Bug 2541402 - systemd-imds-early-network.service fails at boot with AVC denials
Summary: systemd-imds-early-network.service fails at boot with AVC denials
Keywords:
Status: ON_QA
Alias: None
Product: Fedora
Classification: Fedora
Component: systemd
Version: rawhide
Hardware: x86_64
OS: Linux
medium
medium
Target Milestone: ---
Assignee: systemd-maint
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: AcceptedBlocker
Depends On:
Blocks: F45FinalBlocker, FinalBlocker
TreeView+ depends on / blocked
 
Reported: 2026-09-25 12:57 UTC by Petr Sklenar
Modified: 2026-09-30 01:53 UTC (History)
17 users (show)

Fixed In Version: systemd-262-3.fc46
Clone Of:
Environment:
Last Closed: 2026-09-29 16:37:35 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
journalctl -b (236.98 KB, text/plain)
2026-09-26 09:01 UTC, Petr Sklenar
no flags Details

Description Petr Sklenar 2026-09-25 12:57:12 UTC
Description of problem:
systemd-imds-early-network.service is in failed state.

Version-Release number of selected component:
selinux-policy-targeted-45.19-1.fc45.noarch
systemd-262-1.fc45.x86_64
kernel 7.2.7-300.fc45.x86_64


my fedora release: Fedora-Cloud-Base-AmazonEC2.x86_64-45-Prerelease-20260921.0


How reproducible:
Always (100%)

Steps to Reproduce:
1. systemctl --failed
2. systemctl status systemd-imds-early-network.service
3. journalctl -b | grep -iE 'avc.*imds'

Actual results:
x systemd-imds-early-network.service - Enable Pre-IMDS Networking
     Active: failed (Result: exit-code)
   Main PID: 586 (code=exited, status=1/FAILURE)

systemd-imdsd[586]: Failed to create 85-imds-early.network file: Permission denied
systemd-imdsd[586]: Failed to write IMDS RR data: Permission denied
systemd-imds-early-network.service: Failed with result 'exit-code'.

AVC denials (SELinux Enforcing):
avc: denied { write }  pid=586 comm="systemd-imdsd" path="/run/systemd/network/#1687 (deleted)"
     scontext=system_u:system_r:init_t:s0 tcontext=system_u:object_r:net_conf_t:s0 tclass=file permissive=0

avc: denied { create } pid=586 comm="systemd-imdsd" name=".#85-imds-early.network99ed0c802ba21ff1"
     scontext=system_u:system_r:init_t:s0 tcontext=system_u:object_r:net_conf_t:s0 tclass=file permissive=0

avc: denied { create } pid=586 comm="systemd-imdsd" name=".#imds-endpoint.rr4cf31dc6e1f9f0dc"
     scontext=system_u:system_r:init_t:s0 tcontext=system_u:object_r:systemd_resolved_var_run_t:s0 tclass=file permissive=0

Expected results:
systemd-imds-early-network.service starts without failure; no AVC denials.

Additional info:
OS: Fedora 45, AWS EC2
SELinux: Enforcing

Comment 1 Petr Sklenar 2026-09-25 13:03:19 UTC
its starts in permissive mode:

# getenforce 
Permissive
[root@ip-172-31-29-11 ~]# systemctl stop systemd-imds-early-network.service
[root@ip-172-31-29-11 ~]# systemctl start systemd-imds-early-network.service
[root@ip-172-31-29-11 ~]# systemctl status systemd-imds-early-network.service
● systemd-imds-early-network.service - Enable Pre-IMDS Networking
     Loaded: loaded (/usr/lib/systemd/system/systemd-imds-early-network.service; enabled-runtime; preset: disabled)
    Drop-In: /usr/lib/systemd/system/service.d
             └─10-timeout-abort.conf
             /run/systemd/generator.early/systemd-imds-early-network.service.d
             └─50-dmi-id.conf
     Active: active (exited) since Fri 2026-09-25 12:59:28 UTC; 6s ago
 Invocation: 8ed7b32600a2416a8282a9a27643ad4b
       Docs: man:systemd-imdsd@.service(8)
    Process: 3324 ExecStart=/usr/lib/systemd/systemd-imdsd --setup-network (code=exited, status=0/SUCCESS)
   Main PID: 3324 (code=exited, status=0/SUCCESS)
   Mem peak: 2M
        CPU: 11ms

Comment 2 Fedora Blocker Bugs Application 2026-09-25 13:15:59 UTC
Proposed as a Blocker for 45-final by Fedora user psklenar using the blocker tracking app because:

 after system is started , one  service is not started:

Last login: Fri Sep 25 13:10:28 2026 from 3.15.154.109
[systemd]
Failed Units: 1
  systemd-imds-early-network.service

I believed its a blocker due to:
https://fedoraproject.org/wiki/Fedora_45_Final_Release_Criteria#System_services

Comment 3 Petr Sklenar 2026-09-25 13:33:18 UTC
AI note:

The IMDS feature was introduced in systemd 261.

