Bug 2175290 - more specific label for /dev/userfaultfd
Summary: more specific label for /dev/userfaultfd
Keywords:
Status: VERIFIED
Alias: None
Product: Red Hat Enterprise Linux 9
Classification: Red Hat
Component: selinux-policy
Version: 9.2
Hardware: All
OS: Linux
medium
medium
Target Milestone: rc
: ---
Assignee: Zdenek Pytela
QA Contact: Milos Malik
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-03-03 19:22 UTC by Milos Malik
Modified: 2023-07-18 07:07 UTC (History)
5 users (show)

Fixed In Version: selinux-policy-38.1.15-1.el9
Doc Type: No Doc Update
Doc Text:
Clone Of:
Environment:
Last Closed:
Type: Bug
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github fedora-selinux selinux-policy pull 1738 0 None open Label /dev/userfaultfd with userfaultfd_t 2023-06-14 11:42:25 UTC
Red Hat Issue Tracker RHELPLAN-150655 0 None None None 2023-03-03 19:22:49 UTC

Description Milos Malik 2023-03-03 19:22:18 UTC
Description of problem:
 * SELinux policy does not define a more specific label for the /dev/userfaultfd

Version-Release number of selected component (if applicable):
selinux-policy-38.1.8-1.el9.noarch
selinux-policy-targeted-38.1.8-1.el9.noarch
selinux-policy-devel-38.1.8-1.el9.noarch

How reproducible:
 * always

Steps to Reproduce:
# matchpathcon /dev/userfaultfd 
/dev/userfaultfd	system_u:object_r:device_t:s0
# ls -lZ /dev/userfaultfd 
crw-------. 1 root root system_u:object_r:device_t:s0 10, 126 Mar  3 12:39 /dev/userfaultfd
#

Comment 2 Zdenek Pytela 2023-06-15 09:10:45 UTC
Commit to backport:
8f7ccc6e2 (HEAD -> rawhide, upstream/rawhide) Label /dev/userfaultfd with userfaultfd_t


Note You need to log in before you can comment on or make changes to this bug.