import UBI container-selinux-2.240.0-10.el10_1

This commit is contained in:
AlmaLinux RelEng Bot 2026-04-07 12:57:28 -04:00
parent 7a7fb41ca7
commit c5ae39360d
4 changed files with 79 additions and 5 deletions

31
390-backport.patch Normal file
View File

@ -0,0 +1,31 @@
diff -up container-selinux-2.240.0/container.if.390 container-selinux-2.240.0/container.if
--- container-selinux-2.240.0/container.if.390 2025-09-19 07:03:21.827502160 +0200
+++ container-selinux-2.240.0/container.if 2025-09-19 07:03:35.383197574 +0200
@@ -19,6 +19,7 @@ interface(`container_runtime_domtrans',`
corecmd_search_bin($1)
domtrans_pattern($1, container_runtime_exec_t, container_runtime_t)
allow container_runtime_t $1:fifo_file setattr;
+ allow $1 container_runtime_t:bpf prog_run;
')
########################################
diff -up container-selinux-2.240.0/container.te.390 container-selinux-2.240.0/container.te
--- container-selinux-2.240.0/container.te.390 2025-09-19 07:03:25.942964294 +0200
+++ container-selinux-2.240.0/container.te 2025-09-19 07:04:49.113508085 +0200
@@ -744,7 +744,7 @@ optional_policy(`
allow unconfined_domain_type { container_var_lib_t container_ro_file_t }:file entrypoint;
fs_fusefs_entrypoint(unconfined_domain_type)
- domtrans_pattern(unconfined_domain_type, container_runtime_exec_t , container_runtime_t)
+ container_runtime_domtrans(unconfined_domain_type)
')
optional_policy(`
@@ -1335,6 +1335,7 @@ container_manage_share_files(init_t)
container_manage_share_dirs(init_t)
container_filetrans_named_content(init_t)
container_runtime_read_tmpfs_files(init_t)
+allow init_t container_runtime_t:bpf prog_run;
gen_require(`
attribute device_node;

13
397-backport.patch Normal file
View File

@ -0,0 +1,13 @@
diff -up container-selinux-2.240.0/container.te.397 container-selinux-2.240.0/container.te
--- container-selinux-2.240.0/container.te.397 2025-09-19 07:01:45.736869927 +0200
+++ container-selinux-2.240.0/container.te 2025-09-19 07:02:11.869541486 +0200
@@ -1347,6 +1347,9 @@ allow container_domain init_t:unix_strea
allow container_t proc_t:filesystem remount;
+# Allow containers to access shared runtime directories for OCI runtime optimizations
+allow container_t container_var_run_t:dir list_dir_perms;
+
# Container kvm - Policy for running kata containers
container_domain_template(container_kvm, container)
typeattribute container_kvm_t container_net_domain, container_user_domain;

23
412.patch Normal file
View File

@ -0,0 +1,23 @@
From d27647a022f01aa5f847383878cf67c616a5d98e Mon Sep 17 00:00:00 2001
From: Peter Hunt <pehunt@redhat.com>
Date: Fri, 7 Nov 2025 10:27:32 -0500
Subject: [PATCH] container_engine_t: add necessary permissions to ssh in
userns container
Signed-off-by: Peter Hunt <pehunt@redhat.com>
---
container.te | 1 +
1 file changed, 1 insertion(+)
diff --git a/container.te b/container.te
index 63ae6bf..3af1b2b 100644
--- a/container.te
+++ b/container.te
@@ -1487,6 +1487,7 @@ allow container_engine_t kernel_t:system module_request;
allow container_engine_t null_device_t:chr_file { mounton setattr_chr_file_perms };
allow container_engine_t random_device_t:chr_file mounton;
allow container_engine_t self:netlink_tcpdiag_socket nlmsg_read;
+allow container_engine_t self:netlink_audit_socket nlmsg_relay;
allow container_engine_t urandom_device_t:chr_file mounton;
allow container_engine_t zero_device_t:chr_file mounton;
allow container_engine_t container_file_t:sock_file mounton;

View File

@ -1,4 +1,4 @@
%global debug_package %{nil}
%global debug_package %{nil}
# container-selinux stuff (prefix with ds_ for version/release etc.)
# Some bits borrowed from the openstack-selinux package
@ -36,11 +36,14 @@ Epoch: 4
# to the correct value by Packit for copr and koji builds.
# IGNORE this comment if you're looking at it in dist-git.
Version: 2.240.0
Release: 1%{?dist}
Release: 10%{?dist}
License: GPL-2.0-only
URL: https://github.com/containers/%{name}
Summary: SELinux policies for container runtimes
Source0: %{url}/archive/v%{version}.tar.gz
Patch1: https://github.com/containers/container-selinux/pull/397-backport.patch
Patch2: https://github.com/containers/container-selinux/pull/390-backport.patch
Patch3: https://patch-diff.githubusercontent.com/raw/containers/container-selinux/pull/412.patch
BuildArch: noarch
BuildRequires: make
BuildRequires: git-core
@ -111,12 +114,12 @@ fi
%posttrans
%selinux_relabel_post
# Empty placeholder check to silence rpmlint
%check
#define license tag if not already defined
%{!?_licensedir:%global license %doc}
# Placeholder check to silence rpmlint
%check
%files
%doc README.md
%{_datadir}/selinux/*
@ -138,6 +141,10 @@ if %{_sbindir}/selinuxenabled ; then
fi
%changelog
* Wed Feb 25 2026 Jindrich Novy <jnovy@redhat.com> - 4:2.240.0-10
- sync with 9.7.z
- Resolves: RHEL-151428
* Mon Aug 11 2025 Jindrich Novy <jnovy@redhat.com> - 4:2.240.0-1
- update to https://github.com/containers/container-selinux/releases/tag/v2.240.0
- Related: RHEL-80817