diff --git a/.gitignore b/.gitignore index 5493e12..33c0aa8 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1 @@ -SOURCES/passt-a1e48a02ff3550eb7875a7df6726086e9b3a1213.tar.xz +passt-a1e48a02ff3550eb7875a7df6726086e9b3a1213.tar.xz diff --git a/.passt.metadata b/.passt.metadata deleted file mode 100644 index 1ee7dbd..0000000 --- a/.passt.metadata +++ /dev/null @@ -1 +0,0 @@ -6561fdc75b29dc6566bc1fb30b88d6846ef5e23b SOURCES/passt-a1e48a02ff3550eb7875a7df6726086e9b3a1213.tar.xz diff --git a/0001-selinux-passt_repair_exec_t-needs-to-be-a-exec_type.patch b/0001-selinux-passt_repair_exec_t-needs-to-be-a-exec_type.patch new file mode 100644 index 0000000..e18eda5 --- /dev/null +++ b/0001-selinux-passt_repair_exec_t-needs-to-be-a-exec_type.patch @@ -0,0 +1,26 @@ +From 0968be4a8529adb0282be86236ba9d949b30d5b0 Mon Sep 17 00:00:00 2001 +From: Stefano Brivio +Date: Wed, 26 Feb 2025 10:37:37 -0500 +Subject: [PATCH] selinux: passt_repair_exec_t needs to be a exec_type + +Signed-off-by: Stefano Brivio +--- + contrib/selinux/passt-repair.te | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/contrib/selinux/passt-repair.te b/contrib/selinux/passt-repair.te +index e3ffbcd..79f8acf 100644 +--- a/contrib/selinux/passt-repair.te ++++ b/contrib/selinux/passt-repair.te +@@ -33,7 +33,7 @@ require { + type passt_repair_t; + domain_type(passt_repair_t); + type passt_repair_exec_t; +-files_type(passt_repair_exec_t); ++corecmd_executable_file(passt_repair_exec_t); + + role unconfined_r types passt_repair_t; + +-- +2.47.1 + diff --git a/SOURCES/0001-selinux-Drop-user_namespace-create-allow-rules.patch b/SOURCES/0001-selinux-Drop-user_namespace-create-allow-rules.patch deleted file mode 100644 index 4149192..0000000 --- a/SOURCES/0001-selinux-Drop-user_namespace-create-allow-rules.patch +++ /dev/null @@ -1,51 +0,0 @@ -From 6977619743bbc602a865f79562b59a80921d6063 Mon Sep 17 00:00:00 2001 -From: Stefano Brivio -Date: Mon, 21 Aug 2023 17:52:28 +0200 -Subject: [PATCH] selinux: Drop user_namespace create allow rules - -Those are incompatible with current el9 kernels. I introduced them -upstream with commit 62059058cf24 ("selinux: Fix user namespace -creation after breaking kernel change"), in turn as a result of -kernel commit ed5d44d42c95 ("selinux: Implement userns_create hook"), -but on current el9 kernels (which lack the hook) they result in -failures such as: - - Failed to resolve allow statement at /var/lib/selinux/targeted/tmp/modules/200/passt/cil:103 - Failed to resolve AST - /usr/sbin/semodule: Failed! - Failed to resolve allow statement at /var/lib/selinux/targeted/tmp/modules/200/pasta/cil:104 - Failed to resolve AST - /usr/sbin/semodule: Failed! - -Signed-off-by: Stefano Brivio ---- - contrib/selinux/passt.te | 1 - - contrib/selinux/pasta.te | 1 - - 2 files changed, 2 deletions(-) - -diff --git a/contrib/selinux/passt.te b/contrib/selinux/passt.te -index c6cea34..131fadc 100644 ---- a/contrib/selinux/passt.te -+++ b/contrib/selinux/passt.te -@@ -92,7 +92,6 @@ allow syslogd_t self:cap_userns sys_ptrace; - allow passt_t self:process setcap; - allow passt_t self:capability { sys_tty_config setpcap net_bind_service setuid setgid}; - allow passt_t self:cap_userns { setpcap sys_admin sys_ptrace }; --allow passt_t self:user_namespace create; - - auth_read_passwd(passt_t) - -diff --git a/contrib/selinux/pasta.te b/contrib/selinux/pasta.te -index 69be081..892edae 100644 ---- a/contrib/selinux/pasta.te -+++ b/contrib/selinux/pasta.te -@@ -110,7 +110,6 @@ init_daemon_domain(pasta_t, pasta_exec_t) - - allow pasta_t self:capability { setpcap net_bind_service sys_tty_config dac_read_search net_admin sys_resource setuid setgid }; - allow pasta_t self:cap_userns { setpcap sys_admin sys_ptrace net_admin net_bind_service }; --allow pasta_t self:user_namespace create; - - auth_read_passwd(pasta_t) - --- -2.39.2 diff --git a/SPECS/passt.spec b/passt.spec similarity index 61% rename from SPECS/passt.spec rename to passt.spec index 6fb2248..db6c852 100644 --- a/SPECS/passt.spec +++ b/passt.spec @@ -12,14 +12,14 @@ Name: passt Version: 0^20250217.ga1e48a0 -Release: 1%{?dist} +Release: 3%{?dist} Summary: User-mode networking daemons for virtual machines and namespaces License: GPL-2.0-or-later AND BSD-3-Clause Group: System Environment/Daemons URL: https://passt.top/ Source: https://passt.top/passt/snapshot/passt-%{git_hash}.tar.xz -Patch1: 0001-selinux-Drop-user_namespace-create-allow-rules.patch +Patch1: 0001-selinux-passt_repair_exec_t-needs-to-be-a-exec_type.patch BuildRequires: gcc, make, git, checkpolicy, selinux-policy-devel Requires: (%{name}-selinux = %{version}-%{release} if selinux-policy-%{selinuxtype}) @@ -132,92 +132,138 @@ fi %{_datadir}/selinux/packages/%{selinuxtype}/passt-repair.pp %changelog +* Fri Feb 28 2025 Stefano Brivio - 0^20250217.ga1e48a0-3 +- Resolves: RHEL-80297 + +* Wed Feb 26 2025 Stefano Brivio - 0^20250217.ga1e48a0-2 +- Resolves: RHEL-80297 + * Mon Feb 17 2025 Stefano Brivio - 0^20250217.ga1e48a0-1 -- Resolves: RHEL-79787 +- Resolves: RHEL-79788 * Wed Jan 22 2025 Stefano Brivio - 0^20250121.g4f2c8e7-3 -- Resolves: RHEL-75654 +- Resolves: RHEL-75657 * Tue Jan 21 2025 Stefano Brivio - 0^20250121.g4f2c8e7-1 -- Resolves: RHEL-75654 +- Resolves: RHEL-75657 * Thu Nov 21 2024 Stefano Brivio - 0^20241121.g238c69f-1 -- Resolves: RHEL-65502 +- Resolves: RHEL-67556 + +* Tue Oct 29 2024 Troy Dawson - 0^20240806.gee36266-3 +- Bump release for October 2024 mass rebuild: + Resolves: RHEL-64018 * Wed Aug 14 2024 Stefano Brivio - 0^20240806-gee36266-2 -- Resolves: RHEL-54268 +- Resolves: RHEL-54269 * Wed Aug 7 2024 Stefano Brivio - 0^20240806.gee36266-1 -- Resolves: RHEL-53189 +- Resolves: RHEL-53190 * Fri Aug 2 2024 Stefano Brivio - 0^20240726.g57a21d2-1 -- Resolves: RHEL-52638 +- Resolves: RHEL-52639 * Mon Jun 24 2024 Stefano Brivio - 0^20240624.g1ee2eca-1 -- Resolves: RHEL-44837 +- Resolves: RHEL-44838 + +* Mon Jun 24 2024 Troy Dawson - 0^20240523.g765eb0b-2 +- Bump release for June 2024 mass rebuild + +* Thu May 23 2024 Stefano Brivio - 0^20240523.g765eb0b-1 +- Resolves: RHEL-36045 * Wed May 22 2024 Stefano Brivio - 0^20240510.g7288448-1 - Resolves: RHEL-37647 -* Fri Dec 15 2023 Stefano Brivio - 0^20231204.gb86afe3-1 -- Resolves: RHEL-19590 +* Thu Jan 25 2024 Fedora Release Engineering - 0^20231230.gf091893-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -* Tue Aug 22 2023 Stefano Brivio - 0^20230818.g0af928e-4 -- Switch to copies instead of links for pasta: previous workaround unreliable -- Resolves: RHELPLAN-155811 +* Sun Jan 21 2024 Fedora Release Engineering - 0^20231230.gf091893-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -* Tue Aug 22 2023 Stefano Brivio - 0^20230818.g0af928e-3 -- Explicit restorecon in scriptlet as rpm(8) mix up contexts with hard links -- Resolves: RHELPLAN-155811 +* Sat Dec 30 2023 Stefano Brivio - 0^20231230.gf091893-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_12_04.b86afe3..2023_12_30.f091893 -* Mon Aug 21 2023 Stefano Brivio - 0^20230818.g0af928e-2 -- Drop user_namespace create allow rule, incompatible with current el9 kernel -- Resolves: RHELPLAN-155811 +* Mon Dec 4 2023 Stefano