From df59df50d844fd82c5064f2136d260898cd6a4a9 Mon Sep 17 00:00:00 2001 From: Zdenek Pytela Date: Tue, 1 Jul 2025 21:34:32 +0200 Subject: [PATCH] * Tue Jul 01 2025 Zdenek Pytela - 38.1.59-1 - virt: allow QEMU use of the qgs daemon for attestation Resolves: RHEL-87744 - qgs: add contrib module for TDX "qgs" daemon Resolves: RHEL-87744 - kernel: add interfaces for using SGX enclaves Resolves: RHEL-87744 - Allow coreos-installer search sssd library directory Resolves: RHEL-95689 - Label /dev/diag as diagnostic_device_t Resolves: RHEL-95342 - Allow irqbalance execute shell if irqbalance_run_unconfined is on Resolves: RHEL-1556 --- modules-mls-contrib.conf | 7 +++++++ modules-targeted-contrib.conf | 7 +++++++ selinux-policy.spec | 18 ++++++++++++++++-- sources | 4 ++-- 4 files changed, 32 insertions(+), 4 deletions(-) diff --git a/modules-mls-contrib.conf b/modules-mls-contrib.conf index bfa841fb..17e15225 100644 --- a/modules-mls-contrib.conf +++ b/modules-mls-contrib.conf @@ -1579,3 +1579,10 @@ zosremote = module # Policy for mandb # mandb = module + +# Layer: service +# Module: qgs +# +# TDX QGS Daemon +# +qgs = module diff --git a/modules-targeted-contrib.conf b/modules-targeted-contrib.conf index db0c305b..7e2e41a9 100644 --- a/modules-targeted-contrib.conf +++ b/modules-targeted-contrib.conf @@ -2768,3 +2768,10 @@ powerprofiles = module # Policy for switcheroo-control: D-Bus service to check dual GPU availability # switcheroo = module + +# Layer: service +# Module: qgs +# +# TDX QGS Daemon +# +qgs = module diff --git a/selinux-policy.spec b/selinux-policy.spec index de7902f8..cd25e18c 100644 --- a/selinux-policy.spec +++ b/selinux-policy.spec @@ -1,6 +1,6 @@ # github repo with selinux-policy sources %global giturl https://github.com/fedora-selinux/selinux-policy -%global commit 9104418d6c680321bd38d3ebcf8fca8773d47002 +%global commit 906bebe413ca878d733bf4702e0462ea3176f8c9 %global shortcommit %(c=%{commit}; echo ${c:0:7}) %define distro redhat @@ -26,7 +26,7 @@ %define CHECKPOLICYVER 3.2 Summary: SELinux policy configuration Name: selinux-policy -Version: 38.1.58 +Version: 38.1.59 Release: 1%{?dist} License: GPLv2+ Source: %{giturl}/archive/%{commit}/%{name}-%{shortcommit}.tar.gz @@ -906,6 +906,20 @@ exit 0 %endif %changelog +* Tue Jul 01 2025 Zdenek Pytela - 38.1.59-1 +- virt: allow QEMU use of the qgs daemon for attestation +Resolves: RHEL-87744 +- qgs: add contrib module for TDX "qgs" daemon +Resolves: RHEL-87744 +- kernel: add interfaces for using SGX enclaves +Resolves: RHEL-87744 +- Allow coreos-installer search sssd library directory +Resolves: RHEL-95689 +- Label /dev/diag as diagnostic_device_t +Resolves: RHEL-95342 +- Allow irqbalance execute shell if irqbalance_run_unconfined is on +Resolves: RHEL-1556 + * Mon Jun 09 2025 Zdenek Pytela - 38.1.58-1 - Allow mptcpd the net_admin capability Resolves: RHEL-81729 diff --git a/sources b/sources index 624872b3..2e17ac8e 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (selinux-policy-9104418.tar.gz) = 223375367e2da5749c938443939cef11ecb710098d917ad43d5a86c8d0c5b8ff02aafe633d006f8ed961fd70fb38e37aa91de6e8610cad59e0816b85063ca3b6 +SHA512 (selinux-policy-906bebe.tar.gz) = c47b391a3f308f0b4d02977e3c1a49c08e94ae82215906626881225429084d78beeeb518f4d2948bdabfb46805ff5f0654883aa1881a1227071ea12eda2f39c7 SHA512 (macro-expander) = 243ee49f1185b78ac47e56ca9a3f3592f8975fab1a2401c0fcc7f88217be614fe31805bacec602b728e7fcfc21dcc17d90e9a54ce87f3a0c97624d9ad885aea4 -SHA512 (container-selinux.tgz) = 3108a0970c67f122e146c2d2e63bc8b45ad8cb450f3cc18928b9e348a8642e1ca27b73cc0436ed4b63dd76f41fa016866705b9d325f989f4bea986344d07c0e7 +SHA512 (container-selinux.tgz) = 9b9077269cc6fe82b5e305290d6b590036eaf14a495a331251088d809d1d4ac53ec522e42713257b068b10d58f1754eea7e9c4dd98043ccde7037757501bef08