From da72c8245efd4fc514d3fdc6dcc1aa3c61d1418b Mon Sep 17 00:00:00 2001 From: Zdenek Pytela Date: Fri, 21 Aug 2026 17:02:26 +0200 Subject: [PATCH] * Fri Aug 21 2026 Zdenek Pytela - 42.1.27-1 - Label malware-detection-config.yml with insights_client_etc_rw_t Resolves: RHEL-176040 - Add the files_write_system_conf_files() interface Resolves: RHEL-176040 - Allow bluez dbus api pass sockets over dbus Resolves: RHEL-227725 - Support sandboxing features for sysadm_t Resolves: RHEL-227725 - Update dhcpc-hook policy Resolves: RHEL-236646 - Allow dhcpc hook query the chronyd service Resolves: RHEL-240723 - Support gnome-remote-desktop's smartcard redirection support Resolves: RHEL-227725 - Allow gnome-remote-desktop read sssd public files Resolves: RHEL-227725 - Allow gnome-remote-desktop connect to unreserved ports Resolves: RHEL-227725 - Allow gnome-remote-desktop speak with tabrmd over dbus Resolves: RHEL-227725 - Label /run/audit with auditd_var_run_t Resolves: RHEL-224026 - Allow auditd manage its private run dirs Resolves: RHEL-224026 - Allow virtqemud relabelfrom its private fifo files Resolves: RHEL-222520 - Update the ssh_server_template() template Resolves: RHEL-211174 Resolves: RHEL-240887 - Add rules for sshd vsock socket read/write Resolves: RHEL-211174 - Allow sshd-auth/sshd-session get attributes of their sshd parent Resolves: RHEL-211174 - Allow qatlib manage hugetlbfs directories Resolves: RHEL-211089 - Allow sanlock the sys_admin capability Resolves: RHEL-180192 - Allow lsmd-plugin use libStorageMgmt to provision storage Resolves: RHEL-179467 - Allow insights-client read gconf home files Resolves: RHEL-176040 - rhsmcertd: allow bootc/ostree transient package persistence detection Resolves: RHEL-152111 - Allow rhsmcertd read the file_contexts files Resolves: RHEL-152111 - Allow rhsmcertd read selinux config and default file contexts Resolves: RHEL-152111 - Use NetworkManager_t instead of networkmanager_t Resolves: RHEL-145714 --- changelog | 51 +++++++++++++++++++++++++++++++++++++++++++++ selinux-policy.spec | 4 ++-- sources | 4 ++-- 3 files changed, 55 insertions(+), 4 deletions(-) diff --git a/changelog b/changelog index 99edbfff..88d32c2e 100644 --- a/changelog +++ b/changelog @@ -1,3 +1,54 @@ +* Fri Aug 21 2026 Zdenek Pytela - 42.1.27-1 +- Label malware-detection-config.yml with insights_client_etc_rw_t +Resolves: RHEL-176040 +- Add the files_write_system_conf_files() interface +Resolves: RHEL-176040 +- Allow bluez dbus api pass sockets over dbus +Resolves: RHEL-227725 +- Support sandboxing features for sysadm_t +Resolves: RHEL-227725 +- Update dhcpc-hook policy +Resolves: RHEL-236646 +- Allow dhcpc hook query the chronyd service +Resolves: RHEL-240723 +- Support gnome-remote-desktop's smartcard redirection support +Resolves: RHEL-227725 +- Allow gnome-remote-desktop read sssd public files +Resolves: RHEL-227725 +- Allow gnome-remote-desktop connect to unreserved ports +Resolves: RHEL-227725 +- Allow gnome-remote-desktop speak with tabrmd over dbus +Resolves: RHEL-227725 +- Label /run/audit with auditd_var_run_t +Resolves: RHEL-224026 +- Allow auditd manage its private run dirs +Resolves: RHEL-224026 +- Allow virtqemud relabelfrom its private fifo files +Resolves: RHEL-222520 +- Update the ssh_server_template() template +Resolves: RHEL-211174 +Resolves: RHEL-240887 +- Add rules for sshd vsock socket read/write +Resolves: RHEL-211174 +- Allow sshd-auth/sshd-session get attributes of their sshd parent +Resolves: RHEL-211174 +- Allow qatlib manage hugetlbfs directories +Resolves: RHEL-211089 +- Allow sanlock the sys_admin capability +Resolves: RHEL-180192 +- Allow lsmd-plugin use libStorageMgmt to provision storage +Resolves: RHEL-179467 +- Allow insights-client read gconf home files +Resolves: RHEL-176040 +- rhsmcertd: allow bootc/ostree transient package persistence detection +Resolves: RHEL-152111 +- Allow rhsmcertd read the file_contexts files +Resolves: RHEL-152111 +- Allow rhsmcertd read selinux config and default file contexts +Resolves: RHEL-152111 +- Use NetworkManager_t instead of networkmanager_t +Resolves: RHEL-145714 + * Mon Jul 27 2026 Zdenek Pytela - 42.1.26-1 - Add missing rule for automotive policy Resolves: RHEL-216823 diff --git a/selinux-policy.spec b/selinux-policy.spec index 6dc15039..280daffa 100644 --- a/selinux-policy.spec +++ b/selinux-policy.spec @@ -6,7 +6,7 @@ # github repo with selinux-policy sources %global giturl https://github.com/fedora-selinux/selinux-policy -%global commit f19e526752937e4418adfd5c9b3b762a8d8b5e98 +%global commit b417e1578897a25762a3a582adfe4d01bd335bee %global shortcommit %(c=%{commit}; echo ${c:0:7}) %define distro redhat @@ -20,7 +20,7 @@ %define STABLEVER 42.1.18 Summary: SELinux policy configuration Name: selinux-policy -Version: 42.1.26 +Version: 42.1.27 Release: 1%{?dist} License: GPL-2.0-or-later Source: %{giturl}/archive/%{commit}/%{name}-%{shortcommit}.tar.gz diff --git a/sources b/sources index 8fe29eb5..92d14b4e 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (selinux-policy-f19e526.tar.gz) = a3247165104dc2389f9e738a8bb75d1baf022cc419103368d2211b3b272309b6c781ef523daba23e779697cb96f7707bf39acff516c09670fa729b37ea5a7334 +SHA512 (selinux-policy-b417e15.tar.gz) = f9958fe6a6c73d7adb5c3c22106c4258648a19c068698a7edf7bfe7a9604a207a3bc1d9011f921f7b6d577a0509128bb993912471829e575238e0bd5452e5b78 SHA512 (macro-expander) = 243ee49f1185b78ac47e56ca9a3f3592f8975fab1a2401c0fcc7f88217be614fe31805bacec602b728e7fcfc21dcc17d90e9a54ce87f3a0c97624d9ad885aea4 -SHA512 (container-selinux.tgz) = f9b7ac38dd20bdfdec0b2069e77ce5bc97c904ff2fbe6ae83fc296d559e23944da4946f10e6f50fe8aaa0c4dc15b04d7774b74746718180741f816b719d9c175 +SHA512 (container-selinux.tgz) = 204c7e2717ebf07b27e971baf937a33f3d4904eb45fb635aa5cf181651a76b0bb391ef6c558491120b7ee6879e5802a6cff5cb727efbc0f9c236eec15c3f7203