Fedora Account System
Red Hat Associate
Red Hat Customer
After updating selinux-policy and selinux-policy-targeted to 0:44.7-1.fc44, my sshfs broke. I could not figure out what exactly changed that caused this breakage, but I had a lot of permission denied errors, that went away after downgrading these two packages from 44.7-1.fc44 to 0:43.2-1.fc44 on host and client machines. Please let me know if you CAN'T reproduce, so I can try and find more information about this. Reproducible: Always Steps to Reproduce: 1. update packages to 44.7-1.fc44 2. something about ssh public key authentication stops working Actual Results: sshfs starts to not work Expected Results: sshfs to keep working
Probably a variant of Bug 2523732 But a copy of the AVC lines from /var/log/audit/audit.log could be useful.
Please update to selinux-policy-44.8-1.fc44 and if the issue persists, attach output of ausearch -i -m avc,user_avc,selinux_err,user_selinux_err -ts today
I updated server and client to selinux-policy-44.8-1.fc44, but the issue persists. Here is the output of "ausearch -i -m avc,user_avc,selinux_err,user_selinux_err -ts today": # When sshfs is working with an older version of selinux-policy: ---- type=AVC msg=audit(09/01/2026 ##:06:17.357:6913950) : avc: denied { search } for pid=37526 comm=sshd-session name=/ dev="dm-4" ino=256 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unlabeled_t:s0 tclass=dir permissive=1 ---- # When sshfs not working with selinux-policy-44.8-1.fc44: ---- type=AVC msg=audit(09/01/2026 ##:41:27.155:158) : avc: denied { getattr } for pid=3924 comm=sshd-session path=/servername/.ssh/authorized_keys dev="dm-1" ino=17094554 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:default_t:s0 tclass=file permissive=0 ---- type=AVC msg=audit(09/01/2026 ##:41:30.294:165) : avc: denied { getattr } for pid=3926 comm=sshd-session path=/servername/.ssh/authorized_keys dev="dm-1" ino=17094554 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:default_t:s0 tclass=file permissive=0 ----
Both unlabeled_t and default_t indicate an issue with labeling. The unlabeled_t label is usually displayed when a file was created in SELinux disabled state or when its actual label does not currently exist. The default_t type is assigned to filesystem objects that do not match any pattern in file-context configuration.
Besides, the name "/servername" seems a bit unusual for a home directory. sshfs works if the home directory is a subdirectory of /home.
I just suggest to update, new builds should be available on Monday.