST Last Seen 2026-02-01 15:48:43 IST Local ID 0f884186-6304-407a-b616-f790ef9d0435 Raw Audit Messages type=AVC msg=audit(1769941123.210:8284): avc: denied { mounton } for pid=39070 comm="bwrap" path="/" dev="nvme0n1p2" ino=2 scontext=staff_u:staff_r:staff_t:s0-s0:c0.c1023 tcontext=system_u:object_r:root_t:s0 tclass=dir permissive=0 Hash: bwrap,staff_t,root_t,dir,mounton Version-Release number of selected component: selinux-policy-targeted-42.22-1.fc43.noarch Additional info: reporter: libreport-2.17.15 kernel: 6.18.7-200.fc43.x86_64 component: selinux-policy comment: Problem occurs when running any kind of selinux confined user in gnome. type: libreport reason: SELinux is preventing bwrap from 'mounton' accesses on the directory /. hashmarkername: setroubleshoot package: selinux-policy-targeted-42.22-1.fc43.noarch component: selinux-policy
Created attachment 2127686 [details] File: os_info
Created attachment 2127687 [details] File: description
The resolution turned out to be more complex. Please try copr build from https://github.com/fedora-selinux/selinux-policy/pull/3051 if you can.
(In reply to Zdenek Pytela from comment #3) > The resolution turned out to be more complex. Please try copr build from > https://github.com/fedora-selinux/selinux-policy/pull/3051 > > if you can. Installing the copr build fixed the issue.
Thanks, merging then. Build on the way.
FEDORA-2026-3439e5656a (selinux-policy-42.23-1.fc43) has been submitted as an update to Fedora 43. https://bodhi.fedoraproject.org/updates/FEDORA-2026-3439e5656a
FEDORA-2026-3439e5656a (selinux-policy-42.23-1.fc43) has been pushed to the Fedora 43 stable repository. If problem still persists, please make note of it in this bug report.