Commit Graph

216 Commits

Author SHA1 Message Date
RH Container Bot
c208678fca container-selinux-2:2.161.1-2.dev.gite1092cd
- bump to 2.161.1
- autobuilt e1092cd

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2021-05-07 15:39:13 +00:00
Lokesh Mandvekar
fad696781c Revert "container-selinux-2:2.117.0-2.dev.gitbfde70a"
This reverts commit 1b9e9a7937.

Bad commit
2021-05-06 08:24:08 -04:00
RH Container Bot
1b9e9a7937 container-selinux-2:2.117.0-2.dev.gitbfde70a
- bump to 2.117.0
- autobuilt bfde70a

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2021-04-28 13:42:16 +00:00
RH Container Bot
5b38b93dd2 container-selinux-2:2.160.0-3.dev.git5a60716
- autobuilt 5a60716

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2021-04-20 14:53:17 +00:00
Lokesh Mandvekar
a007307517 container-selinux-2:2.160.0-2.dev.gitc9f0cb6
- bump to v2.160.0

Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
2021-03-31 14:39:05 -04:00
RH Container Bot
9cb5b10e56 container-selinux-2:2.159.0-2.dev.gitd89a599
- bump to 2.159.0
- autobuilt d89a599

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2021-03-29 13:18:04 +00:00
RH Container Bot
c3b175e6d9 container-selinux-2:2.158.0-4.dev.gite78ac4f
- autobuilt e78ac4f

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2021-02-16 23:02:11 +00:00
RH Container Bot
ce7f9dfa88 container-selinux-2:2.158.0-3.dev.gitaeb85c4
- autobuilt aeb85c4

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2021-02-12 12:32:56 +00:00
RH Container Bot
e85faff448 container-selinux-2:2.158.0-2.dev.giteb6dad0
- bump to 2.158.0
- autobuilt eb6dad0

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2021-02-11 22:32:55 +00:00
RH Container Bot
13d8074bca container-selinux-2:2.157.0-3.dev.git6d13bf9
- autobuilt 6d13bf9

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2021-02-08 19:25:49 +00:00
RH Container Bot
75547d8ddf container-selinux-2:2.157.0-2.dev.gitf330e81
- bump to 2.157.0
- autobuilt f330e81

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2021-02-02 19:33:00 +00:00
RH Container Bot
0d6f91e1a0 container-selinux-2:2.156.0-2.dev.git75f193a
- bump to 2.156.0
- autobuilt 75f193a

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2021-01-15 17:32:57 +00:00
RH Container Bot
11e4b9b12a container-selinux-2:2.155.0-2.dev.git667f0f3
- bump to 2.155.0
- autobuilt 667f0f3

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2021-01-05 17:33:12 +00:00
RH Container Bot
9ddc5ee996 container-selinux-2:2.154.0-2.dev.git54e2ac5
- bump to 2.154.0
- autobuilt 54e2ac5

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-12-30 17:32:20 +00:00
RH Container Bot
79772309b0 container-selinux-2:2.153.0-2.dev.git8573f8d
- bump to 2.153.0
- autobuilt 8573f8d

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-12-26 11:32:22 +00:00
RH Container Bot
6d70d472bf container-selinux-2:2.152.0-2.dev.git1677bc4
- bump to 2.152.0
- autobuilt 1677bc4

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-12-22 14:02:31 +00:00
RH Container Bot
2a5fd9fae8 container-selinux-2:2.151.0-2.dev.git5d3c461
- bump to 2.151.0
- autobuilt 5d3c461

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-11-05 18:27:45 +00:00
RH Container Bot
d362045995 container-selinux-2:2.150.0-2.dev.git0ef4703
- bump to 2.150.0
- autobuilt 0ef4703

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-10-23 17:25:20 +00:00
RH Container Bot
9fdf5e4f15 container-selinux-2:2.148.0-3.dev.git9b3b66f
- autobuilt 9b3b66f

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-10-15 14:32:32 +00:00
RH Container Bot
b2e55a00f6 container-selinux-2:2.148.0-2.dev.git3c361a2
- bump to 2.148.0
- autobuilt 3c361a2

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-10-14 14:31:51 +00:00
RH Container Bot
f78c91f8fa container-selinux-2:2.147.0-2.dev.git9fb1698
- bump to 2.147.0
- autobuilt 9fb1698

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-10-12 14:31:58 +00:00
RH Container Bot
56ad893019 container-selinux-2:2.146.0-2.dev.git2908536
- bump to 2.146.0
- autobuilt 2908536

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-10-08 14:32:21 +00:00
RH Container Bot
9633f45f8a container-selinux-2:2.145.0-2.dev.git464e922
- bump to 2.145.0
- autobuilt 464e922

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-09-10 18:12:50 +00:00
RH Container Bot
bd03f1a9ad container-selinux-2:2.144.0-3.dev.git5d929d4
- autobuilt 5d929d4

