Bug 1546362

Summary: no transition to wireshark_t + wrong file context pattern
Product: Red Hat Enterprise Linux 7 Reporter: Milos Malik <mmalik>
Component: selinux-policyAssignee: Lukas Vrabec <lvrabec>
Status: CLOSED WONTFIX QA Contact: Milos Malik <mmalik>
Severity: medium Docs Contact:
Priority: medium    
Version: 7.5CC: lvrabec, mgrepl, mmalik, plautrba, ssekidde, zpytela
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 1711005 (view as bug list) Environment:
Last Closed: 2019-03-14 10:40:49 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Milos Malik 2018-02-16 21:12:54 UTC
Description of problem:
* incorrect file context pattern causes that wireshark and tshark run unconfined
* even if the file context pattern for wireshark was correct, there is no transition into wireshark_t domain
* if we are serious about using the wireshark policy then both utilities wireshark (GUI) and tshark (text) should have the same label and they should run in wireshark_t domain

Version-Release number of selected component (if applicable):
selinux-policy-3.13.1-189.el7.noarch
selinux-policy-devel-3.13.1-189.el7.noarch
selinux-policy-targeted-3.13.1-189.el7.noarch
wireshark-1.10.14-14.el7.x86_64
wireshark-gnome-1.10.14-14.el7.x86_64

How reproducible:
* always

Steps to Reproduce:
# semanage fcontext -l | grep wireshark_exec_t
/usr/bin/wireshark                                 regular file       system_u:object_r:wireshark_exec_t:s0 
# ls -Z /usr/bin/wireshark
ls: cannot access /usr/bin/wireshark: No such file or directory
# ls -Z /usr/sbin/wireshark
-rwxr-xr-x. root root system_u:object_r:bin_t:s0       /usr/sbin/wireshark
# rpm -qf /usr/sbin/wireshark
wireshark-gnome-1.10.14-14.el7.x86_64
# sesearch -t wireshark_exec_t -T

#

Comment 5 Zdenek Pytela 2019-03-14 10:40:49 UTC
This issue was not selected to be included in Red Hat Enterprise Linux 7.7 because it is seen either as low or moderate impact to a small number of use-cases. The next release will be in Maintenance Support 1 Phase, which means that qualified Critical and Important Security errata advisories (RHSAs) and Urgent Priority Bug Fix errata advisories (RHBAs) may be released as they become available.

We will now close this issue, but if you believe that it qualifies for the Maintenance Support 1 Phase, please re-open; otherwise, we recommend moving the request to Red Hat Enterprise Linux 8 if applicable.