SELinux is preventing gstglcontext from write access on the file /memfd:/.nvidia_drv.XXXXXX (deleted). ***** Plugin restorecon (99.5 confidence) suggests ************************ If you want to fix the label. /memfd:/.nvidia_drv.XXXXXX (deleted) default label should be default_t. Then you can run restorecon. The access attempt may have been stopped due to insufficient permissions to access a parent directory in which case try to change the following command accordingly. Do # /sbin/restorecon -v /memfd:/.nvidia_drv.XXXXXX (deleted) ***** Plugin catchall (1.49 confidence) suggests ************************** If you believe that gstglcontext should be allowed write access on the .nvidia_drv.XXXXXX (deleted) file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'gstglcontext' --raw | audit2allow -M my-gstglcontext # semodule -X 300 -i my-gstglcontext.pp Additional Information: Source Context unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 Target Context system_u:object_r:xserver_tmpfs_t:s0 Target Objects /memfd:/.nvidia_drv.XXXXXX (deleted) [ file ] Source gstglcontext Source Path gstglcontext Port Host coyote Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-3.14.6-36.fc33.noarch Local Policy RPM selinux-policy-targeted-3.14.6-36.fc33.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name coyote Platform Linux coyote 5.11.11-200.fc33.x86_64 #1 SMP Tue Mar 30 16:53:32 UTC 2021 x86_64 x86_64 Alert Count 14 First Seen 2021-04-10 20:54:09 MDT Last Seen 2021-04-13 10:52:06 MDT Local ID 97b55286-0131-46f4-86ad-481e32b4563f Raw Audit Messages type=AVC msg=audit(1618332726.288:964): avc: denied { write } for pid=129605 comm="gstglcontext" path=2F6D656D66643A2F2E6E76696469615F6472762E585858585858202864656C6574656429 dev="tmpfs" ino=1025 scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_tmpfs_t:s0 tclass=file permissive=0 Hash: gstglcontext,thumb_t,xserver_tmpfs_t,file,write