Bug 1850029

Summary: TCP/UDP Port 61000 neither covered in unreserved_port_t nor in ephemeral_port_t
Product: Red Hat Enterprise Linux 8 Reporter: info
Component: selinux-policyAssignee: Zdenek Pytela <zpytela>
Status: CLOSED DUPLICATE QA Contact: Milos Malik <mmalik>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 8.2CC: lvrabec, mmalik, plautrba, ssekidde
Target Milestone: rc   
Target Release: 8.0   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-06-23 12:34:58 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description info 2020-06-23 12:22:19 UTC
Description of problem:
Often it is necessary to permit access to all high-ports. Normally one would use unreserved_port_t for that - and in addition ephemeral_port_t where the system makes this distinction. On EL 8 the port 61000 for TCP and UDP is in neighther range anymore (it has been within ephemeral_port_t on EL7).

Version-Release number of selected component (if applicable):
3.14.3-41.el8_2.4

How reproducible:
sepolicy network -p 61000

Steps to Reproduce:
1. check with "sepolicy network -p 61000" (only defined for sctp)
2. compare with other ephemeral port "sepolicy network -p 60999"
3. compare with other unreserved port "sepolicy network -p 61001"

Actual results:
Port only in unreserved_port_t for SCTP

Expected results:
Port in eigther ephemeral_port_t (EL7 like) or unreserverd_port_t also for UDP and TCP

Additional info:
-

Comment 1 Zdenek Pytela 2020-06-23 12:34:58 UTC

*** This bug has been marked as a duplicate of bug 1794531 ***