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-08-13 14:10:52 +00:00
RH Container Bot
147e7d7263 container-selinux-2:2.144.0-2.dev.git746ea7a
- bump to 2.144.0
- autobuilt 746ea7a

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-08-12 15:10:13 +00:00
RH Container Bot
23e726843b container-selinux-2:2.143.0-2.dev.gite2d5a9e
- bump to 2.143.0
- autobuilt e2d5a9e

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-08-05 22:10:42 +00:00
RH Container Bot
1cfd08260c container-selinux-2:2.142.0-2.dev.gitfe6a25c
- bump to 2.142.0
- autobuilt fe6a25c

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-07-24 11:09:57 +00:00
RH Container Bot
6901df102e container-selinux-2:2.141.0-2.dev.git2750e78
- bump to 2.141.0
- autobuilt 2750e78

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-07-24 10:09:56 +00:00
RH Container Bot
78aaeb708b container-selinux-2:2.140.0-2.dev.git965c7fb
- bump to 2.140.0
- autobuilt 965c7fb

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-07-23 19:10:43 +00:00
RH Container Bot
dd65c71401 container-selinux-2:2.139.0-2.dev.git8c26927
- bump to 2.139.0
- autobuilt 8c26927

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-07-18 11:10:11 +00:00
RH Container Bot
d96aa6d4ec container-selinux-2:2.138.0-2.dev.git9884317
- bump to 2.138.0
- autobuilt 9884317

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-07-09 16:10:49 +00:00
RH Container Bot
7fd33b9d65 container-selinux-2:2.137.0-2.dev.git6b721da
- bump to 2.137.0
- autobuilt 6b721da

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-06-11 20:09:25 +00:00
RH Container Bot
3ed1e8a576 container-selinux-2:2.136.0-2.dev.git441172a
- bump to 2.136.0
- autobuilt 441172a

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-06-11 18:09:25 +00:00
RH Container Bot
724d3722ea container-selinux-2:2.135.0-2.dev.git0d99e89
- bump to 2.135.0
- autobuilt 0d99e89

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-05-29 18:08:38 +00:00
RH Container Bot
3e718a963f container-selinux-2:2.134.0-2.dev.gitff26015
- bump to 2.134.0
- autobuilt ff26015

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-05-28 21:09:36 +00:00
RH Container Bot
9e927847d1 container-selinux-2:2.132.0-3.dev.git0a878bd
- autobuilt 0a878bd

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-05-11 18:08:15 +00:00
RH Container Bot
fe867eee69 container-selinux-2:2.132.0-2.dev.git448dfbf
- bump to 2.132.0
- autobuilt 448dfbf

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-04-15 14:07:54 +00:00
RH Container Bot
03c15b46a6 container-selinux-2:2.131.0-2.dev.git9ce0dac
- bump to 2.131.0
- autobuilt 9ce0dac

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-04-09 20:08:09 +00:00
RH Container Bot
a260f6569b container-selinux-2:2.130.0-2.dev.gitfd55ae0
- bump to 2.130.0
- autobuilt fd55ae0

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-04-06 19:08:06 +00:00
RH Container Bot
55657d1adf container-selinux-2:2.129.0-2.dev.gitf00d1f4
- bump to 2.129.0
- autobuilt f00d1f4

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-03-29 12:09:29 +00:00
RH Container Bot
c060c61582 container-selinux-2:2.128.0-2.dev.git363646f
- bump to 2.128.0
- autobuilt 363646f

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-03-29 11:09:26 +00:00
RH Container Bot
a762720d65 container-selinux-2:2.127.0-2.dev.git6caf15d
- bump to 2.127.0
- autobuilt 6caf15d

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-03-27 15:07:51 +00:00
RH Container Bot
3c31e55f4e container-selinux-2:2.126.0-2.dev.git867a377
- bump to 2.126.0
- autobuilt 867a377

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-03-26 14:07:29 +00:00
Daniel J Walsh
230c717ecf
Install container_contexts file
Signed-off-by: Daniel J Walsh <dwalsh@redhat.com>
2020-03-23 15:45:54 -04:00
RH Container Bot
be3fb2313c container-selinux-2:2.125.0-3.1.dev.gitfde876b
- autobuilt fde876b

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-03-23 19:07:23 +00:00
RH Container Bot
5629e18d78 container-selinux-2:2.125.0-0.1.dev.gitb321ea4
- bump to 2.125.0
- autobuilt b321ea4

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-03-20 18:11:34 +00:00
RH Container Bot
a7a27f3909 container-selinux-2:2.124.0-0.4.dev.git5624558
- autobuilt 5624558

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2020-02-11 04:12:21 +00:00
RH Container Bot
9f271533a0 container-selinux-2:2.124.0-0.1.dev.gitf958d0c
- bump to 2.124.0
- autobuilt f958d0c

