---- time->Fri Aug 29 21:26:44 2025 type=PROCTITLE msg=audit(1756517204.375:11736): proctitle=676574656E740067726F7570006D7373716C type=SYSCALL msg=audit(1756517204.375:11736): arch=c000003e syscall=42 success=no exit=-13 a0=4 a1=7ffc8b0f8160 a2=2d a3=0 items=0 ppid=70658 pid=70659 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=7 comm="getent" exe="/usr/bin/getent" subj=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1756517204.375:11736): avc: denied { connectto } for pid=70659 comm="getent" path="/run/systemd/userdb/io.systemd.DynamicUser" scontext=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 tcontext=system_u:system_r:kernel_t:s0 tclass=unix_stream_socket permissive=0 ---- time->Fri Aug 29 21:26:44 2025 type=PROCTITLE msg=audit(1756517204.375:11737): proctitle=676574656E740067726F7570006D7373716C type=SYSCALL msg=audit(1756517204.375:11737): arch=c000003e syscall=42 success=no exit=-13 a0=4 a1=7ffc8b0f8150 a2=2d a3=55c57adcda00 items=0 ppid=70658 pid=70659 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=7 comm="getent" exe="/usr/bin/getent" subj=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1756517204.375:11737): avc: denied { connectto } for pid=70659 comm="getent" path="/run/systemd/userdb/io.systemd.DynamicUser" scontext=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 tcontext=system_u:system_r:kernel_t:s0 tclass=unix_stream_socket permissive=0 ---- time->Fri Aug 29 21:26:44 2025 type=PROCTITLE msg=audit(1756517204.387:11738): proctitle=676574656E740067726F7570006D7373716C type=SYSCALL msg=audit(1756517204.387:11738): arch=c000003e syscall=42 success=no exit=-13 a0=4 a1=7ffe34b90050 a2=2d a3=0 items=0 ppid=70662 pid=70663 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=7 comm="getent" exe="/usr/bin/getent" subj=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1756517204.387:11738): avc: denied { connectto } for pid=70663 comm="getent" path="/run/systemd/userdb/io.systemd.DynamicUser" scontext=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 tcontext=system_u:system_r:kernel_t:s0 tclass=unix_stream_socket permissive=0 ---- time->Fri Aug 29 21:26:44 2025 type=PROCTITLE msg=audit(1756517204.387:11739): proctitle=676574656E740067726F7570006D7373716C type=SYSCALL msg=audit(1756517204.387:11739): arch=c000003e syscall=42 success=no exit=-13 a0=4 a1=7ffe34b90040 a2=2d a3=5561ede9da00 items=0 ppid=70662 pid=70663 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=7 comm="getent" exe="/usr/bin/getent" subj=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1756517204.387:11739): avc: denied { connectto } for pid=70663 comm="getent" path="/run/systemd/userdb/io.systemd.DynamicUser" scontext=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 tcontext=system_u:system_r:kernel_t:s0 tclass=unix_stream_socket permissive=0 ---- time->Fri Aug 29 21:26:44 2025 type=PROCTITLE msg=audit(1756517204.406:11740): proctitle=2F62696E2F7368002D63006966202020686173682064706B673B207468656E20636D643D2264706B67202D2D6C697374223B2020202020202020202020202020202020202020656C69662068617368202072706D3B207468656E20636D643D2272706D202D7161223B20202020202020202020202020202020202020656C7365 type=SYSCALL msg=audit(1756517204.406:11740): arch=c000003e syscall=262 success=no exit=-13 a0=ffffff9c a1=5581dd106260 a2=7fff742ea7a0 a3=0 items=0 ppid=70657 pid=70668 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=7 comm="sh" exe="/usr/bin/bash" subj=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1756517204.406:11740): avc: denied { getattr } for pid=70668 comm="sh" path="/usr/bin/rpm" dev="xvda1" ino=632552 scontext=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 tcontext=system_u:object_r:rpm_exec_t:s0 tclass=file permissive=0 ---- time->Fri Aug 29 21:26:44 2025 type=PROCTITLE msg=audit(1756517204.430:11743): proctitle=7375002D70002D63002F6F70742F6D7373716C2F62696E2F73716C7365727672202D2D7365747570202D2D72657365742D73612D70617373776F7264006D7373716C type=SYSCALL msg=audit(1756517204.430:11743): arch=c000003e syscall=42 success=no exit=-13 a0=4 a1=7ffcdd23fcf0 a2=2d a3=55cba1f0a750 items=0 ppid=70671 pid=70677 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=7 comm="su" exe="/usr/bin/su" subj=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1756517204.430:11743): avc: