type=AVC msg=audit(07/26/2024 20:25:44.393:606) : avc: denied { watch } for pid=7485 comm=gnome-software path=/var/cache/swcatalog/xml dev="sda3" ino=142166 scontext=user_u:user_r:user_t:s0 tcontext=system_u:object_r:var_t:s0 tclass=dir permissive=1
Without any context, these denials do not offer indication. It lacks context.
Please review related topics especially in github [1], and also in discourse [2] [3] to get some indication of what is necessary.
Also, I think at the moment, discourse does more develop to a central instance of the confined users SIG since we got our own tags there. I think this repo is currently not really active.
When you reviewed what information and elaboration is necessary, you might get more people to review it when opening a topic in discourse. Also, you might start with one topic and then let us elaborate in that one topic if these denials are related to each other or not.
This also counts for your other tickets here.
But in any case, thanks for contributing :) I'm happy to see that in several areas people start to get into this field. You are on of the first to work on gnome related issues!
By the way, when you elaborate what issue occurs during these denials, do not forgot to add the journal of the respective boot (journalctl --boot=0 for current boot or --boot=-1 for last boot) and let us know what time the denial is to be found. Plus the avcdenial output you see in many topics.
[1] https://github.com/fedora-selinux/selinux-policy/issues (in many tickets you can already read in the header that it is related to confined users) [2] https://discussion.fedoraproject.org/tags/c/project/7/confined-users [3] https://discussion.fedoraproject.org/tag/selinux-confined-users
Metadata Update from @py0xc3: - Issue status updated to: Closed (was: Open)