<div dir="ltr"><div>Package: selinux-policy-default<br>Version:  <span style="font-family:monospace"><span style="color:rgb(0,0,0);background-color:rgb(255,255,255)">2:2.20250213-10</span></span><br>Severity: normal<br><br>Dear Maintainer,<br><br>On Debian 13 with SELinux in Enforcing mode, snapperd starts but runs<br>with the SELinux domain initrc_t.<br><br>D-Bus requests to snapperd then time out. At the same time, SELinux AVC<br>denials are recorded for D-Bus send_msg operations with the source<br>context:<br><br>    system_u:system_r:initrc_t:s0<br><br>Observed behaviour:<br><br>* snapperd.service starts successfully.<br>* busctl introspection of the Snapper D-Bus service times out.<br>* snapper.real list-configs times out when using D-Bus.<br>* snapper.real -c root list times out when using D-Bus.<br>* The equivalent commands succeed immediately with --no-dbus.<br>* SELinux is in Enforcing mode.<br>* snapperd is running in initrc_t rather than a dedicated Snapper domain.<br><br>The installed Snapper package was rebuilt locally from the Debian<br>source package with only one functional packaging change:<br><br>    --enable-selinux<br><br>The rebuilt binary reports SELinux support. No local SELinux policy<br>module was added for Snapper.<br><br>This suggests that the current Debian SELinux policy does not provide<br>a suitable domain transition and/or D-Bus permissions for snapperd.<br><br>Attached are:<br><br>* system summary;<br>* relevant AVC records;<br>* results of the D-Bus tests;<br>* results of equivalent --no-dbus tests.<br><br>The complete diagnostic archive is available on request.<br><br>Regards,<br>Vadim</div><div><br></div><div><br></div></div>