Bug 2523504 - Newest update to selinux breaks ssh [NEEDINFO]
Summary: Newest update to selinux breaks ssh
Keywords:
Status: CLOSED INSUFFICIENT_DATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 44
Hardware: x86_64
OS: Linux
unspecified
high
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-25 14:44 UTC by fygdxcyw
Modified: 2026-09-11 09:42 UTC (History)
9 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-09-11 09:42:25 UTC
Type: ---
Embargoed:
fygdxcyw: needinfo? (fedora-kernel-selinux)


Attachments (Terms of Use)

Description fygdxcyw 2026-08-25 14:44:42 UTC
After updating selinux-policy and selinux-policy-targeted to 0:44.7-1.fc44, my sshfs broke. I could not figure out what exactly changed that caused this breakage, but I had a lot of permission denied errors, that went away after downgrading these two packages from 44.7-1.fc44 to 0:43.2-1.fc44 on host and client machines.

Please let me know if you CAN'T reproduce, so I can try and find more information about this.

Reproducible: Always

Steps to Reproduce:
1. update packages to 44.7-1.fc44
2. something about ssh public key authentication stops working 
Actual Results:
sshfs starts to not work

Expected Results:
sshfs to keep working

Comment 1 Villy Kruse 2026-08-26 06:04:02 UTC
Probably a variant of Bug 2523732 

But a copy of the AVC lines from /var/log/audit/audit.log could be useful.

Comment 2 Zdenek Pytela 2026-08-31 08:46:55 UTC
Please update to selinux-policy-44.8-1.fc44 and if the issue persists, attach output of

ausearch -i -m avc,user_avc,selinux_err,user_selinux_err -ts today

Comment 3 fygdxcyw 2026-09-01 10:14:58 UTC
I updated server and client to selinux-policy-44.8-1.fc44, but the issue persists. Here is the output of "ausearch -i -m avc,user_avc,selinux_err,user_selinux_err -ts today":

# When sshfs is working with an older version of selinux-policy:

----
type=AVC msg=audit(09/01/2026 ##:06:17.357:6913950) : avc:  denied  { search } for  pid=37526 comm=sshd-session name=/ dev="dm-4" ino=256 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unlabeled_t:s0 tclass=dir permissive=1
----


# When sshfs not working with selinux-policy-44.8-1.fc44:

----
type=AVC msg=audit(09/01/2026 ##:41:27.155:158) : avc:  denied  { getattr } for  pid=3924 comm=sshd-session path=/servername/.ssh/authorized_keys dev="dm-1" ino=17094554 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:default_t:s0 tclass=file permissive=0
----
type=AVC msg=audit(09/01/2026 ##:41:30.294:165) : avc:  denied  { getattr } for  pid=3926 comm=sshd-session path=/servername/.ssh/authorized_keys dev="dm-1" ino=17094554 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:default_t:s0 tclass=file permissive=0
----

Comment 4 Zdenek Pytela 2026-09-07 15:16:54 UTC
Both unlabeled_t and default_t indicate an issue with labeling.

The unlabeled_t label is usually displayed when a file was created in SELinux disabled state or when its actual label does not currently exist.

The default_t type is assigned to filesystem objects that do not match any pattern in file-context configuration.

Comment 5 Villy Kruse 2026-09-08 06:21:02 UTC
Besides, the name "/servername" seems a bit unusual for a home directory.  sshfs works if the home directory is a subdirectory of /home.

Comment 6 Zdenek Pytela 2026-09-11 09:42:25 UTC
I just suggest to update, new builds should be available on Monday.


Note You need to log in before you can comment on or make changes to this bug.