Brivio - 0^20231204.gb86afe3-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_11_19.4f1709d..2023_12_04.b86afe3 -* Sat Aug 19 2023 Stefano Brivio - 0^20230818.g0af928e-1 -- Rebase from Fedora 39 -- Resolves: RHELPLAN-155811 +* Sun Nov 19 2023 Stefano Brivio - 0^20231119.g4f1709d-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_11_10.5ec3634..2023_11_19.4f1709d -* Sun Jun 11 2023 Stefano Brivio - 0^20230222.g4ddbcb9-4 -- Drop (pointless) patches 20, 21, 22, actually apply changes to the spec file! -- Refresh SELinux labels in scriptlets, require -selinux package (rhbz#2183089) -- Don't install useless SELinux interface file for pasta (rhbz#2183106) +* Fri Nov 10 2023 Stefano Brivio - 0^20231110.g5ec3634-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_11_07.74e6f48..2023_11_10.5ec3634 -* Fri Apr 28 2023 Stefano Brivio - 0^20230222.g4ddbcb9-3 -- Refresh SELinux labels in scriptlets, require -selinux package (rhbz#2183089) -- Don't install useless SELinux interface file for pasta (rhbz#2183106) +* Tue Nov 7 2023 Stefano Brivio - 0^20231107.g56d9f6d-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_10_04.f851084..2023_11_07.56d9f6d +- SELinux: allow passt_t to use unconfined_t UNIX domain sockets for + --fd option (https://bugzilla.redhat.com/show_bug.cgi?id=2247221) -* Thu Mar 16 2023 Stefano Brivio - 0^20230222.g4ddbcb9-2 -- udp: Actually use host resolver to forward DNS queries (rhbz#2177075) -- conf: Split add_dns{4,6}() out of get_dns() (rhbz#2177075) -- conf, udp: Allow any loopback address to be used as resolver (rhbz#2177075) -- tcp, tcp_splice: Get rid of false positive CWE-394 Coverity warning from fls() (rhbz#2177084) -- tcp: Avoid false (but convoluted) positive Coverity CWE-476 warning (rhbz#2177084) -- tcp: Avoid (theoretical) resource leak (CWE-772) Coverity warning (rhbz#2177084) -- Fix definitions of SOCKET_MAX, TCP_MAX_CONNS (rhbz#2177084) -- doc/demo: Fix and suppress ShellCheck warnings (rhbz#2177084) -- contrib/selinux: Drop duplicate init_daemon_domain() rule (rhbz#2176813) -- contrib/selinux: Let passt write to stdout and stderr when it starts (rhbz#2176813) -- contrib/selinux: Allow binding and connecting to all UDP and TCP ports (rhbz#2176813) -- contrib/selinux: Let interface users set paths for log, PID, socket files (rhbz#2176813) -- contrib/selinux: Drop "example" from headers: this is the actual policy (rhbz#2176813) -- contrib/selinux: Drop unused passt_read_data() interface (rhbz#2176813) -- contrib/selinux: Split interfaces into smaller bits (rhbz#2176813) -- fedora: Install SELinux interface files to shared include directory (rhbz#2176813) -- tcp, udp, util: Pass socket creation errors all the way up (rhbz#2177080) -- tcp, udp: Fix partial success return codes in {tcp,udp}_sock_init() (rhbz#2177080) -- conf: Terminate on EMFILE or ENFILE on sockets for port mapping (rhbz#2177080) -- tcp: Clamp MSS value when queueing data to tap, also for pasta (rhbz#2177083) -- Fix up SELinux labels on install/uninstall, require matching -selinux package (rhbz#2176813) -- Resolves: rhbz#2177075 rhbz#2177084 rhbz#2177080 rhbz#2177083 rhbz#2176813 +* Wed Oct 4 2023 Stefano Brivio - 0^20231004.gf851084-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_09_08.05627dc..2023_10_04.f851084 -* Wed Feb 22 2023 Camilla Conte - 0^20230222.g4ddbcb9-1 -- Import from fedora to CentOS/RHEL -- Resolves: rhbz#2172244 +* Fri Sep 8 2023 Stefano Brivio - 0^20230908.g05627dc-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_09_07.ee58f37..2023_09_08.05627dc -* Wed Nov 16 2022 Miroslav Rezanina - 