Upstream systemd v261 release notes (NEWS), 2026-06-19 - the "IMDS
subsystem" section documents systemd-imdsd, systemd-imds and the
systemd-imds-early-network / generator that pull the service into boot
when a supported cloud is detected:
  https://github.com/systemd/systemd/releases/tag/v261

systemd 260 does not ship these files; systemd 261 is the first that does.
selinux-policy has no rules for this feature yet, so the service fails
under SELinux Enforcing.

Comment 4 Zdenek Pytela 2026-09-25 14:19:31 UTC
Thanks for reporting. Confining a new service takes months and we unfortunately don't have test coverage.
Moreover, the service seems not to be enabled by default so I don't think it qualifies for a blocker.

Comment 5 Petr Sklenar 2026-09-25 14:31:38 UTC
(In reply to Zdenek Pytela from comment #4)
> Moreover, the service seems not to be enabled by default ...

It seems that 'systemd-imds-generator' recognizes cloud, and starts systemd-imds-early-network.
In other words its default at each cloud (amazon-ec2, Azure, ...)

Comment 6 Zdenek Pytela 2026-09-25 14:47:01 UTC
(In reply to Petr Sklenar from comment #5)
> (In reply to Zdenek Pytela from comment #4)
> > Moreover, the service seems not to be enabled by default ...
> 
> It seems that 'systemd-imds-generator' recognizes cloud, and starts
> systemd-imds-early-network.
> In other words its default at each cloud (amazon-ec2, Azure, ...)

OK, taking back. The first part keeps being valid - the report came too late for full service confinement, so I don't think it is reasonable to block the release.

If you still have the system at hand, can you boot the system in permissive mode and gather all denials?

Comment 7 Adam Williamson (Fedora) 2026-09-25 21:45:48 UTC
Well, we don't have to write a new policy to address the blocker, necessarily. We could also simply disable the service by default. Presumably it doesn't do anything anyway since it's blocked by SELinux, so disabling it shouldn't make anything worse?

Let's CC zbyszsek for his opinion.

Comment 8 Petr Sklenar 2026-09-26 09:01:15 UTC
Created attachment 2158678 [details]
journalctl -b

journalctl -b > journalctl-b

The AVCs can be find in journalctl-b.

The denials happen in early boot - systemd-imds-early-network.service runs
in sysinit.target, before auditd is ready to write. So 'ausearch' dont find such a denials

Comment 9 Petr Sklenar 2026-09-26 09:30:45 UTC
(In reply to Petr Sklenar from comment #8)
during SELINUX=permissive in /etc/selinux/config

Comment 10 Adam Williamson (Fedora) 2026-09-28 20:10:59 UTC
Discussed in 2026-09-28 blocker review meeting: https://meetbot-raw.fedoraproject.org//blocker-review_matrix_fedoraproject-org/2026-09-28/f45-blocker-review.2026-09-28-16.00.html . This is accepted as a blocker as a violation of final criterion "All system services present after installation with one of the release-blocking package sets must start properly, unless they require hardware which is not present". We note that disabling the service by default would be an acceptable resolution; if that's the only practical option, the bug should be re-assigned to systemd.

Comment 11 Fedora Update System 2026-09-29 14:35:01 UTC
FEDORA-2026-430ec11225 (systemd-262-3.fc46) has been submitted as an update to Fedora 46.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-430ec11225

Comment 12 Fedora Update System 2026-09-29 15:42:17 UTC
FEDORA-2026-e3388d1568 (systemd-262-3.fc45) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-e3388d1568

Comment 13 Zbigniew Jędrzejewski-Szmek 2026-09-29 15:44:18 UTC
Eventually, the SELinux policy will need to be updated too. Do we need a separate bugzilla to track this?

Comment 14 Petr Sklenar 2026-09-29 15:53:20 UTC
Thanks for the quick fix!

yes,  I'll open a separate BZ for selinux-policy.

+could you please reassign this Bugzilla to the systemd component?

Comment 15 Zbigniew Jędrzejewski-Szmek 2026-09-29 16:06:05 UTC
Great. (FWIW, anybody can reassign.)

Comment 16 Petr Sklenar 2026-09-29 16:07:34 UTC
(In reply to Zbigniew Jędrzejewski-Szmek from comment #15)
> Great. (FWIW, anybody can reassign.)
I see ...

thanks

filled Bug 2543273 - AVC denial: systemd-imds-early-network.service fails at boot with AVC denials

Comment 17 Fedora Update System 2026-09-29 16:37:35 UTC
FEDORA-2026-430ec11225 (systemd-262-3.fc46) has been pushed to the Fedora 46 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 18 Fedora Update System 2026-09-30 01:53:20 UTC
FEDORA-2026-e3388d1568 has been pushed to the Fedora 45 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-e3388d1568`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-e3388d1568

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.


Note You need to log in before you can comment on or make changes to this bug.