# RL9: SELinux errors when starting Podman socket

**URL:** <https://forums.rockylinux.org/t/rl9-selinux-errors-when-starting-podman-socket/6676>\
**Category:** Rocky Linux Help & Support\
**Created:** [July 21, 2022, 2:51pm UTC](https://forums.rockylinux.org/t/rl9-selinux-errors-when-starting-podman-socket/6676 "2022-07-21T14:51:27Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![bertmelis](https://avatars.discourse-cdn.com/v4/letter/b/d07c76/32.png) [@bertmelis](https://forums.rockylinux.org/u/bertmelis)\
**Post date:** [July 21, 2022, 2:51pm UTC](https://forums.rockylinux.org/t/rl9-selinux-errors-when-starting-podman-socket/6676/1 "2022-07-21T14:51:27Z")

</div>

I have a clean install of RL9 and installed Podman.  
As a non-root user (although sudo powers) I tried to start the Podman socket via the cockpit console. SELinux was flooded with errors:

```auto
		SELinux is preventing /usr/bin/podman from create access on the file labeled etc_t.	
		SELinux is preventing /usr/bin/rpm from setattr access on the file rpmdb.sqlite-wal.	
		SELinux is preventing /usr/bin/podman from getattr access on the sock_file /run/podman/podman.sock.	
		SELinux is preventing /usr/bin/podman from read access on the file system.journal.	
		SELinux is preventing /usr/bin/podman from map access on the file /run/log/journal/45e3664c7d634182a97fbf7c7a666028/system.journal.	
		SELinux is preventing /usr/bin/podman from watch access on the directory /run/log/journal.

```

Is this intentional? Obviously, Podman doesn’t start.  
Any hints on how to deal with this?

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [July 21, 2022, 2:53pm UTC](https://forums.rockylinux.org/t/rl9-selinux-errors-when-starting-podman-socket/6676/2 "2022-07-21T14:53:01Z")

</div>

Please show the exact podman command that you used instead of just the results. It helps to see all information for anyone to be able to assist as we are unable to guess.

---

<div class="post-metadata">

**Author:** ![bertmelis](https://avatars.discourse-cdn.com/v4/letter/b/d07c76/32.png) [@bertmelis](https://forums.rockylinux.org/u/bertmelis)\
**Post date:** [July 21, 2022, 2:57pm UTC](https://forums.rockylinux.org/t/rl9-selinux-errors-when-starting-podman-socket/6676/3 "2022-07-21T14:57:39Z")

</div>

- Clean install of RL9
- `sudo dnf install podman cockpit-podman`
- opened the cockpit dashboard and went to the Pdoman Containers page
- Clicked “Start podman”

I didn’t use cli but clicked “start Podman” on the cockpit-podman page.

![image](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/2X/d/d0a6e6aee11351afe368e7e83ad16f98d518215a.png)

If I’m not mistaken, it starts the `podman.socket`.

 ![image](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/2X/9/93de209d32e6dd3718799def3e82c64188a06f8a.png)

It’s running with SELinux disbled, which is obviously not what I want.

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [July 21, 2022, 3:33pm UTC](https://forums.rockylinux.org/t/rl9-selinux-errors-when-starting-podman-socket/6676/4 "2022-07-21T15:33:44Z")

</div>

Did you disable selinux via /etc/selinux/config or did you just use setenforce temporarily to put in permissive mode? Or put it in permissive by editing /etc/selinux/config?

Ideally via ssh and get to root access and then do:

```auto
systemctl stop podman.socket
setenforce 1
systemctl start podman.socket

```

if it fails, take a look at /var/log/audit/audit.log and see if anything then shows up. You can also do:

```auto
audit2why -a /var/log/audit/audit.log

```

and this should print out what has happened and what remedy needs to be taken to get selinux to allow it to work.

---

<div class="post-metadata">

**Author:** ![bertmelis](https://avatars.discourse-cdn.com/v4/letter/b/d07c76/32.png) [@bertmelis](https://forums.rockylinux.org/u/bertmelis)\
**Post date:** [July 21, 2022, 3:51pm UTC](https://forums.rockylinux.org/t/rl9-selinux-errors-when-starting-podman-socket/6676/5 "2022-07-21T15:51:40Z")

</div>

```auto
type=AVC msg=audit(1658414107.681:233): avc: denied { read } for pid=7964 comm="podman" name="journal" dev="tmpfs" ino=65 scontext=system_u:system_r:container_runtime_t:s0 tcontext=system_u:object_r:syslogd_var_run_t:s0 tclass=dir permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1658414107.801:234): avc: denied { quotamod } for pid=7964 comm="podman" scontext=system_u:system_r:container_runtime_t:s0 tcontext=system_u:object_r:fs_t:s0 tclass=filesystem permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1658414107.816:235): avc: denied { create } for pid=7964 comm="podman" name="net.d" scontext=system_u:system_r:container_runtime_t:s0 tcontext=system_u:object_r:etc_t:s0 tclass=dir permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1658414107.819:236): avc: denied { create } for pid=7964 comm="podman" name="net.d" scontext=system_u:system_r:container_runtime_t:s0 tcontext=system_u:object_r:etc_t:s0 tclass=dir permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

```

The list goes on and on because the service tries to restart.