denied { connectto } for pid=70677 comm="su" path="/run/systemd/userdb/io.systemd.DynamicUser" scontext=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 tcontext=system_u:system_r:kernel_t:s0 tclass=unix_stream_socket permissive=0 ---- time->Fri Aug 29 21:26:44 2025 type=PROCTITLE msg=audit(1756517204.430:11745): proctitle=7375002D70002D63002F6F70742F6D7373716C2F62696E2F73716C7365727672202D2D7365747570202D2D72657365742D73612D70617373776F7264006D7373716C type=SYSCALL msg=audit(1756517204.430:11745): arch=c000003e syscall=42 success=no exit=-13 a0=4 a1=7ffcdd23f8b0 a2=2d a3=55cba1f0a700 items=0 ppid=70671 pid=70677 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=7 comm="su" exe="/usr/bin/su" subj=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1756517204.430:11745): avc: denied { connectto } for pid=70677 comm="su" path="/run/systemd/userdb/io.systemd.DynamicUser" scontext=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 tcontext=system_u:system_r:kernel_t:s0 tclass=unix_stream_socket permissive=0 ---- time->Fri Aug 29 21:26:50 2025 type=PROCTITLE msg=audit(1756517210.257:11749): proctitle="(sd-askpwagent)" type=SYSCALL msg=audit(1756517210.257:11749): arch=c000003e syscall=59 success=no exit=-13 a0=7f0f8fac4f78 a1=7ffd744c8170 a2=7ffd744c8a08 a3=0 items=0 ppid=70874 pid=70875 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=7 comm="(sd-askpwagent)" exe="/usr/bin/systemctl" subj=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 key=(null) type=SELINUX_ERR msg=audit(1756517210.257:11749): op=security_compute_sid invalid_context="unconfined_u:unconfined_r:systemd_passwd_agent_t:s0-s0:c0.c1023" scontext=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 tcontext=system_u:object_r:systemd_passwd_agent_exec_t:s0 tclass=process ---- time->Fri Aug 29 21:27:15 2025 type=PROCTITLE msg=audit(1756517235.876:12295): proctitle=676574656E740067726F7570006D7373716C type=SYSCALL msg=audit(1756517235.876:12295): arch=c000003e syscall=42 success=no exit=-13 a0=4 a1=7ffe552188d0 a2=2d a3=0 items=0 ppid=73964 pid=73965 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=7 comm="getent" exe="/usr/bin/getent" subj=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1756517235.876:12295): avc: denied { connectto } for pid=73965 comm="getent" path="/run/systemd/userdb/io.systemd.DynamicUser" scontext=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 tcontext=system_u:system_r:kernel_t:s0 tclass=unix_stream_socket permissive=0 ---- time->Fri Aug 29 21:27:15 2025 type=PROCTITLE msg=audit(1756517235.876:12296): proctitle=676574656E740067726F7570006D7373716C type=SYSCALL msg=audit(1756517235.876:12296): arch=c000003e syscall=42 success=no exit=-13 a0=4 a1=7ffe552188c0 a2=2d a3=55e2af08ba00 items=0 ppid=73964 pid=73965 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=7 comm="getent" exe="/usr/bin/getent" subj=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1756517235.876:12296): avc: denied { connectto } for pid=73965 comm="getent" path="/run/systemd/userdb/io.systemd.DynamicUser" scontext=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 tcontext=system_u:system_r:kernel_t:s0 tclass=unix_stream_socket permissive=0 ---- time->Fri Aug 29 21:27:15 2025 type=PROCTITLE msg=audit(1756517235.884:12297): proctitle=707974686F6E33002F6F70742F6D7373716C2F62696E2F2E2E2F6C69622F6D7373716C2D636F6E662F6D7373716C2D636F6E662E707900736574006E6574776F726B2E746370706F72740031343333 type=SYSCALL msg=audit(1756517235.884:12297): arch=c000003e syscall=42 success=no exit=-13 a0=4 a1=7ffec8e3a460 a2=10 a3=7fbd2cc189f1 items=0 ppid=73961 pid=73963 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=7 comm="python3" exe="/usr/bin/python3.9" subj=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1756517235.884:12297): avc: denied { name_connect } for pid=73963 comm="python3" dest=1433 scontext=unconfined_u:unconfined_r:mssql_conf_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mssql_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Fri Aug 29 21:27:56 2025 type=PROCTITLE msg=audit(1756517276.983:13015): proctitle="/opt/mssql/bin/sqlservr" type=SYSCALL msg=audit(1756517276.983:13015): arch=c000003e syscall=262 success=no exit=-2 a0=ffffff9c a1=7fc75dff53c0 