Bug 2175290

Summary: more specific label for /dev/userfaultfd
Product: Red Hat Enterprise Linux 9 Reporter: Milos Malik <mmalik>
Component: selinux-policyAssignee: Zdenek Pytela <zpytela>
Status: VERIFIED --- QA Contact: Milos Malik <mmalik>
Severity: medium Docs Contact:
Priority: medium    
Version: 9.2CC: lvrabec, mburket, mmalik, vpolasek, zpytela
Target Milestone: rcKeywords: Triaged
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: selinux-policy-38.1.15-1.el9 Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Milos Malik 2023-03-03 19:22:18 UTC
Description of problem:
 * SELinux policy does not define a more specific label for the /dev/userfaultfd

Version-Release number of selected component (if applicable):
selinux-policy-38.1.8-1.el9.noarch
selinux-policy-targeted-38.1.8-1.el9.noarch
selinux-policy-devel-38.1.8-1.el9.noarch

How reproducible:
 * always

Steps to Reproduce:
# matchpathcon /dev/userfaultfd 
/dev/userfaultfd	system_u:object_r:device_t:s0
# ls -lZ /dev/userfaultfd 
crw-------. 1 root root system_u:object_r:device_t:s0 10, 126 Mar  3 12:39 /dev/userfaultfd
#

Comment 2 Zdenek Pytela 2023-06-15 09:10:45 UTC
Commit to backport:
8f7ccc6e2 (HEAD -> rawhide, upstream/rawhide) Label /dev/userfaultfd with userfaultfd_t