0^20221110.g4129764-1 -- Import from fedora to CentOS/RHEL -- Resolves: rhbz#2131015 +* Thu Sep 7 2023 Stefano Brivio - 0^20230907.gee58f37-1 +- Replace pasta hard links by separate builds +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_08_23.a7e4bfb..2023_09_07.ee58f37 + +* Wed Aug 23 2023 Stefano Brivio - 0^20230823.ga7e4bfb-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_08_18.0af928e..2023_08_23.a7e4bfb + +* Fri Aug 18 2023 Stefano Brivio - 0^20230818.g0af928e-1 +- Install pasta as hard link to ensure SELinux file context match +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_06_27.289301b..2023_08_18.0af928e + +* Thu Jul 20 2023 Fedora Release Engineering - 0^20230627.g289301b-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Tue Jun 27 2023 Stefano Brivio - 0^20230627.g289301b-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_06_25.32660ce..2023_06_27.289301b + +* Sun Jun 25 2023 Stefano Brivio - 0^20230625.g32660ce-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_06_03.429e1a7..2023_06_25.32660ce + +* Sat Jun 3 2023 Stefano Brivio - 0^20230603.g429e1a7-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_05_09.96f8d55..2023_06_03.429e1a7 + +* Tue May 9 2023 Stefano Brivio - 0^20230509.g96f8d55-1 +- Relicense to GPL 2.0, or any later version +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_03_29.b10b983..2023_05_09.96f8d55 + +* Wed Mar 29 2023 Stefano Brivio - 0^20230329.gb10b983-1 +- Adjust path for SELinux policy and interface file to latest guidelines +- Don't install useless SELinux interface file for pasta +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_03_21.1ee2f7c..2023_03_29.b10b983 + +* Tue Mar 21 2023 Stefano Brivio - 0^20230321.g1ee2f7c-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_03_17.dd23496..2023_03_21.1ee2f7c + +* Fri Mar 17 2023 Stefano Brivio - 0^20230317.gdd23496-1 +- Refresh SELinux labels in scriptlets, require -selinux package +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_03_10.70c0765..2023_03_17.dd23496 + +* Fri Mar 10 2023 Stefano Brivio - 0^20230310.g70c0765-1 +- Install SELinux interface files to shared include directory +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_03_09.7c7625d..2023_03_10.70c0765 + +* Thu Mar 9 2023 Stefano Brivio - 0^20230309.g7c7625d-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_02_27.c538ee8..2023_03_09.7c7625d + +* Mon Feb 27 2023 Stefano Brivio - 0^20230227.gc538ee8-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_02_22.4ddbcb9..2023_02_27.c538ee8 + +* Wed Feb 22 2023 Stefano Brivio - 0^20230222.g4ddbcb9-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2023_02_16.4663ccc..2023_02_22.4ddbcb9 + +* Thu Feb 16 2023 Stefano Brivio - 0^20230216.g4663ccc-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2022_11_16.ace074c..2023_02_16.4663ccc + +* Thu Jan 19 2023 Fedora Release Engineering - 0^20221116.gace074c-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Wed Nov 16 2022 Stefano Brivio - 0^20221116.gace074c-1 +- Upstream changes: https://passt.top/passt/log/?qt=range&q=2022_11_10.4129764..2022_11_16.ace074c * Thu Nov 10 2022 Stefano Brivio - 0^20221110.g4129764-1 - Upstream changes: https://passt.top/passt/log/?qt=range&q=2022_11_04.e308018..2022_11_10.4129764 diff --git a/sources b/sources new file mode 100644 index 0000000..23bf0c3 --- /dev/null +++ b/sources @@ -0,0 +1 @@ +SHA512 (passt-a1e48a02ff3550eb7875a7df6726086e9b3a1213.tar.xz) = 8f55b4a1c1d1ba5a33e880e228a0db4ab1ad7ea0fad046808d3816999815ad3a0bf80f0d153bfd1c2b6ec62cb5c96c2a783d032d6bdf4d3a32e38e6d6cca12b5