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2019-12-11 18:13:36 +00:00
RH Container Bot
fda115ab94 container-selinux-2:2.123.0-0.3.dev.git0b25a4a
- autobuilt 0b25a4a

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2019-11-29 12:10:21 +00:00
RH Container Bot
c10fcb7be3 container-selinux-2:2.123.0-0.1.dev.git661a904
- bump to 2.123.0
- autobuilt 661a904

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2019-11-25 16:10:35 +00:00
RH Container Bot
7d86365609 container-selinux-2:2.122.0-0.1.dev.git4560dd4
- bump to 2.122.0
- autobuilt 4560dd4

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2019-11-22 21:10:14 +00:00
RH Container Bot
8afcfa88a8 container-selinux-2:2.120.1-0.2.dev.gita233788
- autobuilt a233788

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2019-11-19 14:15:26 +00:00
RH Container Bot
445a455adf container-selinux-2:2.120.1-0.1.dev.git6fb6dcf
- bump to 2.120.1
- autobuilt 6fb6dcf

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2019-11-06 20:15:33 +00:00
RH Container Bot
244a2cbe3c container-selinux-2:2.119.1-0.1.dev.git2ecb2a8
- bump to 2.119.1
- autobuilt 2ecb2a8

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2019-10-27 09:21:18 +00:00
RH Container Bot
c9e415f48d container-selinux-2:2.119.0-0.1.dev.gitb383f07
- bump to 2.119.0
- autobuilt b383f07

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2019-10-24 16:26:13 +00:00
RH Container Bot
7605f73935 container-selinux-2:2.118.0-0.1.dev.git79bdcb5
- bump to 2.118.0
- autobuilt 79bdcb5

Signed-off-by: RH Container Bot <rhcontainerbot@fedoraproject.org>
2019-10-11 14:19:30 +00:00
Lokesh Mandvekar (Bot)
603bad3c42 container-selinux-2:2.117.0-0.1.dev.gitbfde70a
- bump to 2.117.0
- autobuilt bfde70a

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2019-09-20 08:27:36 +00:00
Lokesh Mandvekar (Bot)
121490dc1d container-selinux-2:2.116.0-0.1.dev.gitc5ef5ac
- bump to 2.116.0
- autobuilt c5ef5ac

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2019-09-05 14:35:01 +00:00
Lokesh Mandvekar (Bot)
5e7899d66a container-selinux-2:2.115.0-0.1.dev.gitfddfbbb
- bump to 2.115.0
- autobuilt fddfbbb

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2019-08-21 14:30:06 +00:00
Lokesh Mandvekar (Bot)
c42be5bbaa container-selinux-2:2.114.0-0.1.dev.git028ab00
- bump to 2.114.0
- autobuilt 028ab00

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2019-08-19 12:25:19 +00:00
Daniel J Walsh
3125beb1b1
Allow containers to name_bind to rawip_sockets. 2019-08-09 15:10:42 -04:00
Daniel J Walsh
7390ff8b05
Allow containers to use fusefs_t entrypoint
Dontaudit attempts to setattr on devicenodes.
2019-08-08 17:22:59 -04:00
Lokesh Mandvekar (Bot)
20e3511f2b container-selinux-2:2.111.0-2.1.dev.git9a75deb
- bump to 2.111.0
- autobuilt 9a75deb

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2019-07-18 03:24:01 +00:00
Lokesh Mandvekar
9db5509450 container-selinux-2.110.0-1.1.dev.git544d71f
- bump to v2.110.0
- hook up to autobuild

Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
2019-07-11 00:16:25 +05:30
Daniel J Walsh
ff9d4132e3
Allow containers to accept connections on all socket types
Allow containers to connect to gssproxy stream sockets if added to container
2019-07-08 13:40:06 -04:00
Daniel J Walsh
e642c7930b
Allow containers to manipulate Onload files. 2019-06-14 09:49:20 -04:00
Daniel J Walsh
535b77ce65
Allow all unconfined domains to manage unlabeled keyrings
Add labeling for kubernetes pods
2019-06-11 15:04:40 -04:00
Daniel J Walsh
5a72894caf
Set proper labeling for container volumes in SilverBlue 2019-06-03 06:51:52 +02:00
Daniel J Walsh
c4b1cdf7e5
Set proper labeling for container volumes 2019-05-17 16:35:24 -04:00
Daniel J Walsh
0ced217ba7
Allow all container domains to be entered from container_file_t 2019-05-12 06:50:58 -04:00
Daniel J Walsh
5c4855c313
Allow containers to read rpm cache and rpm databse 2019-05-03 15:32:13 -04:00
Daniel J Walsh
3cdf9de46f
Allow containers running as spc_t to create unlabeled_t kernel keyrings 2019-04-23 11:44:55 -04:00
Daniel J Walsh
bd9b0f5853
Allow containers running as spc_t to create unlabeled_t kernel keyrings 2019-04-23 11:44:39 -04:00
Daniel J Walsh
920a724abf
Fix labeling on /var/lib/containers/storage/overlay-layers,images to be sharable.
Signed-off-by: Daniel J Walsh <dwalsh@redhat.com>
2019-04-23 11:43:50 -04:00
Daniel J Walsh
e2b52d2d49
Allow iptables to append to container_file_t 2019-04-15 09:14:34 -04:00
Daniel J Walsh
7bfa450762
Allow containers to read/write sysctl_kernel_ns_last_pid_t
Allow containers to manage fusefs sockets and named pipes
2019-04-12 12:48:55 -04:00
Daniel J Walsh
9a2cedceeb
Allow containers to create fusefs sockets and named pipes 2019-04-01 17:47:51 -04:00
Daniel J Walsh
e0dcd250c0
Allow init_t to manage container content
Allow container domains to create fifo_files on fusefs file systems
Add boolean to allow containers to use ceph file systems
2019-03-28 08:00:26 -04:00
Daniel J Walsh
81c6f71fc4
Allow container runtimes to create unlabeled keyrings 2019-03-26 08:15:18 -04:00
Daniel J Walsh
4b3e8ccdf7
Allow containers to mount and umount fuse file systems. This will allow us
to use buidlah within a user namespace separated container.
2019-03-20 15:41:00 -04:00
Daniel J Walsh
c650254748
Allow all container domains to have container file types entrypoint
Add new release to fix issues with udica
Allow container_runtime_t to dyntransition to container domains
2019-03-09 08:38:21 -05:00
Daniel J Walsh
7ef0bf8d6f
Allow unconfined user and services to dyntrans to container domains, needed for CRIU
Allow containers exectue hugetlb files.
2019-03-01 09:00:53 -05:00
Daniel J Walsh
cdbdbb8ff6
More allow rules to allow containers to run within containers 2019-02-28 14:51:59 -05:00
Daniel J Walsh
9481eed87d
More allow rules to allow containers to run within containers 2019-02-28 08:15:40 -05:00
Lokesh Mandvekar (Bot)
0a83311798 container-selinux-2:2.82-2.git5e1f62f
- bump to 2.82
- autobuilt 5e1f62f

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2019-02-26 05:15:09 +00:00
Daniel J Walsh
a2d2cf7715
Allow containers to mounton cgroup and container_file_t 2019-02-25 10:08:25 -05:00
Daniel J Walsh
9c1bcaed9f
Allow confined users to use containers 2019-02-10 07:36:32 -07:00
Lokesh Mandvekar (Bot)
e791d82a98 container-selinux-2:2.80-3.git21c2be6
- bump to 2.80
- autobuilt 21c2be6

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2019-02-08 05:02:18 +00:00
Daniel J Walsh
2ae0570400
Add new labels for paths for containerd 2019-02-07 10:02:09 -07:00
Daniel J Walsh
ff7f910564
Don't allow containers to talk to contianer runtime sockets 2019-01-22 15:05:39 +01:00
Daniel J Walsh
d4eda46462
Fix labeling on /var/lib/registries 2019-01-11 11:05:46 -05:00
Lokesh Mandvekar (Bot)
3899d72021 container-selinux-2:2.77-2.git2c57a17
- bump to 2.77
- autobuilt 2c57a17

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2019-01-11 04:55:44 +00:00
Daniel J Walsh
5e8d437aba
Fix labeling for images in docker daemon user namespace 2019-01-10 15:17:44 -05:00
Daniel J Walsh
22b5b2899f
Allow container-runtime to setattr on fifo_file handed into container runtime. 2018-12-17 15:47:41 -05:00
Daniel J Walsh
6065af86d3
Allow container-runtime to setattr on fifo_file handed into container runtime. 2018-12-17 14:23:41 -05:00
Lokesh Mandvekar (Bot)
fbbda7e411 container-selinux-2:2.752.75-1.dev.git99e2cfd1
- bump to 2.75
- autobuilt 99e2cfd

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2018-11-13 04:05:43 +00:00
Daniel J Walsh
60e901fa33
Allow containers to sendto dgram socket of container runtimes
Needed to run container runtimes in notify socket unit files.
2018-11-12 15:48:53 -05:00
Daniel J Walsh
20e37ffd79
Allow containers to use fuse file systems by default 2018-10-30 08:34:06 -04:00
Daniel J Walsh
5df1d6fc43
Allow containers to setexec themselves 2018-10-19 17:45:33 -04:00
Daniel J Walsh
88328244ed
Define spc_t as a container_domain, so that container_runtime will transition
to spc_t even when setup with nosuid.
2018-09-13 09:33:50 -04:00