- 
    Bug 
- 
    Resolution: Done-Errata
- 
    Normal 
- 
    rhel-9.3.0.z
- 
        selinux-policy-38.1.53-2.el9
- 
        None
- 
        Moderate
- 
        3
- 
        rhel-security-selinux
- 
        ssg_security
- 
        25
- 
        3
- 
        QE ack
- 
        False
- 
        False
- 
        
- 
        No
- 
        Red Hat Enterprise Linux
- 
        SELINUX 241106 - 241127, SELINUX 241127 - 241218, SELINUX 250129: 1
- 
        
- 
        Pass
- 
        Automated
- 
        Release Note Not Required
- 
        documented inRHEL-17346
- 
        Done
- 
        
- 
        x86_64
- 
        None
What were you trying to do that didn't work?
the power-profiles-daemon process runs under the "unconfined_service_t" label which means that the system can't pass the CIS 9 - "1.6.1.6 Ensure no unconfined services exist (Automated)".
Please provide the package NVR for which bug is seen:
How reproducible:
always
Steps to reproduce
- Fresh install the RHEL9 with "Server with GUI".
- Switch the system to graphical.target via "systemctl set-default graphical.target"
- Check the process label via "ps -eZ|egrep 'unconfined_service_t'"
Expected results
the power-profiles-daemon process(es) are confined by SELinux, they do not run under the "unconfined_service_t" label
Actual results
# cat /etc/redhat-release Red Hat Enterprise Linux release 9.3 (Plow) # systemctl get-default graphical.target # ps -eZ|egrep 'unconfined_service_t' system_u:system_r:unconfined_service_t:s0 862 ? 00:00:00 power-profiles- system_u:system_r:unconfined_service_t:s0 865 ? 00:00:00 switcheroo-cont #
- clones
- 
                    RHEL-24268 [rhel-9] the switcheroo-control service runs under unconfined_service_t label -         
- Closed
 
-         
- is cloned by
- 
                    RHEL-62356 [rhel-10] the power-profiles-daemon service runs under unconfined_service_t label -         
- Closed
 
-         
- links to
- 
                     RHBA-2024:139849
        selinux-policy bug fix and enhancement update RHBA-2024:139849
        selinux-policy bug fix and enhancement update
- mentioned in
- 
                    Page Loading... 
             (1 links to, 1 mentioned in)