a2=7fc75de7e0c0 a3=0 items=0 ppid=74272 pid=74298 auid=4294967295 uid=993 gid=993 euid=993 suid=993 fsuid=993 egid=993 sgid=993 fsgid=993 tty=(none) ses=4294967295 comm="sqlservr" exe="/opt/mssql/bin/sqlservr" subj=system_u:object_r:unlabeled_t:s0 key=(null) type=AVC msg=audit(1756517276.983:13015): avc: denied { search } for pid=74298 comm="sqlservr" name="mssql" dev="xvda1" ino=25166088 scontext=system_u:object_r:unlabeled_t:s0 tcontext=unconfined_u:object_r:var_t:s0 tclass=dir permissive=1 srawcon="system_u:system_r:mssql_server_t:s0" type=AVC msg=audit(1756517276.983:13015): avc: denied { search } for pid=74298 comm="sqlservr" name="var" dev="xvda1" ino=133 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:var_t:s0 tclass=dir permissive=1 srawcon="system_u:system_r:mssql_server_t:s0" type=AVC msg=audit(1756517276.983:13015): avc: denied { search } for pid=74298 comm="sqlservr" name="/" dev="xvda1" ino=128 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=dir permissive=1 srawcon="system_u:system_r:mssql_server_t:s0" ---- time->Fri Aug 29 21:27:58 2025 type=PROCTITLE msg=audit(1756517278.983:13061): proctitle="/opt/mssql/bin/sqlservr" type=SYSCALL msg=audit(1756517278.983:13061): arch=c000003e syscall=262 success=no exit=-2 a0=ffffff9c a1=7fc75dff53c0 a2=7fc75de7e0c0 a3=0 items=0 ppid=74272 pid=74298 auid=4294967295 uid=993 gid=993 euid=993 suid=993 fsuid=993 egid=993 sgid=993 fsgid=993 tty=(none) ses=4294967295 comm="sqlservr" exe="/opt/mssql/bin/sqlservr" subj=system_u:object_r:unlabeled_t:s0 key=(null) type=AVC msg=audit(1756517278.983:13061): avc: denied { search } for pid=74298 comm="sqlservr" name="mssql" dev="xvda1" ino=25166088 scontext=system_u:object_r:unlabeled_t:s0 tcontext=unconfined_u:object_r:var_t:s0 tclass=dir permissive=1 srawcon="system_u:system_r:mssql_server_t:s0" type=AVC msg=audit(1756517278.983:13061): avc: denied { search } for pid=74298 comm="sqlservr" name="var" dev="xvda1" ino=133 scontext=system_u:object_r:unlabeled_t:s0 tcontext=system_u:object_r:var_t:s0 tclass=dir permissive=1 srawcon="system_u:system_r:mssql_server_t:s0" ---- time->Fri Aug 29 21:28:31 2025 type=AVC msg=audit(1756517311.005:13977): avc: denied { signal } for pid=1 comm="systemd" scontext=system_u:system_r:init_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=process permissive=1 trawcon="system_u:system_r:mssql_server_t:s0" ---- time->Fri Aug 29 21:28:31 2025 type=AVC msg=audit(1756517311.008:13981): avc: denied { read } for pid=526 comm="systemd-journal" name="status" dev="proc" ino=272487 scontext=system_u:system_r:syslogd_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1 trawcon="system_u:system_r:mssql_server_t:s0" ---- time->Fri Aug 29 21:28:31 2025 type=AVC msg=audit(1756517311.008:13982): avc: denied { open } for pid=526 comm="systemd-journal" path="/proc/74298/status" dev="proc" ino=272487 scontext=system_u:system_r:syslogd_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1 trawcon="system_u:system_r:mssql_server_t:s0" ---- time->Fri Aug 29 21:28:31 2025 type=AVC msg=audit(1756517311.008:13983): avc: denied { getattr } for pid=526 comm="systemd-journal" path="/proc/74298/status" dev="proc" ino=272487 scontext=system_u:system_r:syslogd_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1 trawcon="system_u:system_r:mssql_server_t:s0" ---- time->Fri Aug 29 21:28:31 2025 type=AVC msg=audit(1756517311.008:13984): avc: denied { ioctl } for pid=526 comm="systemd-journal" path="/proc/74298/status" dev="proc" ino=272487 ioctlcmd=0x5401 scontext=system_u:system_r:syslogd_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1 trawcon="system_u:system_r:mssql_server_t:s0" ---- time->Fri Aug 29 21:28:31 2025 type=AVC msg=audit(1756517311.008:13985): avc: denied { read } for pid=526 comm="systemd-journal" name="exe" dev="proc" ino=273753 scontext=system_u:system_r:syslogd_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=lnk_file permissive=1 trawcon="system_u:system_r:mssql_server_t:s0" ---- time->Fri Aug 29 21:28:31 2025 type=AVC msg=audit(1756517311.008:13986): avc: denied { getattr } for pid=526 comm="systemd-journal" scontext=system_u:system_r:syslogd_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=process permissive=1 trawcon="system_u:system_r:mssql_server_t:s0"