Since it starts directly as root perhaps check for SELinux AVCs? Maybe a
relabel would help (or try permissive to catch the full set).
rob
unfortunately selinux was already in permissive mode and no recent avcs:
# ausearch -m avc -ts recent
<no matches>
The latest avc is from a few days agoi regarding the ipa_custodia which we do not use.
I did a restorecon -rv / and it corrected some labels, but no difference so far.