It’s always missing type information, for net.d and journal and…

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [July 21, 2022, 4:01pm UTC](https://forums.rockylinux.org/t/rl9-selinux-errors-when-starting-podman-socket/6676/6 "2022-07-21T16:01:15Z")

</div>

OK, so we can now allow it. First you can do:

```auto
audit2allow -a /var/log/audit/audit.log

```

this will generate a smaller amount of text with the type enforcement rules that would allow it to run/work. Then we generate a module:

```auto
audit2allow -a /var/log/audit/audit.log -M podman

```

this will generate you a file called `podman.pp`, and we can then apply this with:

```auto
semodule -i podman.pp

```

then it should work with selinux enabled.

---

<div class="post-metadata">

**Author:** ![bertmelis](https://avatars.discourse-cdn.com/v4/letter/b/d07c76/32.png) [@bertmelis](https://forums.rockylinux.org/u/bertmelis)\
**Post date:** [July 21, 2022, 5:11pm UTC](https://forums.rockylinux.org/t/rl9-selinux-errors-when-starting-podman-socket/6676/7 "2022-07-21T17:11:50Z")

</div>

Of course your solution worked. Thank you!

But allow me to make a remark that in RL8, this wasn’t needed. I understand many things changed for the better and this is (for me) something unexpected.

I’m happy it works now though.

---

<div class="post-metadata">

**Author:** ![nousrnm](https://avatars.discourse-cdn.com/v4/letter/n/a3d4f5/32.png) [@nousrnm](https://forums.rockylinux.org/u/nousrnm)\
**Post date:** [July 21, 2022, 6:39pm UTC](https://forums.rockylinux.org/t/rl9-selinux-errors-when-starting-podman-socket/6676/8 "2022-07-21T18:39:12Z")

</div>

The solutions allows to correctly start the service, but on the cockpit podman page you can’t do anything with each container cause SELinux is blocking all the commands.

For exemple when I want to start a container or if I want to see the logs I get errors and these logs appears on SELinux page:

 ![Immagine 2022-07-21 203821](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/2X/9/903e3bb6d20a3a5245cc63ef361124baf5669606.png)

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [July 21, 2022, 6:46pm UTC](https://forums.rockylinux.org/t/rl9-selinux-errors-when-starting-podman-socket/6676/9 "2022-07-21T18:46:04Z")

</div>

That means you need to run the same commands as in the solution to allow the remaining problems that selinux is blocking.

The combination of audit2why, audit2allow, semodule allow you to fix selinux problems. That’s what the tools are there for. So any subsequent blockages also need to be allowed.

---

<div class="post-metadata">

**Author:** ![nousrnm](https://avatars.discourse-cdn.com/v4/letter/n/a3d4f5/32.png) [@nousrnm](https://forums.rockylinux.org/u/nousrnm)\
**Post date:** [July 21, 2022, 7:24pm UTC](https://forums.rockylinux.org/t/rl9-selinux-errors-when-starting-podman-socket/6676/10 "2022-07-21T19:24:01Z")

</div>

Thank you, I will try.

For fun I also tried with the latest CentOs version and everything work out of the box. Also in the previous version of RockyLinux everything worked out of the box.  
Block that service is a specific choice or a “bug”?

Sorry for the question but I was courious of this different behaviour.  
Thank you again.

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [July 21, 2022, 7:36pm UTC](https://forums.rockylinux.org/t/rl9-selinux-errors-when-starting-podman-socket/6676/11 "2022-07-21T19:36:42Z")

</div>

Bear in mind CentOS Stream is not the same thing. The only real thing to compare with would be to install RHEL9 and see if the same problems exist. Chances are it may do, in which case a bug report most likely exists for it and would be fixed in due course.

---

<div class="post-metadata">

**Author:** ![nousrnm](https://avatars.discourse-cdn.com/v4/letter/n/a3d4f5/32.png) [@nousrnm](https://forums.rockylinux.org/u/nousrnm)\
**Post date:** [July 22, 2022, 6:42pm UTC](https://forums.rockylinux.org/t/rl9-selinux-errors-when-starting-podman-socket/6676/12 "2022-07-22T18:42:25Z")

</div>

Sorry, it’s me again. I had the opportunity to try RHEL9 with a developer subscription and a fresh install (like I did with Rocky). Everything seems to work out of the box.  
The podman service correctly start and you can use the cockpit page to manage the system container without errors and SELinux logs.  
I’m a newbie with Linux so if you need some other informations let me know. I also see there is already a bug report here on the RockyLinux section ([0000147: Rocky Linux 9 Podman无法成功启动 - Rocky BugTracker](https://bugs.rockylinux.org/view.php?id=147)).

Thank you and best.

---

<div class="post-metadata">

**Author:** ![brian](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/brian/32/5777_2.png) [@brian](https://forums.rockylinux.org/u/brian)\
**Post date:** [August 25, 2023, 3:44am UTC](https://forums.rockylinux.org/t/rl9-selinux-errors-when-starting-podman-socket/6676/13 "2023-08-25T03:44:49Z")

</div>


