Description of problem: Every device should be labeled with some non-generic SELinux label so that we can be sure that the access control is properly applied. On Fedora rawhide, there are some device_t /dev entries. Version-Release number of selected component (if applicable): selinux-policy-targeted-3.14.7-8.fc34.noarch How reproducible: Deterministic. Steps to Reproduce: 1. find /dev -context *:device_t:* \( -type c -o -type b \) -printf "%p %Z\n" Actual results: /dev/zram0 system_u:object_r:device_t:s0 /dev/udmabuf system_u:object_r:device_t:s0 /dev/dma_heap/system system_u:object_r:device_t:s0 Expected results: No output. Additional info:
I believe this bug is a duplicate of BZ#1894939.
*** This bug has been marked as a duplicate of bug 1894939 ***