Closed Geomancer626 closed 1 year ago
Encountered this too. Is there a known workaround?
Please file a bug in bugzilla for the SELinux policy.
@Geomancer626 @mooreye please link here when you create the bug on Fedora's bugzilla, please, or state if you haven't. Also having this issue, using the big hammer to avoid it ( setenforce 0
), would prefer to use a finer-grained approach.
Thanks!
@Segment0895 @mooreye Sorry for the delay. I did not create a new report on the Fedora bugzilla as I turned up two existing entries by the time I went to report. They can be located at the following URLs and have better solutions which involve altering the SElinux policy for Wireguard. Follow the instructions in either report to get it functioning again.
Describe the bug Attempting to start a Wireguard tunnel through the systemd service results in a permission denied error for nft attempting to access /dev/fd/63. The tunnel is successfully created when issued through the wg-quick command instead of the systemd service "wg-quick up 'config name'. Setting SELinux to permissive allows the systemd service to function normally. SELinux audit logs show the following denials.
To Reproduce
Expected behavior The Wireguard tunnel is successfully created.
OS version: