* Fri Aug 21 2026 Zdenek Pytela <zpytela@redhat.com> - 42.1.27-1

- Label malware-detection-config.yml with insights_client_etc_rw_t
Resolves: RHEL-176040
- Add the files_write_system_conf_files() interface
Resolves: RHEL-176040
- Allow bluez dbus api pass sockets over dbus
Resolves: RHEL-227725
- Support sandboxing features for sysadm_t
Resolves: RHEL-227725
- Update dhcpc-hook policy
Resolves: RHEL-236646
- Allow dhcpc hook query the chronyd service
Resolves: RHEL-240723
- Support gnome-remote-desktop's smartcard redirection support
Resolves: RHEL-227725
- Allow gnome-remote-desktop read sssd public files
Resolves: RHEL-227725
- Allow gnome-remote-desktop connect to unreserved ports
Resolves: RHEL-227725
- Allow gnome-remote-desktop speak with tabrmd over dbus
Resolves: RHEL-227725
- Label /run/audit with auditd_var_run_t
Resolves: RHEL-224026
- Allow auditd manage its private run dirs
Resolves: RHEL-224026
- Allow virtqemud relabelfrom its private fifo files
Resolves: RHEL-222520
- Update the ssh_server_template() template
Resolves: RHEL-211174
Resolves: RHEL-240887
- Add rules for sshd vsock socket read/write
Resolves: RHEL-211174
- Allow sshd-auth/sshd-session get attributes of their sshd parent
Resolves: RHEL-211174
- Allow qatlib manage hugetlbfs directories
Resolves: RHEL-211089
- Allow sanlock the sys_admin capability
Resolves: RHEL-180192
- Allow lsmd-plugin use libStorageMgmt to provision storage
Resolves: RHEL-179467
- Allow insights-client read gconf home files
Resolves: RHEL-176040
- rhsmcertd: allow bootc/ostree transient package persistence detection
Resolves: RHEL-152111
- Allow rhsmcertd read the file_contexts files
Resolves: RHEL-152111
- Allow rhsmcertd read selinux config and default file contexts
Resolves: RHEL-152111
- Use NetworkManager_t instead of networkmanager_t
Resolves: RHEL-145714
This commit is contained in:
Zdenek Pytela 2026-08-21 17:02:26 +02:00
parent 3801b359e9
commit da72c8245e
3 changed files with 55 additions and 4 deletions

View File

@ -1,3 +1,54 @@
* Fri Aug 21 2026 Zdenek Pytela <zpytela@redhat.com> - 42.1.27-1
- Label malware-detection-config.yml with insights_client_etc_rw_t
Resolves: RHEL-176040
- Add the files_write_system_conf_files() interface
Resolves: RHEL-176040
- Allow bluez dbus api pass sockets over dbus
Resolves: RHEL-227725
- Support sandboxing features for sysadm_t
Resolves: RHEL-227725
- Update dhcpc-hook policy
Resolves: RHEL-236646
- Allow dhcpc hook query the chronyd service
Resolves: RHEL-240723
- Support gnome-remote-desktop's smartcard redirection support
Resolves: RHEL-227725
- Allow gnome-remote-desktop read sssd public files
Resolves: RHEL-227725
- Allow gnome-remote-desktop connect to unreserved ports
Resolves: RHEL-227725
- Allow gnome-remote-desktop speak with tabrmd over dbus
Resolves: RHEL-227725
- Label /run/audit with auditd_var_run_t
Resolves: RHEL-224026
- Allow auditd manage its private run dirs
Resolves: RHEL-224026
- Allow virtqemud relabelfrom its private fifo files
Resolves: RHEL-222520
- Update the ssh_server_template() template
Resolves: RHEL-211174
Resolves: RHEL-240887
- Add rules for sshd vsock socket read/write
Resolves: RHEL-211174
- Allow sshd-auth/sshd-session get attributes of their sshd parent
Resolves: RHEL-211174
- Allow qatlib manage hugetlbfs directories
Resolves: RHEL-211089
- Allow sanlock the sys_admin capability
Resolves: RHEL-180192
- Allow lsmd-plugin use libStorageMgmt to provision storage
Resolves: RHEL-179467
- Allow insights-client read gconf home files
Resolves: RHEL-176040
- rhsmcertd: allow bootc/ostree transient package persistence detection
Resolves: RHEL-152111
- Allow rhsmcertd read the file_contexts files
Resolves: RHEL-152111
- Allow rhsmcertd read selinux config and default file contexts
Resolves: RHEL-152111
- Use NetworkManager_t instead of networkmanager_t
Resolves: RHEL-145714
* Mon Jul 27 2026 Zdenek Pytela <zpytela@redhat.com> - 42.1.26-1
- Add missing rule for automotive policy
Resolves: RHEL-216823

View File

@ -6,7 +6,7 @@
# github repo with selinux-policy sources
%global giturl https://github.com/fedora-selinux/selinux-policy
%global commit f19e526752937e4418adfd5c9b3b762a8d8b5e98
%global commit b417e1578897a25762a3a582adfe4d01bd335bee
%global shortcommit %(c=%{commit}; echo ${c:0:7})
%define distro redhat
@ -20,7 +20,7 @@
%define STABLEVER 42.1.18
Summary: SELinux policy configuration
Name: selinux-policy
Version: 42.1.26
Version: 42.1.27
Release: 1%{?dist}
License: GPL-2.0-or-later
Source: %{giturl}/archive/%{commit}/%{name}-%{shortcommit}.tar.gz

View File

@ -1,3 +1,3 @@
SHA512 (selinux-policy-f19e526.tar.gz) = a3247165104dc2389f9e738a8bb75d1baf022cc419103368d2211b3b272309b6c781ef523daba23e779697cb96f7707bf39acff516c09670fa729b37ea5a7334
SHA512 (selinux-policy-b417e15.tar.gz) = f9958fe6a6c73d7adb5c3c22106c4258648a19c068698a7edf7bfe7a9604a207a3bc1d9011f921f7b6d577a0509128bb993912471829e575238e0bd5452e5b78
SHA512 (macro-expander) = 243ee49f1185b78ac47e56ca9a3f3592f8975fab1a2401c0fcc7f88217be614fe31805bacec602b728e7fcfc21dcc17d90e9a54ce87f3a0c97624d9ad885aea4
SHA512 (container-selinux.tgz) = f9b7ac38dd20bdfdec0b2069e77ce5bc97c904ff2fbe6ae83fc296d559e23944da4946f10e6f50fe8aaa0c4dc15b04d7774b74746718180741f816b719d9c175
SHA512 (container-selinux.tgz) = 204c7e2717ebf07b27e971baf937a33f3d4904eb45fb635aa5cf181651a76b0bb391ef6c558491120b7ee6879e5802a6cff5cb727efbc0f9c236eec15c3f7203