first of all, thank you and jeff v as well. Since your reply I’ve been trying to learn more about selinux. I have re-enabled it, but in permissive mode to start. Regarding “Did you change anything related to the item in question?”, no I had not changed anything. What I did was to attempt to run snap remove, which basically hung without a message. Only later, after a reboot did I get the selinux popup. At that point I disabled selinux, rebooted, and was able to successfully run the snap remove command.
Since, I re-enabled selinux again and rebooted. It spent a long time relabeling everything. After logging in, I checked journalctl -t setroubleshoot --since= [time]
It shows 1 item:
Jan 21 19:48:54 fedora setroubleshoot[4658]: SELinux is preventing dbus-daemon from watch access on the directory /var/lib/snapd/dbus-1/services.
The detail on this is below.
I’m confused about this because I see that part of what was installed with snap was snapd-selinux. I can’t find anything that explains what that does but the implication is that it somehow tells selinux what it would need to know to allow snap to function without complaining.
As you can tell, I know next to nothing about this aspect of fedora so my guesses and intuition are essentially worthless.
I’m going to eliminate snap completely and reinstall the one thing that I was using (opera) a different way. I will then watch for future selinux messages and see if I can understand them without your help.
Thank you again
Additional Information:
Source Context system_u:system_r:xdm_t:s0-s0:c0.c1023
Target Context system_u:object_r:snappy_var_lib_t:s0
Target Objects /var/lib/snapd/dbus-1/services [ dir ]
Source dbus-daemon
Source Path dbus-daemon
Port
Host fedora
Source RPM Packages
Target RPM Packages snapd-2.57.6-2.fc37.x86_64
SELinux Policy RPM selinux-policy-targeted-37.18-1.fc37.noarch
Local Policy RPM selinux-policy-targeted-37.18-1.fc37.noarch
Selinux Enabled True
Policy Type targeted
Enforcing Mode Permissive
Host Name fedora
Platform Linux fedora 6.1.6-200.fc37.x86_64 #1 SMP
PREEMPT_DYNAMIC Sat Jan 14 16:55:06 UTC 2023
x86_64 x86_64
Alert Count 4
First Seen 2023-01-18 13:11:57 PST
Last Seen 2023-01-21 19:48:50 PST
Local ID 7b2d36d7-6ac5-419b-a860-1e5284cb7b89
Raw Audit Messages
type=AVC msg=audit(1674359330.420:724): avc: denied { watch } for pid=3930 comm=“dbus-daemon” path=“/var/lib/snapd/dbus-1/services” dev=“sda5” ino=9177360 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:snappy_var_lib_t:s0 tclass=dir permissive=1
Hash: dbus-daemon,xdm_t,snappy_var_lib_t,dir,watch